Frameworks. Fully integrated.
ISO 27001, ISO 27701, TISAX, NIS2, BSI IT-Grundschutz, GDPR, HinSchG and the Cyber Resilience Act — mappings, templates and workflows in deveca. Combine them freely, or use each one on its own.
ISO/IEC 27001:2022
ISO 27001 with deveca GRC
Build your information security management system along the current ISO/IEC 27001:2022. Full Annex A mapping (93 controls), statement of applicability, risk management, awareness and an audit programme — audit-ready, without Excel.
Learn moreISO/IEC 27701
ISO 27701 as an extension of your ISMS
ISO 27701 extends your ISMS with privacy controls (PIMS) and bridges ISO 27001 and the GDPR. deveca provides the full mapping, including processing activities, data-subject rights and subprocessors.
Learn moreTISAX · VDA ISA
TISAX with deveca
TISAX is mandatory for automotive suppliers — and a nightmare in Excel. deveca walks you through the current VDA ISA, with maturity ratings, action tracking and auditor-ready reports. Usable without ISO 27001.
Learn moreNIS2 Directive · German NIS2 implementation act
NIS2 compliance without the headache
NIS2 obliges tens of thousands of companies to manage risk, notify incidents (24h/72h), secure the supply chain and document management responsibility. deveca provides a ready cockpit — including incident notification, action tracking and evidence.
Learn moreBSI Standards 200-1, 200-2, 200-3
BSI IT-Grundschutz with deveca
Structure analysis, protection-needs assessment, modelling, basic, standard and core protection — deveca guides you through the full BSI IT-Grundschutz lifecycle, including the current compendium.
Learn moreGDPR · German BDSG
Live the GDPR — don't just document it
Records of processing, TOMs under Art. 32, data protection impact assessments, processor contracts with subprocessors, data-subject rights as a workflow and 72-hour breach notification — all in deveca.
Learn moreHinSchG · EU Whistleblower Directive
The German Whistleblower Protection Act — done properly
More than “ready”. deveca delivers a complete reporting portal with anonymous two-way communication, encrypted attachments, a case file, investigation records, deadline monitoring and action tracking — multi-tenant for groups.
Learn moreEU Regulation 2024/2847
EU Cyber Resilience Act – CRA ready
The CRA requires manufacturers of connected products to apply security by design, vulnerability management, SBOMs and vulnerability disclosure. deveca brings CRA conformity into your software lifecycle — including SBOM management (CycloneDX/SPDX) and CVSS/CWE scoring.
Learn more