Deadlines

Every date that matters,
none of the surprises.

Every review, renewal and finding due in the next 30 days on one calendar, derived from the work you already track, from risk, asset and access reviews to audit findings, treatment actions and vendor reassessments. Subscribe to the calendar feed and your own calendar app reminds you before each date is due, so nothing you have to act on quietly lapses.

Start for freeBook a conversation
++++
app.devguard.ch / deadlines
3 upcoming
JUNE 2026
MTWTFSS1617181920212223242526272829
Next: ISO review · in 3 days
Upcoming
JUN24
ISO 9.3 management review
Owner · J. Doe
in 3 days
JUL03
Quarterly access review
Owner · A. Klein
in 2 weeks
AUG21
SOC 2 surveillance renewal
Owner · M. Rossi
in 2 months
SEP18
Annual penetration test
Owner · T. Schmid
in 3 months
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Derived, in view, subscribable.

Dates are derived onto one calendar from the work you already track, the next 30 days shown, with a feed your own calendar can subscribe to.

01

Dates are derived on their own

As you work, due dates flow onto one calendar: a risk review’s deadline, an asset retention date, an audit finding’s closure, a vendor reassessment. You don’t keep a separate list; the list is the work.

02

The next 30 days, in view

The calendar shows what’s due in the next 30 days, a hard cap. Anything further out stays off the view until it comes within range, so what you’re looking at is what you can act on now.

03

Your calendar reminds you

Subscribe to the iCalendar (.ics) feed and your deadlines land in your own calendar, each event carrying an alarm your calendar app fires before the date is due. devguard emails you as well, ahead of the date and again the day before, so a reminder reaches you even when you are nowhere near the calendar.

Reminded in the tool you already live in

Because the feed flows into the calendar you already check, an upcoming date surfaces where you’ll see it, and no renewal becomes a last-week scramble.

Why it’s built this way

One calendar, fed by the work.

Four choices behind how deadlines work here — each one something you can check, not an adjective.

01

Derived from reviews, findings, vendors and actions

Deadlines are derived from risk, asset and access reviews, audit findings, treatment actions, asset retention and vendor reassessments. You don’t re-enter dates you’ve already set on the work.

02

The next 30 days, in view

The calendar shows what’s due in the next 30 days, a hard cap, so the view stays the things you can act on now instead of a wall of far-off dates.

03

Reminded by email, and in your own calendar

An email reaches you a week ahead of a date, again the day before, and once if it slips, never twice for the same point. Recurring training and policy assignments follow their own cadence instead, up to a month ahead of a yearly one. Subscribe to the iCalendar feed as well and every date also lands in your own calendar with an alarm.

04

Everything due, on one calendar

Reviews, renewals and findings sit on a single calendar, so nothing important lives only in one person’s memory or one team’s spreadsheet.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where deadlines come from.

A deadline isn’t typed in by hand — it’s a date that already lives on a review, an audit, a vendor or an action, surfaced here so it can’t slip.

Internal audit00:42
Access controls
Backup & recovery
Incident response

Audits

Surface each finding’s closure date before it slips.

AWAWSReviewed
CFCloudflareReviewed
StStripe

Vendors

Surface every vendor reassessment before it’s overdue.

2.0SCORE

Risks

Bring each risk and treatment review onto the calendar.

EventPR merged
ActionEvidence captured

Actions

Bring each treatment action’s due date onto the calendar.

FAQ

The questions evaluators ask.

Where do deadlines come from — do I enter them?

Mostly they pull in on their own. A risk, asset or access review, an audit finding, a treatment action, an asset retention date or a vendor reassessment already carries a date, and that date surfaces here automatically. You’re not keeping a separate list in parallel with the work.

How do reminders work?

Both by email and in your own calendar. devguard emails you ahead of each date, again the day before, and once if it goes overdue, never twice for the same point, and each category has its own setting in your notification preferences: as it happens, gathered into one weekly digest, or off. You can also subscribe to an iCalendar (.ics) feed of your deadlines, where every event carries an alarm your own calendar app fires. The view itself shows what’s coming up in the next 30 days.

What kinds of dates show up here?

Reviews (risk, asset, access), audit findings, treatment actions, asset retention dates and vendor reassessments — the recurring review and renewal dates an ISMS has to keep, in one place. Anything due more than 30 days out stays off the view until it’s within range.

How is this different from a spreadsheet or another GRC tool?

A spreadsheet of dates goes stale the moment the underlying work changes, and someone has to remember to look at it. Here the dates are derived from the reviews, findings, vendors and actions you already track, so the calendar stays current without anyone maintaining it.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. You can subscribe to an iCalendar (.ics) feed of your deadlines and take them into your own calendar, so there’s no lock-in.

Never let a date sneak up again.

Put every review, renewal and finding due in the next 30 days on one calendar, derived from the work you track, and subscribe to the feed so your own calendar reminds you before anything lapses.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free