Manage your ISMS
with full sovereignty

ISO 27001 & NIS2 · Zero installation · 100% open source · Works offline

ISO 27001 ISO 27002 ISO 27005 DORA PCI DSS
cyber-assistant.com
Cyber Assistant - Free ISMS management tool with ISO 27001, ISO 27002, NIS2 compliance dashboard
The challenge

SaaS solutions expose your sensitive data

Risk registers, business continuity plans, critical asset mappings... Do these strategic documents really belong on external servers?

Data out of control

With SaaS, your risk registers and continuity plans transit through third-party servers. For a DPO or CISO, this is a permanent GDPR vulnerability.

Unavailable during crisis

Cyberattack, network outage, major incident? Your SaaS solution becomes inaccessible, depriving your crisis team of continuity plans at the worst moment.

Heavy infrastructure

Docker, PostgreSQL, DevOps team... Small municipalities don't have these resources. Total cost of ownership explodes before you even start.

Our answer

Cyber Assistant: sovereignty by design

A tool designed for all security managers, suited to public administrations and businesses alike. No data ever transits through external servers. Privacy by Design.

Cyber Assistant Dashboard - Executive ISMS reporting for security managers

Zero cloud, zero compromise

  • Complete sovereignty: your data stays in your browser or on your internal server — never elsewhere
  • Crisis-resilient: works offline, even when internet is down or your network is compromised
  • Zero installation: open the HTML file in your browser, that's it. No Docker, no database
  • Collaborative mode available: a simple web server is all you need for team collaboration on your own infrastructure
Risk Analysis

Master your risks with full autonomy

An ISO 27005-aligned risk analysis module, pragmatic and guided. From assessment to PDF report, in just a few clicks.

Step-by-step guidance

Perform a risk analysis in a few pragmatic steps

An 8-step wizard guides you through: CIA classification, continuity (RTO/RPO), data protection, security controls, risk scenarios, and automatic recommendations.

  • 8 guided steps, from CIA classification to final report
  • 24 control questions covering 6 operational domains
  • ISO 27005-aligned — without the methodological overhead
Wizard d'analyse de risques - Questionnaire contrôles de sécurité avec 6 domaines opérationnels
Automatic scoring

Manage your risk analyses

10 built-in scenarios or the threats of 6 embedded frameworks (NIST SP 800-30, OWASP Top 10:2025, STRIDE, MITRE ATT&CK, OWASP LLM and API), with suggested ratings you always review. Probability × severity matrix, customizable thresholds, and 35 recommendation rules.

  • 6 threat frameworks on top of the 10 built-in scenarios: NIST, OWASP, STRIDE, MITRE ATT&CK...
  • 5×5 probability × severity matrix with 5 risk levels
  • Automatic recommendations and treatment strategy per risk
Sélection et évaluation des scénarios de risques avec matrice probabilité × gravité
PDF Export

Produce your risk analysis reports

Generate a complete PDF report ready for the board or auditor: executive summary, domain radar chart, threat/scenario register, method and framework traced (frozen version), priority recommendations.

  • Multi-page PDF report with professional cover page
  • Domain radar chart and traffic light global assessment
  • Ready for the board, audit, or NIS2 reporting
Rapport PDF d'analyse de risques - Page de garde et synthèse exécutive avec feu tricolore

