Platform

Continuous Compliance · Prevent

Axyom calculates the status of every control with the evidence your connected systems already collect and with the documents you upload. When the audit or the customer's questionnaire arrives, you download the ENS attestation with the evaluation date and the content hash.

The status per framework lights up when you connect your systems.

What it is

The living status of your controls.

It means gathering the status of the controls from the available configuration of the systems you already use and the documentation you provide, instead of rebuilding it by hand every time someone asks. The date of each source shows which point in time the evidence from your email, your identity and your cloud reflects.

Almost everyone starts the same way: someone builds a spreadsheet with the ISO 27001, NIS2 or ENS controls and fills it in, and on that day the sheet is true. Three months later someone has changed a conditional access policy, a new administrator has joined without two-factor, a permission nobody reviewed has been opened, and the sheet still says everything is green.

The problem shows up when the date arrives: a large customer sends their supplier questionnaire, a public tender asks for ENS, your sector enters the scope of NIS2 or the consultancy starts the pre-audit. Then it is time to rebuild months of configurations by hand, find out who saved each policy and ask for screenshots over Slack. Gathering that evidence takes weeks, and it expires again as soon as you hand it in.

889

controls across the six catalogs

92

Annex A controls cataloged

6

frameworks in the catalog

1

framework with a PDF attestation: ENS

What it is
The status of the controls within the evaluated scope, calculated from the available configuration of the systems you already use and from the documents you upload. The source and its date accompany the evidence.
Who it is for
Companies of 10 to 250 employees that a customer, a tender or their sector requires to demonstrate controls. If you are already being asked for ISO 27001, ENS or NIS2 in writing, this is your module.
Where it fits
In the Max plan, with the complete platform. The domain scan already moves framework controls, starting on the free plan, and the status per framework with evidence arrives with Max.
What we need
Connect Microsoft 365, Google Workspace, GitHub or your cloud with read-only access to configuration. The permissions do not open the contents of mailboxes or files, and you upload the policy documents yourself.
Cadence
The status is recalculated with every sync of the connected systems, without waiting for the next audit. The documents you upload count from their effective date and expire when their validity ends.

What it checks

Six frameworks loaded, and how each one is tested.

Each framework is tested with the evidence your connected systems return, and the measures no machine can see are covered with documents.

ENS, RD 311/2022
121 measures in the catalog. The evaluation combines technical signal and documents. Attestation available in PDF.
ISO 27001:2022
92 Annex A controls cataloged. The evaluation depends on the available evidence; some remain unevaluated.
NIS2, EU 2022/2555
The technical measures of Article 21. Applicability depends on your sector and on the transposition.
NIST CSF 2.0
79 controls in the catalog, evaluated according to the available sources and documentation.
Technical GDPR
Articles 25, 30 and 32. It is a technical baseline and does not replace a complete legal audit.
CIS Benchmarks
462 controls over AWS, Azure, GCP and Microsoft 365, plus Workspace and supply chain.

DORA and SOC 2 are declared outside the auditable scope in the catalog, and we do not count them as covered until they are.

Mapping

How a finding is translated into control status.

Every mapping between a finding and a control is written by hand, with its justification alongside so an auditor can challenge it.

Catalog

Controls organized by framework

The six catalogs gather 889 controls, from ENS and its 121 measures to the 462 CIS controls. The view lets you check what evidence exists and what remains unevaluated. The catalog count does not equal approved controls.

Justification

Mappings with evidence

An administrator without two-factor can affect several controls. The mappings relate the finding to its framework reference and its justification, so you can review the cause and the evidence behind each status.

Coverage

Evaluated and unevaluated

Part of Annex A has no automatic signal associated. These controls remain unevaluated. The management clauses and the certification require the corresponding documentary and professional work.

The date is part of the evidence

The status is read alongside the latest information available from each source. A failing control links to the finding that contradicts it, with its origin and its date. An unevaluated control means evidence is missing within Axyom's scope. That way you can prepare the review without mixing up old information, documents you have supplied and technical checks.

What you take away

Three pieces you can show to outsiders.

01

Readiness per framework

A single figure at the top and the list of what raises it most, ordered by leverage rather than by control code. It is the view you can take to the committee without having to translate it.

02

The ENS attestation

A PDF with the evaluation date, the status measure by measure and the content fingerprint. It exists today for ENS; for the rest of the frameworks the full status is visible on screen.

03

Signed exceptions

A control that does not apply or that is accepted as a risk is documented as an exception, with its owner and its date, instead of staying red forever without explanation.

