Skip to main content
Complete platform

Everything you need to run resilience, risk, and compliance

9 functional domains, 60+ integrated features, 36 native risk methodologies — the richest BCMS + GRC platform on the European market.

67
Features
36
Risk methodologies
8
Plan types
9
Regulatory frameworks

Business Continuity Management

Everything needed to implement, certify and operate an ISO 22301 BCMS at scale.

Live

Business Impact Analysis (BIA)

Collaborative BIA with 8 impact dimensions, RTO/RPO/MBCO auto-computation, dependency mapping, department questionnaires.

Learn more

8 plan types library

BCP, BRP, DRP, IRP, ERP, CMP, CCP, SRP — each preconfigured per ISO 22301 with templates, versioning, approval workflow.

Included

Mobile Reflex Cards

Quick-reference action cards pushable to crisis team mobile devices in seconds when minutes matter.

Included

Tabletop Exercises

40+ scenario library, injection generator, timeline tracking, roles & observers, post-mortem template.

Learn more

Dependencies cascade

Visual graph from business processes → applications → infrastructure → suppliers. One-click impact analysis on failure.

Included

BCMS Maturity Assessment

Self-assessment against ISO 22301 with benchmark vs peers in the same sector / size bracket.

Included

Stress Tests Engine

Plan-level stress testing with parameterized scenarios (cyber, physical, supply chain, regulatory).

Included

Emergency Operations Center

Digital EOC with real-time dashboards, decision logging, multi-location coordination, public-private interface.

Included

Business Processes mapping

BPMN 2.0 diagrams, ownership, criticality rating, SLA tracking — linked to BIAs and plans.

Included

Risk Management

36 risk methodologies natively supported — the widest catalog on the market.

Live

36 methodologies

FAIR, EBIOS RM, ISO 27005, Bow-Tie, FMEA, HAZOP, COSO ERM, NIST 800-30, MEHARI, OCTAVE, RBA, VaR, TCFD, PESTEL, HRA...

Learn more

FAIR + Monte Carlo

Quantitative risk analysis with built-in Monte Carlo engine (10k+ iterations), loss distribution curves, expected loss.

Included

EBIOS RM (ANSSI)

Full 5-workshop methodology: scoping, risk sources, strategic scenarios, operational scenarios, risk treatment.

Included

Bow-Tie Analysis

Threat → top event → consequences visualization with preventive and reactive barriers + effectiveness rating.

Included

HAZOP / FMEA

Industrial-grade hazard identification, failure mode analysis with RPN scoring, cross-linked to BIAs.

Included

VaR / CVaR quantitative

Value at Risk + Conditional VaR with historical, variance-covariance and Monte Carlo approaches.

Included

TCFD climate scenarios

Physical and transition risk under RCP 4.5 / 8.5 and NGFS scenarios. Time horizons 2030, 2050, 2100.

Included

Insider Threat

Structured assessment of employee/contractor malicious or accidental risk with behavior indicators.

Included

Concentration Risk

Vendor, geographic, customer concentration with Herfindahl-Hirschman index + stress testing.

Included

Geopolitical Risk

Country-level ratings (200+ countries), sanction exposure, supply chain cartography, daily news feeds.

Included

KRI / KPI dashboards

Key Risk Indicators with thresholds, alerts, trends. Linked to risks, controls, plans.

Included

Risk Register + Treatment

Enterprise-wide register with accept / mitigate / transfer / avoid tracking, residual risk, action plans.

Included

Compliance & Governance

Multi-framework compliance with cross-mapping, audit trail, and automated evidence collection.

Live

Multi-framework mapping

DORA, NIS2, ISO 22301, ISO 27001, NIST CSF 2.0, CRA, GDPR, CyFun — cross-mapped. One control satisfies many frameworks.

Learn more

2000+ controls library

Pre-mapped controls across all major frameworks with evidence templates, ownership, frequency.

Included

Gap Analysis

Current vs target posture per framework with remediation roadmap, effort sizing, priority ranking.

Included
New

Regulatory Watch

AI-curated feed of regulatory changes with impact analysis on your current controls.

Included

Policies & Document Control

Policy templates library, version control, approval workflows, distribution tracking, acknowledgment logs.

Included

Committees & Minutes

Meeting scheduler, agenda templates, minutes editor, decision tracker, action assignment.

Included

Non-conformities

CAPA workflow (Corrective And Preventive Actions) with root cause analysis, owner, deadline, closure evidence.

Included

Competency Matrix

Employee skills inventory, certifications tracking, training plan alignment with control operator roles.

Included

Complete audit trail

Every CRUD action logged with user, timestamp, before/after diff, IP — for ISO 27001, SOC 2, DORA audits.

Included

AI-Powered Features

AI accelerates analysis, draft generation, and decision support — with EU hosting and audit trail.

Live

AI Analyst

13 industry-specific AI agents generating insights, anomaly detection, board-ready reports from your data.

Learn more
Live

AI Contract Analysis

Upload contract → instant gap report against DORA, NIS2, CRA, ISO 22301, GDPR in < 2 minutes.