Methodology, standards, frameworks and features: how it all fits together

COMMENT TOUT S'ARTICULE Méthodologie, normes & frameworks, fonctionnalités Un seul effort, trois domaines, tous les référentiels. Méthodologie / norme Fonction de l'outil PLAN Planifier ISO 27001 cl.4-7 & 6.1 DO Déployer ISO 27001 cl.8 CHECK Contrôler ISO 27001 cl.9 ACT Améliorer ISO 27001 cl.10 cycle d'amélioration continue GOUVERNANCE l'axe qui pilote le cycle diriger · décider · mesurer ISO 27001 cl.8-10 · NIS2 art.20 ACT · Amélioration ISO 27001 §10.1 §10.2 — NC Plan d'actions — 6 types de lien Non-conformités (détection → clôture) Budget cybersécurité PLAN · Gestion du risque ISO 27005 EBIOS RM NIST SP 800-30 Analyse des risques — wizard 8 étapes Matrice d'impacts — 3 grilles Déclaration d'applicabilité (SoA) — 93 Actifs essentiels & parties prenantes CHECK · Conformité ISO 27001 §9 CyFun 2025 ReCyF NIST CSF 2.0 Dashboard — Score SMSI consolidé Contrôles NIS2 CyFun — 218 exigences Mesures ReCyF — 152 mesures Audits · KPI · Revues de direction DO · Contrôles ISO 27002 — 93 Maturité CMM 1-5 Contrôles ISO 27002 — 93 mesures Menaces (traitement ISO 27005) Socle de sécurité NIS2 MOTEUR DE TRANSVERSALITÉ Corrèle sans recopier — chaque référentiel garde son évaluation souveraine ISO 27002 Frameworks NIS2 NIST CSF 2.0 132 correspondances couvre 97 équivalent 9 lié 26 Signale les conflits de statut entre référentiels mappés. un contrôle documenté une fois éclaire ISO ET NIS2 — l'effort compte double. NATIFS ISO 27001 ISO 27002 NIS2 CyFun CCB ReCyF ANSSI CORRESPONDANCES DORA PCI DSS 5 natifs évaluables + 2 correspondances croisées
Comment tout s'articule
Méthodologie, normes & frameworks, fonctionnalités
Un seul effort, trois domaines, tous les référentiels.
PLAN DO CHECK ACT GOUVERNANCE l'axe du cycle ISO 27001 cl.8-10
cycle d'amélioration continue (PDCA)
PLAN · Gestion du risque · cl.4-7 & 6.1
ISO 27005EBIOS RMNIST SP 800-30RGPD
  • Analyse des risques — wizard 8 étapes
  • Matrice d'impacts — 3 grilles
  • Déclaration d'applicabilité (SoA) — 93 contrôles
  • Actifs essentiels & parties prenantes
DO · Contrôles · cl.8
ISO 27002 — 93Maturité CMM 1-5
  • Contrôles ISO 27002 — 93 mesures
  • Menaces (traitement ISO 27005)
  • Socle de sécurité NIS2
CHECK · Conformité · cl.9
ISO 27001 §9CyFun 2025ReCyFNIST CSF 2.0
  • Dashboard — Score SMSI consolidé
  • Contrôles NIS2 CyFun — 218 exigences
  • Mesures ReCyF — 152 mesures
  • Audits · KPI · Revues de direction
ACT · Amélioration · cl.10
ISO 27001 §10.1§10.2 — NC
  • Plan d'actions — 6 types de lien
  • Non-conformités (détection → clôture)
  • Budget cybersécurité
MOTEUR DE TRANSVERSALITÉ
132
correspondances ISO 27002 ↔ Frameworks NIS2 ↔ NIST CSF 2.0
couvre 97équivalent 9lié 26
l'effort compte double
Corrèle sans recopier — chaque référentiel garde son évaluation souveraine
NATIFS ISO 27001ISO 27002NIS2CyFun CCBReCyF ANSSI CORRESPONDANCES DORAPCI DSS
Why Cyber Assistant

Three guarantees for your peace of mind

Designed to meet the requirements of DPOs, CISOs and compliance officers in the public sector and critical infrastructure.

Data sovereignty

Without an external backend, it is technically impossible for your data to leave your perimeter without your knowledge. Privacy by Design for uncompromising GDPR compliance.

Operational resilience

Cyberattack, network outage, crisis situation? Cyber Assistant remains accessible. Your continuity plans available even in "scorched earth" mode. Essential for emergency services.

Zero infrastructure debt

No Docker, no PostgreSQL, no DevOps team. Open an HTML file, that's it. The lowest total cost of ownership on the market, even for a 500-inhabitant municipality.

Cross-framework mapping

Visualize cross-coverage of your frameworks

The bidirectional mapping system visualizes overlaps between ISO 27002, CyFun 2025/NIS2, DORA and PCI DSS. Immediately identify covered areas and gaps.

Heatmap view

Map your coverage at a glance

The interactive heatmap shows correspondence levels between frameworks. Three relationship types (equivalent, covers, related) enable fine-grained cross-coverage analysis.

  • Bidirectional mapping with 3 relationship types
  • Real-time coverage statistics
  • Filtering by relationship type and text search
Detailed view

Explore each relationship control by control

The list view lets you explore each cross-framework relationship in detail, with relationship type, coverage percentage and explanatory notes.

