devguard - Your Compliance Platform
PlatformSolutionsFrameworksDevelopersPricing
devguard

One workspace for your whole ISMS — Swiss-hosted, one control set, mapped to every framework you run.

All systems operational
Product
PlatformFeaturesSolutionsFrameworksPricing
Developers
API & CLIIntegrationsDocumentationChangelogSwiss hosting
Company
AboutBlogCompare
© 2026 devguard AG. All rights reserved.
Terms of servicePrivacy policySite noticeTrust centerLLM info
Swiss Made Software
Trainings

Assign the training,
keep the record per person.

Point a training at material you already have, a video, a link to your LMS, or a PDF you upload. Attach an assignment and it gets an audience, a first due date and a frequency. Reminders reach the people who owe it, and each completion records who attested to what, on which date, against which source. Completion is self-attestation, and the record says exactly that.

++++
app.devguard.ch / portal / trainings
Annual · due Mar 31
This cycle
18
of 24 completed
Completed75%
Pending05
Overdue01
Next reminder in 12 days
Security awareness 2026 · 22 min
14:5222:00
01Phishing and social engineering6 min
02Passwords and MFA5 min
03Reporting an incident7 min
04Working on the move4 min
I have completed this trainingMark as completed
Recorded as J. Lee · Mar 11 · against source v3
Every framework
How it works

Registered, assigned, attested.

A training points at material you already have, an assignment gives it an audience and a cadence, and each person attests when they have worked through it.

01

Point at the material you already have.

A training carries a title, a description, an owner role and a duration in minutes. Its content is a YouTube or Vimeo video played inline, an external link that opens your LMS or a vendor’s portal in a new tab, or a PDF you upload, served through a time-limited download link rather than a public URL.

The owner is a business role, the security team, HR or the CISO, never a named individual. People come and go from roles, and the accountability stays put.

02

Attach an assignment and it goes live.

A training does nothing until you attach an assignment: an audience, a first due date, and a frequency of one-off, monthly, quarterly, semi-annual or annual. A training has at most one assignment, and a recurring one generates a series of due dates without storing anything per cycle, so changing the frequency reshapes the whole series instead of leaving orphaned dates behind.

The audience resolves live.

An audience is the union of named members and selected business roles, resolved live rather than frozen when you saved it. Add somebody to the engineering role and they are enrolled in every assignment that targets it, take them out and the obligation goes with them. Archiving a role has the same effect as emptying it.

03

People complete it, you see who hasn’t.

Assigned people work in the employee portal, a portal-only seat that needs no main-app license. They see the material, work through it, tick that they have completed the training and mark it as completed. The assignment card then shows completed, pending and overdue counts, and lists every person with their status and last completion date.

Why it’s built this way

Built around the record it produces.

Four choices behind how trainings work here — each one something you can check, not an adjective.

01

Points at the material you already have.

A training is a YouTube or Vimeo video played inline, an external link that opens your LMS or a vendor’s portal, or a PDF you upload, served through a time-limited download link rather than a public URL. Nothing has to be rebuilt inside devguard for the obligation and the record to exist.

02

The audience resolves live, not at save time.

An audience is named members plus business roles, resolved at the moment it is read. Adding someone to the engineering role enrolls them in every assignment targeting that role, removing them takes the obligation away, and archiving a role does the same as emptying it.

03

Self-attestation, and the record says so.

devguard records that a named person stated they worked through the material, on a date, for that cycle, against the source they were shown at the time. It does not check that a video played to the end. Trainings are unversioned, so that snapshot is what makes a two-year-old completion still say exactly what that person was given, even after you swap the video.

04

Reminders that stop when they should.

Four triggers: enrollment, ahead of the due date, a final nudge on the last day, and overdue. The first nudge scales with cadence, 30 days ahead of an annual training and 3 days ahead of a monthly one. Anyone who has completed the current cycle stops hearing about it, nothing goes out twice for the same cycle, and several items falling due together arrive as one email.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

One module of the platform

Where trainings connect.

A training shares its assignment machinery with policies, its proof with evidence, and its open cycles with the deadline calendar.

FAQ

The questions evaluators ask.

What counts as a completion?

A person confirms they have completed the training and marks it as completed. devguard records that they stated so, on a date, for that cycle, against the source they were shown at the time. It does not check that a video played to the end. If you want harder proof, file it on the Evidence tab: an attendance export from your LMS, a signed sign-off sheet, quiz results.

Do I have to build the training content in devguard?

No, and devguard ships none of its own. A training points at material you already have: a YouTube or Vimeo video played inline, an external link that opens an LMS course or an intranet page in a new tab, or a PDF you upload, served through a time-limited download link rather than a public URL.

How do recurring trainings work, and what happens when someone joins or leaves a role?

An assignment repeats one-off, monthly, quarterly, semi-annually or annually. Each due date is a cycle, and a completion is recorded against the cycle it satisfies. Nothing is generated in advance, so changing the frequency reshapes the whole series instead of leaving orphaned dates behind. The audience resolves live, so joining a role picks up every assignment aimed at it, and leaving drops the obligation and its reminders.

How is this different from an LMS or a training spreadsheet?

It sits next to the rest of your ISMS. An LMS delivers material and a spreadsheet holds dates, but neither carries the obligation, the cycle, the per-person status, the reminder trail and the proof in the same place as your controls. So an auditor following a control down to its evidence lands on the same attendance export you filed here, and you keep the LMS you already have.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Select any trainings in the list and export them to CSV, and your completion history is yours and exportable in full at any time, with no lock-in. Archiving keeps a training, its assignment and its completion history intact while taking it off the active register.

Show who completed what, and when they did.

Register the trainings you already run, give each one an audience and a cadence, and let the reminders do the chasing while the dated per-person record builds itself.

Start for free
Book a conversation
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
See the full feature comparison
policyv1.3
access_control {
require mfa = true
}

Policies

Assigned the same way, completed by acknowledging.

342
artifacts captured
linked to controls

Evidence

Attendance exports and sign-off sheets, linked to controls.

JUN
ISO review
in 3 days

Deadlines

Each open training cycle as a dated item on the calendar.

TSK-012Document backups
TSK-013Access review
TSK-014Scope statementFri

Tasks

Refresh the material, chase the people still overdue.

Start for free
Book a conversation
Sign in
Start for free
Book a conversation
Start for free