# CISAPP product roadmap

What the CISAPP team recently shipped, what it is working on and what it plans next for the third-party risk and compliance platform.

> Indicative roadmap: upcoming items and their timing may change. Only "Shipped" items are commitments delivered.

Updated: 2026-10-07 — https://www.cisapp.eu/en/roadmap

## Shipped

### Light or dark theme and multilingual interface

Pick the light, dark or system theme and work in your team's language.

- Theme: Platform
- Date: Aug 2024
- Link: https://www.cisapp.eu/en/roadmap

### Secure sign-in: SSO and two-factor authentication

Sign in with your Google or Microsoft account, or company SSO, and protect every account with a second verification step.

- Theme: Platform
- Date: Oct 2024
- Link: https://www.cisapp.eu/en/roadmap/connexion-securisee-sso-mfa

#### The problem

Passwords alone don't protect sensitive data, and extra accounts slow adoption.

#### What changes

- **One-click sign-in** with Google, Microsoft or your company SSO.
- **Two-factor authentication** of your choice: authenticator app, SMS or email.
- **Easy invitations**: colleagues activate their account and set their own password.
- **Protected sessions**, with verification methods ranked by your preference.

#### Who it's for

Every team, and CISOs in particular who must show controlled access to the platform.

### Security questionnaires

Build questionnaires section by section, import them from a file and send them to your vendors to answer.

- Theme: Assessments
- Date: Mar 2025
- Link: https://www.cisapp.eu/en/roadmap/questionnaires-securite

#### The problem

Each assessment starts from a different spreadsheet that is hard to compare across vendors.

#### What changes

- **Section-based editor** to compose your own questionnaires.
- **Import of an existing questionnaire** instead of retyping it.
- **AI-assisted answers** and comments exchanged with the vendor.
- **Printing and tracking** of answers to keep a record.

#### Who it's for

Security, compliance and procurement teams assessing their vendors.

### Vendor register

Keep all your vendors in one place, with contacts, services, criticality and assessment history.

- Theme: Mapping
- Date: Mar 2025
- Link: https://www.cisapp.eu/en/roadmap/registre-fournisseurs

#### The problem

The vendor list lives in several files, with no owner and no history.

#### What changes

- **Complete record**: contacts, services, contract, business and security owners.
- **Guided creation** with company lookup by name or registration number.
- **Notes, tags and export** to organize things your way.
- **Overview** of action plans and ongoing assessments.

#### Who it's for

Procurement leads, CISOs and third-party risk managers.

### Teams, roles and permissions

Invite colleagues, organize them into teams and decide who can see or edit each vendor, scope and project.

- Theme: Platform
- Date: May 2025
- Link: https://www.cisapp.eu/en/roadmap

### Profile and guided onboarding

New users fill in their profile and company in a few steps, then land straight in the platform.

- Theme: Platform
- Date: Jun 2025
- Link: https://www.cisapp.eu/en/roadmap

### Technical service checks

Check the security setup of your services: SSL certificate, email protection and blocklist presence.

- Theme: Mapping
- Date: Jul 2025
- Link: https://www.cisapp.eu/en/roadmap

### Scopes and critical activities

Define the activities to protect, rate their criticality and link them to the vendors they depend on.

- Theme: Mapping
- Date: Oct 2025
- Link: https://www.cisapp.eu/en/roadmap/perimetres-activites-critiques

#### The problem

Without a clear view of essential activities, you can't tell which vendors really matter.

#### What changes

- **Scopes** describing your activities, services or entities.
- **Criticality rated** and re-rated over time.
- **Vendors linked** to each scope so you can prioritize your efforts.
- **Bulk import** from a file.

#### Who it's for

CISOs and compliance leads who need to prioritize their controls.

### Vendor assessments

Launch an assessment, send it with a due date, review the answers and approve them, all tracked in one table.

- Theme: Assessments
- Date: Nov 2025
- Link: https://www.cisapp.eu/en/roadmap/evaluations-fournisseurs

#### The problem

Assessments are tracked by email and spreadsheet: nobody knows who answered or where the review stands.

#### What changes

- **Creation wizard**: choose questionnaires, vendors and access rights.
- **Sending with a due date** and a personal message.
- **Answer review**: approve, send back, reject with a reason, or approve in bulk.
- **Side-by-side comparison** of vendors.

#### Who it's for

Security and procurement teams running several assessments in parallel.

### Client management

Vendors and service providers see the client organizations assessing them, with a detail page for each.

- Theme: Platform
- Date: Nov 2025
- Link: https://www.cisapp.eu/en/roadmap

### Vendor risk map

See your vendors by criticality on a radar and read key statistics at a glance.

- Theme: Mapping
- Date: Mar 2026
- Link: https://www.cisapp.eu/en/roadmap

### Crisis management

Bring crisis cells, communication channels and stakeholders together in a space ready when you need it.