  • 132 pre-configured relationships between ISO 27002 and CyFun 2025
  • Coverage percentage per relationship
  • Export mappings for your audits
Features

Everything you need to manage your ISMS

A complete suite of tools designed for operational efficiency, executive reporting and audit compliance.

ISMS Dashboard

Clickable KPIs, ISO 27002 and NIS2 maturity radars, impact × probability risk matrix, evolution charts.

Global compliance Critical risks CMM Maturity

ISO 27001/27002 Controls

Integrated library of 93 Annex A 2022 controls. Status, CMM maturity, filters by domain and operational capabilities.

93 controls SoA 27001 doc review

Complete NIS2 Program

NIS2 controls, 2027/2028 radar, phased action plans, budget management by action and domain, color-coded milestones.

Phases 2026-2028 5 pillars Budgets

Action Plans & Risks

Actions linked to controls, risks, audits, non-conformities and threats. Impact × probability score, treatment strategy, board date.

Priorities Owners Deadlines

Exports & Reports

Global PDF report, Excel export per module, standalone NIS2 HTML export, local snapshots with one-click restore.

PDF CODIR Excel JSON/SMSI

Search & Quality

Global search across all objects. Quality tools: duplicate detection, invalid links, controls without subcategory.

Unified search Data audit

Cross-framework mapping

Visualize correspondences between ISO 27002, CyFun 2025, DORA and PCI DSS with heatmap and detailed list view.

132 relationships Heatmap Bidirectional

Impact matrices

Assess impacts using NIST SP 800-30, PESTEL/5M or EBIOS RM with customizable multi-dimensional matrices.

NIST SP 800-30 PESTEL EBIOS RM
NIS2 · CyFun & ReCyF

A complete NIS2 program: CyFun (CCB) label and ReCyF (ANSSI) framework

Drive your NIS2 compliance end-to-end: budget program, controls with CMM maturity, 5-pillar security baseline, and national framework tracking — Belgium's CyFun (CCB) label and France's ReCyF (ANSSI) framework.

Program & Budget

NIS2 budget management and CyFun CCB milestones

Configure your budget blocks, track compliance KPIs, visualize maturity on radar chart and drive regulatory milestones toward the CyFun label from Belgium's CCB.

  • Configurable budget blocks (OPEX, CAPEX, infra, ISS)
  • NIS2 maturity radar with 2027/2028 targets
  • 10+ strategic domains with actions and owners
  • PDF, HTML and Excel export of the complete program
NIS2 Controls

23 NIS2 controls with integrated CMM maturity

Manage your NIS2 controls by function (Identify, Protect, Detect, Respond, Recover), assess CMM maturity for each and document your justifications.

  • Complete NIS2 library (ID, PR, DE, RS, RC)
  • 5-level CMM maturity per control
  • Filters by function, category, status and level
NIST CSF 2.0 Baseline

A security baseline structured on NIST CSF 2.0

The security baseline is built on the NIST Cybersecurity Framework 2.0 with 6 structural functions: Govern, Identify, Protect, Detect, Respond and Recover.

  • 6 NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover
  • Aligned with NIS2 and CyFun 2025 CCB requirements
  • Supply chain, Identities & IAM, Risk management
CyFun 2025

Choose your NIS2 assurance level

The CyFun 2025 framework from Belgium's Centre for Cybersecurity (CCB) defines 3 assurance levels aligned with the NIS2 directive. Configure your target level directly in the setup wizard.

  • 3 levels: Basic, Important, Essential
  • 218 CyFun 2025 requirements based on NIST CSF 2.0
  • 6 functions: Govern, Identify, Protect, Detect, Respond, Recover
  • Maturity thresholds adapted to each level
ReCyF 2025 · ANSSI

France's path to NIS2 with the ANSSI's ReCyF framework

For French entities, Cyber Assistant natively integrates the ANSSI's ReCyF framework. Unlike CyFun's maturity model, ReCyF follows a conformity logic: for each of the 152 measures, you declare your status and justify it. The objective scope adapts automatically to your tier (Important or Essential Entity).