Learn more

Crisis Copilot

AI assistant during live incidents: reads context, drafts communications, suggests next actions.

Included

Automated Reports

Board reports, regulator reports, exec summaries generated from your BCMS data in one click.

Included

AI Regulatory Watch

LLM-powered scraping + classification + impact analysis of new EU/national regulations daily.

Included

EBIOS suggestions

AI proposes risk sources, attack paths, missing clauses based on your industry + scope.

Included

CMDB & Supply Chain

Full asset inventory linked to business processes, suppliers, and risks — the foundation for resilience.

IT Assets inventory

Applications, infrastructure, systems, data, facilities — unified view with criticality rating.

Included

Suppliers & third-parties

Tier-1/2/3 supplier registry, criticality, SLA, risk scores, concentration analysis.

Included

Dependencies graph

Interactive visualization: process → app → infra → supplier. Click any node to see upstream/downstream impact.

Included

Vendor Risk Management

40+ question vendor questionnaires, due diligence workflow, re-assessment scheduler, SOC 2 / ISO 27001 evidence collection.

Included

ServiceNow integration

Bi-directional sync of CIs, incidents, changes. Auto-import CMDB assets from ServiceNow.

Included

Jira / Slack / Teams

Push incidents to Slack channels, create Jira tickets for risks, notify Teams during crisis.

Included

Business processes + BPMN

BPMN 2.0 diagrams editor, process ownership, SLA targets, links to BIAs + plans.

Included

Controls implementation

2000+ control library (ISO, NIST, COBIT) — assign to assets, suppliers, processes. Evidence tracking.

Included

Crisis Management

From tabletop to live crisis — gamified training and real-time coordination.

Live

Crisis Gaming

Interactive tabletop exercises with AI injections, decision scoring, multi-team simulation, post-mortem.

Learn more

Scenario library

40+ scenarios: ransomware, natural disaster, supply chain disruption, pandemic, data breach, and sector-specific.

Included

Digital crisis cell

Real-time collaboration space with role assignment, decision log, status dashboard, external stakeholder view.

Included

Communication templates

Pre-approved templates for employees, customers, regulators, media — adjustable severity + tone.

Included

Incident management

End-to-end incident workflow: detect → qualify → notify → remediate → close. ITIL + NIS2 ready.

Included

War room EOC

Digital Emergency Operations Center with multi-screen layout, timeline, decision authority tracking.

Included

CRA Compliance Suite

7 integrated modules to be ready for the Cyber Resilience Act deadline of 11 December 2027.

Live

PDE Registry

Inventory Products with Digital Elements, classification, conformity route, CE marking, lifecycle.

Learn more

SBOM Management

Import CycloneDX / SPDX, CVE cross-reference, version diff, supplier SBOM ingestion.

Included

Coordinated Vulnerability Disclosure

RFC 9116 security.txt + public intake form + 8-state triage workflow + 30-day CVSS ≥ 7 SLA.

Included

Annex I Matrix

13 essential CRA requirements × products + evidence library + readiness score for CE marking.

Included

Security Updates Lifecycle

Patch history with CVE links + 5-year / 15-year support clock + customer notification log.

Included

Market Surveillance

Pre-assembled audit dossiers + 15-business-day response timer for authority requests.

Included

Climate & ESG

Climate resilience and ESG reporting aligned with CSRD, TCFD, GHG Protocol.

Carbon Footprint (Scope 1/2/3)

GHG Protocol compliant carbon accounting with emission factors, supplier scope 3, reduction plans.

Included

TCFD Climate Scenarios

Physical + transition risk analysis under RCP 2.6/4.5/8.5 and NGFS Orderly/Disorderly/Hot House.

Included

CSRD Reporting

ESRS-aligned reporting: environmental (E1-E5), social (S1-S4), governance (G1) data collection + audit evidence.

Included

Site-level resilience

Per-site climate exposure heat maps (flood, wildfire, heat waves, drought) with adaptation plans.

Included

Platform & Reporting

Multi-tenant, approval workflows, board-ready reports, and enterprise-grade observability.

Executive dashboards

Board-ready dashboards with risk heat maps, plan coverage, maturity trends, compliance scores.

Included

Board & regulator reports

One-click report generation: ACPR, BCE, ENISA, SEC — pre-formatted for each authority.

Included

Multi-step approvals

Parallel and sequential approval chains with notifications, delegation, audit trail.

Included

Multi-tenant (groups / subsidiaries)

Hierarchical org structure: group-level rollup, subsidiary isolation, cross-entity risk aggregation.

Included

Enterprise security

SSO SAML/OIDC, SCIM provisioning, MFA, RBAC (9 roles), EU hosting, SOC 2 Type II ready.

Included

PWA offline mode

Progressive Web App with offline reflex cards, crisis docs caching, install on mobile/desktop.

Included

Help center + in-app guides

Contextual tours, video tutorials, 500+ article knowledge base, live chat with BCMS experts.

Included

67+ features, one platform

Free 14-day trial, no credit card. Access to all features during the evaluation period.

ResiPlan Features | BCMS, 36 risk methods, AI, CRA, CMDB — complete platform