Skip to content
deveca GRC
Compliance

Frameworks. Fully integrated.

ISO 27001, ISO 27701, TISAX, NIS2, BSI IT-Grundschutz, GDPR, HinSchG and the Cyber Resilience Act — mappings, templates and workflows in deveca. Combine them freely, or use each one on its own.

ISO/IEC 27001:2022

ISO 27001 with deveca GRC

Build your information security management system along the current ISO/IEC 27001:2022. Full Annex A mapping (93 controls), statement of applicability, risk management, awareness and an audit programme — audit-ready, without Excel.

Learn more

ISO/IEC 27701

ISO 27701 as an extension of your ISMS

ISO 27701 extends your ISMS with privacy controls (PIMS) and bridges ISO 27001 and the GDPR. deveca provides the full mapping, including processing activities, data-subject rights and subprocessors.

Learn more

TISAX · VDA ISA

TISAX with deveca

TISAX is mandatory for automotive suppliers — and a nightmare in Excel. deveca walks you through the current VDA ISA, with maturity ratings, action tracking and auditor-ready reports. Usable without ISO 27001.

Learn more

NIS2 Directive · German NIS2 implementation act

NIS2 compliance without the headache

NIS2 obliges tens of thousands of companies to manage risk, notify incidents (24h/72h), secure the supply chain and document management responsibility. deveca provides a ready cockpit — including incident notification, action tracking and evidence.

Learn more

BSI Standards 200-1, 200-2, 200-3

BSI IT-Grundschutz with deveca

Structure analysis, protection-needs assessment, modelling, basic, standard and core protection — deveca guides you through the full BSI IT-Grundschutz lifecycle, including the current compendium.

Learn more

GDPR · German BDSG

Live the GDPR — don't just document it

Records of processing, TOMs under Art. 32, data protection impact assessments, processor contracts with subprocessors, data-subject rights as a workflow and 72-hour breach notification — all in deveca.

Learn more

HinSchG · EU Whistleblower Directive

The German Whistleblower Protection Act — done properly

More than “ready”. deveca delivers a complete reporting portal with anonymous two-way communication, encrypted attachments, a case file, investigation records, deadline monitoring and action tracking — multi-tenant for groups.

Learn more

EU Regulation 2024/2847

EU Cyber Resilience Act – CRA ready

The CRA requires manufacturers of connected products to apply security by design, vulnerability management, SBOMs and vulnerability disclosure. deveca brings CRA conformity into your software lifecycle — including SBOM management (CycloneDX/SPDX) and CVSS/CWE scoring.

Learn more