  • 20 security objectives and 152 measures (ANSSI acceptable means)
  • Two tiers: Important Entity (objectives 1 to 15) and Essential Entity (objectives 1 to 20)
  • Conformity-based assessment: compliant, partial, non-compliant, alternative measure, not applicable — with justification
  • Conformity radar per objective and overall % score, separate from the CyFun engine
Impact matrices

Assess your impacts with precision

Two pre-configured matrices (PESTEL/5M and NIST SP 800-30) assess impacts across 6 to 10 dimensions with 5 severity levels. Create your own custom matrices.

Multi-methodology

NIST SP 800-30, PESTEL and EBIOS RM in one tool

Three pre-configured matrices cover the main impact assessment methodologies. Customize dimensions, levels and calculation rules to fit your context.

  • NIST SP 800-30: 6 dimensions (Mission, Data, Physical Security, Relationships, Finance, Planning)
  • PESTEL: 10 dimensions with Confidentiality/Integrity/Availability impacts
  • Compatible with EBIOS RM, ISO 27005 and NIST
  • Customizable matrices: levels, dimensions, calculation rules
0 guided steps
0 control questions
0 risk scenarios
0 recommendation rules
0 risk levels
0 mapping relationships
0 integrated frameworks
Extensibility

A platform open to sector-specific regulations

Cyber Assistant's modular architecture enables integration of new regulatory frameworks. The bidirectional mapping system automatically connects new frameworks to existing controls.

DORA

Digital Operational Resilience Act. European regulation for digital resilience in the financial sector. Available on request with ISO 27002 mapping.

PCI DSS

Payment Card Industry Data Security Standard. Security standard for payment card data. Available on request with complete mapping.

Your framework

Custom integration of sector-specific or internal frameworks. Contact us to evaluate the integration of your specific regulatory framework.

Server mode

Go collaborative on your infrastructure

Upload the files to any simple web server (Apache, Nginx, or any PHP hosting) and Cyber Assistant becomes a multi-user collaborative platform. No database, no complex setup — your data stays on your own infrastructure.

Real-time co-editing

Tab-level locking system with heartbeat. Automatic conflict detection. Multiple users work simultaneously on different modules.

Multi-account & Roles

JWT authentication with strong passwords. Session management and automatic action attribution in the audit log.

Contractual guarantees

Deployment on your infrastructure (Express.js or PHP). SLA, support and maintenance according to your requirements. Data never externalized.

Continuous updates

New features, frameworks and fixes deployed regularly. Backward compatibility guaranteed with your existing data.

Server mode · Multi-entity

A partitioned ISMS per site or entity

Manage several entities — subsidiaries, sites, business units — in a single installation. Data partitioned per sub-entity, a consolidated view for the parent company, per-section rights.

Partitioning + consolidation

Each entity its own space, management its overview

Each sub-entity keeps its own risks, actions, controls and audits. The parent company consolidates in one click and enforces a common frame (framework, scoring scales).

  • Strict data isolation per partition, enforced server-side
  • Per-section rights (none / read / write) via reusable profiles
  • Consolidated group view, with the source entity on every row
  • Per-entity SSO default and backup of all partitions
Explore multi-entity →
Server mode · AI access

Your ISMS, queryable by your AI

Open read-only access to your governance data for an AI assistant, through MCP — the interoperability standard for assistants. Ideally an AI hosted on your own infrastructure, or sovereign.

Read-only · Revocable tokens

Ask the question, the AI reads your real data

“Which critical risks have no action plan?”, “Where does my NIS2 maturity stand, function by function?” — no more copy-paste or manual exports: your assistant works on up-to-date data, within its scope.

  • Structurally read-only: no assistant can modify your data
  • Personal, expirable and revocable tokens — the account's entity scope is enforced
  • Access log; activation and tokens recorded in the security audit trail
  • Shared responsibility: we secure application access, you control network exposure
See how it works →
AI access (MCP) activation panel in the settings
Action plan

Track your remediation actions end-to-end

A complete action plan to drive compliance. Each action is linked to the controls, risks, audits or non-conformities that generated it.

Full tracking

Manage each action from creation to closure

From opening to closure, each action is tracked with its status, priority, owner and deadline. Dashboard KPIs reflect progress in real time.