Sample failing control · Sample data

Control
Two-factor on administrator accounts
Status
Failing · illustrative data
Evidence
Two Microsoft 365 administrator accounts without MFA enforced
Reference
ISO 27001 A.5.17 · catalog mapping
Action
Step-by-step playbook with estimated effort and evidence required on closing

Where it fits in the platform

Where the evidence for each control comes from.

The technical evidence is brought by the modules that are already looking, and every finding arrives with the control it answers to written next to it. What no machine can see, you upload yourself: policies, procedures and signed minutes in PDF or DOCX, each tied to its control, with its effective date and its SHA-256 fingerprint.

Limits

What continuous compliance does not do.

Check the scope before turning on the module and coordinate with your team the actions that fall to them.

It does not issue the certificate

Certification is issued by an accredited body. Axyom keeps the status up to date between audits and gathers the evidence, which is where the time goes.

It does not replace your consultancy

The scope, the risk analysis and the statement of applicability are matters of judgment and remain theirs. What disappears is chasing screenshots over Slack.

Clauses 4 to 10 are left out

Left out on purpose, because they are not audited through configuration. That takes a management system that no telemetry calculates.

The PDF attestation only exists for ENS

For the rest of the frameworks the full status is visible on screen, with its date and its evidence, and there is no downloadable document yet.

We cover the technical side of GDPR

Articles 25, 30 and 32. It does not replace a legal audit or the work of a data protection officer.

A framework only lights up with its sources

Without Microsoft 365, Google Workspace or your cloud connected, the control stays unevaluated, with the name of the integration that lights it up.

It does not read the contents of your systems

The permissions open the configuration: applications, directory, audit logs and the status of cloud resources. None of them opens mailboxes, conversations or files.

DORA and SOC 2 are out of scope

Declared as such in the catalog, both of them. We do not count them as covered or present them as available until they are.

Plans

Compliance per framework comes with Max.

The domain scan already moves framework controls, starting on the free plan. The status per framework with evidence, the ENS attestation and the support in audits live in Max.

Free

To see your real risk before deciding anything.

€0

No cost · No card.

Everything to get looking:

  • Continuous scan External surface, 24/7
  • Posture and risk map Real-time CyberScore
  • Leaked credentials Counted, no detail
Start free

Base

For companies that want the whole platform without a security team of their own.

€190 / month

Self-serve · No commitment.

Everything in Free, plus:

  • Integrations Microsoft 365, Google Workspace and cloud
  • AI risk Apps with permissions over your data
  • Prioritized backlog Monthly remediation
  • 1 domain Continuously scanned
Get Base

Pro

For teams that need every sensor active and an expert behind it.

€990 / month

Advisor on escalation · No commitment.

Everything in Base, plus:

  • Security advisor On escalation, with SLA
  • Threat Intelligence Exposed credentials, under watch
  • Recurring pentesting Authenticated, report reviewed by Axyom
  • MDR 24/7 Up to 20 managed devices
  • Up to 5 domains All continuously scanned
Get Pro

Max

For high exposure or compliance demands.

€1,990 / month

Dedicated advisor · No commitment.

Everything in Pro, plus:

  • Dedicated security advisor A fixed person, monthly session
  • Priority response Incidents
  • Compliance by framework Downloadable evidence and attestation
  • Audit support Customer questionnaires and due diligence
Contact sales

FAQs.

Does this replace the audit or the consultancy?

Certification is issued by an accredited body and the scoping judgment comes from your consultancy. Axyom keeps the status of the controls up to date between one audit and the next, and gathers the evidence you are going to be asked for, which is where your team's time goes.

Where do the control catalogs come from?

The six catalogs gather 889 controls. The mapping between findings and controls includes its justification. The status of each control depends on the available signal and documentation, and keeps the unevaluated points visible.

What permissions are needed and what can you see?

All permissions are read-only access to configuration: applications, directory, audit logs, identity policies and the status of cloud resources. That is what it takes to know whether two-factor is on or whether a bucket is public. None of them opens the contents of mailboxes or files.

Can I get ISO 27001 certified with this alone?

The platform helps prepare the audit with evidence and Annex A controls. Some of those controls require additional evaluation, and clauses 4 to 10 need a management system. Certification is up to the accredited body.

Do you cover DORA and SOC 2?

Not yet. Both are declared in the catalog as outside the auditable scope, and we do not count them as covered until they are. The six frameworks that are calculated today are ISO 27001, NIS2, ENS, NIST CSF 2.0, technical GDPR and CIS.

Choose how to start.

On your own

Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.

With our team

Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.

Start now.