For certified companies

Stay audit-ready,
without the yearly scramble.

devguard keeps your ISMS audit-ready year-round, so the surveillance audit is a check, not a two-week fire drill. Whether you’re earning your first certificate or keeping the ones you have, the gap list is visible months out, not the week before. Swiss-hosted, German and English, on-prem possible. If you’re moving off another tool, we migrate your existing ISMS across ourselves, at a fixed price on a fixed date.

Book a conversation
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after — the spreadsheet sprawl, the evidence you reassemble from memory the week before an audit, the client (or control) you haven't looked at since last cycle. That's the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
Year over year
audit-readyYear 1Year 2Year 3
Point-in-time tools — scramble & drift
devguard — a state you keep
From scramble to a state you keep

How you stay ready between audits.

Set your frameworks up once, then keep them audit-ready through the same loop: coverage, reviews, audits, policies and the reports you hand the auditor.

Coverage

See the gaps months out

Control coverage per framework moves from unknown to partial to full as each control maps to the policies, assets and risks that satisfy it. An open gap shows up months before the surveillance audit, not the week of it.

Coverage per framework: unknown, partial, full
Gaps surfaced by control, not found late
app.devguard.ch / coverage
63 / 93 controls
68%
controls covered
ISO 2700184%
SOC 271%
GDPR49%
Reviews

Reviews that don’t sneak up

Asset, risk and vendor reviews each run draft to in-progress to completed, with findings, recommendations and the next review date set on completion. A deadlines view surfaces what’s due early, so the cadence holds across the year instead of bunching before the audit.

Asset, risk and vendor reviews on a cadence
Next review date set the moment one closes
app.devguard.ch / deadlines
3 upcoming
Next: access review · in 5 days
JUL03Access reviewin 5 days
JUL21Risk review · Q3in 3 weeks
AUG14Vendor reassessmentin 6 weeks
Audits

Findings tracked to closure

Log audit findings with their root cause and corrective measure, each with its own deadline, and carry every non-conformity through to closed. When the auditor returns, the state of the last cycle is something you show, not reconstruct.

Root cause and corrective measure per finding
Non-conformities carried to closed
app.devguard.ch / audits
internal audit
ISO 27001 internal audit · Q2
Access controlsA.5.15
Backup & recoveryA.8.13
Use of cryptographyreviewing
Supplier securityA.5.19
3 findings carried to closure
Policies

Versioned policies with an approval trail

Author your policies in devguard, then move them draft, needs-approval, published, with the full version history kept. The auditor sees the current policy and the approval standing behind it, without you digging through email.

Draft to needs-approval to published
Full version history per policy
app.devguard.ch / policies
12 published
PolicyVerStatus
Access control policyv2.1Published
Data retention policyv1.3Published
Encryption policyv0.9Needs approval
Reports

Ten reports you hand over

Generate the documents an auditor expects as PDFs, including the Statement of Applicability, plus audit, risk, asset, vendor, policy and review reports. The artifact you hand over is produced from the live workspace, not assembled by hand the night before.

Statement of Applicability as a report
Ten PDF report types, on demand
app.devguard.ch / reports
10 report types
Generated as PDF, on demand
Statement of ApplicabilityPDF
Risk assessment reportPDF
Vendor risk reportPDF
+ audit, asset, policy and review reports
What makes us different

Four things we mean literally.

Not a metrics wall (we're early; we won't invent numbers). The differentiators we can stand behind today:

01

Continuous, not point-in-time

Reviews run on a cadence and gaps surface early, so readiness is a state you hold across the year, not a sprint before each audit.

02

Native, no bolt-ons, one clear price

The ISMS core is the product. Policies, reviews, audits and reports are one workspace, not a separate invoice each.

03

Swiss-hosted, on-prem possible, no lock-in

You control where your evidence sits, in German and English, and it exports in full whenever you ask.

04

The artifacts an audit expects

Versioned policies, tracked findings and ten report types including the Statement of Applicability, in the shape an audit expects.

Straight talk

Where the line sits.

You run your ISMS and keep it audit-ready in the workspace. If you’re moving off another tool, the first migration is work we do for you. Here’s exactly what’s self-serve and what the conversation adds — no number on the page, because the right price depends on your setup and we work it out together.

The workspace, self-serve
  • Coverage, reviews, audits, policies and ten report types
  • A deadlines view so review cycles never bunch before an audit
  • Your data exportable to CSV and PDF, any time, no lock-in
  • Swiss-hosted, German and English, on-prem possible
The conversation adds
  • We hand-migrate your existing ISMS into devguard
  • A fixed price and a fixed date for that move
  • A price worked out for your framework mix
  • A direct line to the founder running the migration
Residency your auditor can check.

Hosted in Switzerland by default, on-prem possible, German and English throughout — so when a customer or auditor asks where your compliance evidence sits, you have a precise answer. Your data exports in full, any time.

See the full feature comparison

How we start

We move your ISMS across, by hand.

No empty workspace handed over. If you’re switching from another tool, we migrate your existing ISMS into devguard ourselves, on a fixed scope and a fixed date, and nothing is switched over until you’ve checked it side by side. Then you run from there, and your data exports in full whenever you want it.

01 · Fixed scope

We scope the move together

We agree exactly what the migration covers, which frameworks and how much evidence, so the engagement isn’t open-ended.

02 · Founder-run

We migrate it for you

The founder moves your ISMS from wherever it lives today, whether another tool, spreadsheets, Word or Confluence, on an agreed schedule, not a ticket queue.

03 · You verify, then run

Nothing switches until you sign off

You check the auditor-facing trail side by side. When you’re satisfied it’s intact, you’re live and you run from there.

Book a conversation
Certified companies FAQ

The questions teams actually ask.

We’re already certified on another tool. Can you migrate it?

Yes. We take your existing ISMS, wherever it lives today, whether another tool, spreadsheets, Word or Confluence, and move it into devguard ourselves, at a fixed price on a fixed date. Nothing is switched over until you’ve reviewed it side by side and you’re satisfied the auditor-facing trail is intact.

We’re going for our first certificate. Can devguard help?

Yes. devguard is the ISMS whether you’re earning your first certificate or keeping the ones you have. Coverage shows what each framework still needs, policies and reviews give you the trail, and the reports are the documents an auditor expects. We won’t put a date on your certification, that’s between you and your auditor, but the workspace is the same one certified companies use to stay ready year-round.

What do we hand the auditor?

Ten PDF report types generated from the live workspace, including the Statement of Applicability, plus audit, risk, asset, vendor, policy and review reports. You produce them on demand instead of assembling documents by hand the week before the audit.

How does it keep us ready between audits?

Asset, risk and vendor reviews run on a cadence, each with its next review date set on completion, and a deadlines view surfaces what’s due early. Control coverage per framework shows open gaps months out, so the work spreads across the year instead of bunching before a surveillance audit.

Where does the data live, and can it run on-prem?

Hosted in Switzerland by default, in German and English. On-prem is possible, so your data residency stays under your control — which matters when a customer or auditor asks where your compliance evidence sits.

What happens to our data if we leave?

No lock-in by design. Your policies, evidence and review history export to CSV, and your reports to PDF, whenever you want. The export is part of the product, not a favour you have to ask for.

Let’s talk about staying audit-ready.

A 15-minute conversation, not a sales demo. How your ISMS works today, whether devguard fits, and what moving it across, or earning a first certificate, would look like.

Book a conversation
Sign in
Start for free
Book a conversationStart for free