  • Statuses: Open, In Progress, Completed, Postponed, Rejected
  • Priorities, owners, deadlines and progress rates
  • Direct link to ISO 27002, NIS2 controls and risks
  • Dashboard KPI: percentage of completed actions
Comparison

Cyber Assistant vs CISO Assistant

Two different approaches. CISO Assistant requires server infrastructure and DevOps skills. Cyber Assistant works directly in your browser, without any dependencies.

Criteria
Cyber Assistant
CISO Assistant
Installation
Open index.html
Docker + Python
Data sovereignty
100% local
Server required
Offline mode
Native
No
IT skills required
None
DevOps / Admin sys
ISO 27001/27002 compliance
Native (93 controls)
Via frameworks
Dedicated NIS2 program
Budget, milestones, pillars
Partial
Budget management
Per NIS2 action
No
Public sector adapted
Built for
Generic
Cross-framework mapping
Heatmap + list
Basic
Impact matrices
NIST + PESTEL + EBIOS
No

CISO Assistant is an excellent tool for organizations with IT teams. Cyber Assistant is for structures that prioritize data sovereignty and operational simplicity.

Governance & Compliance

Drive your compliance over time

From NIS2 to ISO 27001, Cyber Assistant covers key frameworks and structures roles for effective governance.

NIS2 Roadmap

1
2026

Gap analysis & initial action plan

2
2027

Implementation of priority controls

3
2028

Full compliance & audit

Ready-to-use frameworks

Everything below ships in the current version — nothing is «coming soon». Native frameworks are built into the tool; cross-mappings are generated by the mapping engine.

ISO 27001 Natively built in

Complete management system with document review

ISO 27002 Natively built in

93 Annex A controls with CMM assessment

NIS2 Natively built in

Dedicated program with phases, budget and radar

CyFun CCB Natively built in

Belgian framework (CCB) natively integrated

ReCyF ANSSI Natively built in

French framework (ANSSI) natively integrated

DORA Cross-mappings

Digital resilience for the financial sector

PCI DSS Cross-mappings

Payment card data security

A tool for every role

CISO

Strategic ISMS management, board reporting, risk analysis

DPO

GDPR compliance, data protection, processing register

Management

Executive dashboard, KPIs, NIS2 budget tracking

Teams

Operational actions, control tracking, documentation

Gallery

An application for all security managers

Clean design, intuitive navigation, clear information. Everything is made to save time.

1 Cyber Assistant ISMS Dashboard - Executive summary with cybersecurity KPIs

ISMS Dashboard

Executive summary view with KPIs and maturity charts.

2 ISO 27002 and NIS2 controls management - Operational ISMS management

Operational management

Manage controls, risks and actions from a unified interface.

3 Cyber Assistant collaborative mode - Simplified sharing for cybersecurity teams

Simplified sharing

Optional web hosting to collaborate with stakeholders.

4 ISMS document structure - ISO 27001 pyramid with evidence and audit deliverables

Document structure

Complete ISO pyramid with links to evidence and deliverables.

5 Cyber Assistant modern interface - Clean design with light and dark themes

Modern design

Clean interface with light, dark and Poudre themes.

6 Detailed list view of ISO 27002 ↔ CyFun 2025 mapping

Cross-framework mapping

Correspondences between ISO 27002 and CyFun 2025 with detailed coverage.

7 Impact matrices — PESTEL, NIST SP 800-30 and EBIOS RM

Impact matrices

Multi-dimensional assessment using NIST SP 800-30, PESTEL and EBIOS RM.

8 Action plan — Remediation action tracking

Action plan

Remediation action tracking with priorities and deadlines.

Audit Trail

Every action is automatically tracked

A comprehensive audit log records every creation, modification and deletion across all application modules. Total transparency for your internal audits and regulatory compliance.

Audit log

18 traceability categories covering all modules

From ISO controls to NIS2 actions, every operation is timestamped and automatically attributed. Filter by action type, search by element, and export the complete history.

  • Controls, risks, actions, documents, KPIs, audits, NIS2…
  • Filter by action type and search by target
  • Automatic user attribution (local or authenticated)
  • Dashboard integration with the 10 latest entries
Ils en parlent

Pourquoi ils choisissent Cyber Assistant

Accessible, souverain, abordable : ce que retiennent les RSSI, DPO et CISO qui l'ont comparé aux outils GRC classiques.

