Certatix

ISO 27001:2022 · NIS2 · DORA

Your compliance, kept like a ledger.

Certatix takes your organisation from the statement of applicability to the audit file: 216 controls preloaded across 3 frameworks, a maturity level that is computed, evidence attached to every question, a dated version to hand to the auditor.

See pricing

European hosting · Google or Microsoft sign-in · two-factor authentication for everyone.

62%
Audit readiness38 of 61 applicable controls at their target+7 pts over 30 days
  • A.52.4 / 3.0
  • A.63.1 / 3.0
  • A.71.8 / 3.0
  • A.82.2 / 4.0
  • A.8.16Monitoring activitiesCritical1 / 4
  • A.5.30ICT readiness for business continuityCritical0 / 3
preloaded controls, across three frameworks
216

preloaded controls, across three frameworks

audit questions, each traceable to a piece of evidence
1,324

audit questions, each traceable to a piece of evidence

maturity level, computed rather than declared
0 – 4

maturity level, computed rather than declared

interface and audit file in four languages
FrançaisEnglishDeutschEspañol

interface and audit file in four languages

The method

Four steps, in this order, all the way to your auditor

  1. 01

    Decide applicability

    Applicable, not applicable, to determine — one control at a time or in bulk. Every exclusion requires a written rationale: that is the first thing an auditor opens.

  2. 02

    Answer the questionnaire

    Questions in plain language, theme by theme. Everyone fills in their own domain; the maturity level follows from the answers, nobody rates themselves.

  3. 03

    Link the evidence

    Each piece of evidence is a link to your own document, attached to the question it proves. You see at once what is missing and who to ask.

  4. 04

    Generate the audit file

    A dated, frozen version including the SoA, shareable read-only with your auditor. The change history stays available.

For a company

Everyone their own domain, one figure for the board

  • Tailored roles: who fills in what, who validates, who sees nothing
  • Leadership follows progress from a phone
  • An audit trail on every change of status or evidence
Company plans

For a consultancy

All your clients, one workspace

  • Client portfolio, dated engagements, assigned consultants
  • Step into a client without switching accounts, with a standing banner
  • The client stays in control: they accept the engagement and can end it
Consultancy plans

One foundation, several frameworks

The mechanics — applicability, maturity, evidence, audit file — do not change from one framework to the next. You pick the framework at the top of the screen; your evidence and your roles stay in place.

  • ISO 27001:202293 controls, 4 themesAvailable
  • NIS259 controls, including the 10 measures of Article 21Available
  • DORA64 controls, operational resilience for the financial sectorAvailable

What we do not store

  1. 01

    No passwords. You sign in with your company’s Google or Microsoft account; there is nothing to steal from us.

  2. 02

    No card details. Payment happens on our provider’s hosted pages, never on Certatix.

  3. 03

    No evidence files. Your documents stay where they are: Certatix keeps only the link. Two-factor authentication is mandatory for everyone from the first sign-in, and every organisation is strictly partitioned.

Open your workspace and start assessing the same day.

The controls of all 3 frameworks are already there. All you have to do is start deciding.