AccessibleSouverainAbordable
★★★★★

« Plus accessible que Monarc. »

Conseiller Sécurité de l'information — Administration publique
★★★★★

« Correspond bien mieux à nos besoins que CISO Assistant. »

Responsable sécurité — Secteur industriel
★★★★★

« La souveraineté des données était non négociable : ici, tout reste chez nous. »

CISO — Opérateur public (entité essentielle NIS2)
★★★★★

« Zéro installation, on a démarré en quelques minutes. »

RSSI — Conseil & audit
Recommended by CCB experts — Centre pour la Cybersécurité Belgique

Keep control of your sensitive data

Your risk registers and continuity plans deserve a solution that respects their confidentiality. Cyber Assistant runs entirely locally — no data ever leaves your organization.

Pricing

Buy it once. It stays yours.

A purchase that's easy to defend before an executive committee: you pay once, the license is perpetual — no subscription, no imposed recurring cost.

Free for life

Community Local

Individual use — Offline local mode

Open source No account required, zero installation
  • 100% offline in your browser
  • Open NIS2 frameworks: CyFun (BE) & ReCyF (FR)
  • Zero install — just open the HTML file
  • Risk analysis, action plans, audits, KPIs
  • ISO 27001 & 27002 standards not included
  • No collaborative mode

Start right now, locally — then move up to Corporate Locale or Server anytime; your data follows you, no starting from scratch.

Download for free Installation guide

Corporate Server ISO

Multi-user collaborative

7 900 € one-time payment · excl. VAT · perpetual license No subscription — you only pay once

Everything in Corporate Local, plus:

  • Real-time co-editing with tab locking
  • Up to 100 collaborators co-editing — roles & audit trail
  • Multi-entity included — up to 50 sub-entities from one instance
  • 1st year of support & updates included
  • Deployed on your infrastructure — your data stays with you
  • All Corporate Local features included
  • Enterprise SSO (OIDC) — Azure AD, Google Workspace, Okta, Keycloak
  • Read-only AI access (MCP) — off by default, opened by the administrator
Voir le détail

* ISO 27001 and ISO 27002 standards are copyrighted documents. Their integration in Corporate versions requires the user to provide proof of a valid purchase license from ISO or a national standards body.

Need support? Training, deployment assistance and customizations available on request.

Already on Corporate Local? Upgrading to the Server edition is possible — your existing data is carried over. Write to us for the details.

Tailored

Three editions. And one setup that looks like you.

Cyber Assistant ships in three editions — free local, local ISO, collaborative server. Then it is tuned to your organisation: your sections, your needs, your colours, your methodology. No two organisations run their ISMS the same way.

Edition 1 — Local

Community Local

One file, your browser, and you are running. No cloud, no install, no account to create. Ideal to get started and prove the value internally.

Edition 2 — Local ISO

Corporate Locale ISO

The same tool, extended with the official ISO 27001 and 27002 standards and the trilingual interface. Still offline, still on your own machine.

Edition 3 — Server

Corporate Server ISO

The whole team on a single shared base: co-editing, roles, audit log, SSO, multi-entity. Deployed on your infrastructure, not ours.

No cloud does not mean no server. No data ever leaves for a third-party host — that is what "no cloud" means. The Server edition does exist — but it runs on your server, behind your firewall, under your administration.

And then we fit it to your context

An ISMS cannot simply be dropped onto an organisation: it has to adopt its vocabulary, its priorities and its established practices. That is where the tailoring work begins.

Your sections

Rename, reorder, hide: the tool speaks your organisation's vocabulary. A section can be renamed, moved up the menu, or removed entirely if it serves no purpose for you.

Your needs

Public administration, private company, multi-site group: everyone has different priorities. If NIS2 matters more than ISO in your organisation, the tool is reorganised accordingly — fields, statuses, indicators and exports follow your processes, not generic ones.

Your colours

Logo, palette, themes: the interface carries your visual identity. Reports and exports come out in your own colours, ready to present to the board.

Your methodology

Your rating scale, your risk matrix, your analysis method, your own take on the ISMS. If you already have an in-house method that works, the tool bends to it — your teams do not have to relearn their own.

Every deployment starts with a scoping session: we look at how you actually work, then we adjust. Tell us what, in your organisation, fits no standard box.

See the 3 editions in detail Discuss your context