- Theme: Compliance
- Date: Apr 2026
- Link: https://www.cisapp.eu/en/roadmap

### Policy exemptions

Request, document and track exceptions to your internal rules, with a guided three-step flow.

- Theme: Compliance
- Date: Apr 2026
- Link: https://www.cisapp.eu/en/roadmap

### Risk register

Record, score and treat your risks in one place, with guided creation and your own scoring methodology.

- Theme: Compliance
- Date: Apr 2026
- Link: https://www.cisapp.eu/en/roadmap/registre-des-risques

#### The problem

Risks are scattered across spreadsheets and meeting notes, with no shared scoring method.

#### What changes

- **Guided creation**, step by step.
- **Configurable methodology** at organization level.
- **Tracked treatment**: measures, owners and status.
- **Links** to the related vendors, incidents and projects.

#### Who it's for

CISOs, risk managers and compliance leadership.

### Security incident management

Log your incidents and notify the affected client organizations directly from the platform.

- Theme: Compliance
- Date: Apr 2026
- Link: https://www.cisapp.eu/en/roadmap

### Security policies

Write and maintain your security policies and their requirements in one shared, versioned space.

- Theme: Compliance
- Date: Apr 2026
- Link: https://www.cisapp.eu/en/roadmap

### Command palette

Reach any page or action from the keyboard, without going through menus.

- Theme: Platform
- Date: Apr 2026
- Link: https://www.cisapp.eu/en/roadmap

### Built-in support

Reach support from inside the platform: your context is passed along, nothing to re-explain.

- Theme: Platform
- Date: May 2026
- Link: https://www.cisapp.eu/en/roadmap

### Subscription, usage and card payment

See your subscription and usage, pay by card and discover which features your plan includes.

- Theme: Platform
- Date: May 2026
- Link: https://www.cisapp.eu/en/roadmap

### Custom tags

Classify vendors and scopes with your own tags to filter and find what matters fast.

- Theme: Platform
- Date: Jun 2026
- Link: https://www.cisapp.eu/en/roadmap

### Frameworks and compliance requirements

Follow the requirements of your frameworks, spot gaps and activate suggested measures, with the number of linked proofs.

- Theme: Compliance
- Date: Jun 2026
- Link: https://www.cisapp.eu/en/roadmap/referentiels-et-exigences

#### The problem

Knowing where you stand against a framework means cross-checking dozens of documents.

#### What changes

- **Unified view**: measure register and tasks in one place.
- **Gap analysis** with suggested measures to activate.
- **Proofs counted** for each requirement.
- **New frameworks** added regularly, including EASA Part-IS.

#### Who it's for

Compliance leads and CISOs preparing for a certification or an audit.

### Technology catalog

Select the technologies in use from a shared list instead of typing them by hand.

- Theme: Platform
- Date: Jun 2026
- Link: https://www.cisapp.eu/en/roadmap

### Vendor access requests

A vendor contact requests access to your workspace, a reviewer approves or declines, and both sides are notified by email at each step.

- Theme: Assessments
- Date: Jun 2026
- Link: https://www.cisapp.eu/en/roadmap

### Dependency and exposure mapping

An interactive map links your vendors, their subcontractors and your assets across several tiers, and a concentration view shows where risk piles up in your supply chain.

- Theme: Mapping
- Date: Jul 2026
- Regulations: NIS2, DORA
- Link: https://www.cisapp.eu/en/roadmap/cartographie-dependances

#### The problem

A vendor registry is a list. Risk is a network: a tier-2 subcontractor shared by three critical providers is a single point of failure no spreadsheet will show.

#### What changes

- **Multi-tier map**: vendors, nth-party subcontractors and assets on a single view.
- **Concentration view**: shared dependencies stand out immediately.
- **Controlled sharing**: a vendor can expose its own chain with cascading visibility.

#### Who it's for

CISOs and procurement teams who must back a concentration analysis (DORA, art. 28-29) or map their supply chain (NIS2, art. 21).

### GitHub connector and Dependabot alerts

First connector of the integrations platform: link your GitHub repositories and centralise Dependabot alerts in your vulnerability inventory.

- Theme: Integrations
- Date: Jul 2026
- Link: https://www.cisapp.eu/en/roadmap/connecteur-github

#### What changes

- Connection through a **GitHub App**: read-only permissions, revocable at any time.
- **Dependabot alerts** flow in automatically and join your vulnerability tracking.
- A single Connectors page to enable, configure and monitor each integration.

#### What's next

GitHub is the first connector on a generic foundation: every new integration reuses the same configuration and sync framework.

### AI-assisted Excel questionnaire import

Import any Excel security questionnaire; AI drafts answers from your existing evidence and a three-pane review space lets you validate everything before sending.

- Theme: Assessments
- Date: Jul 2026
- Link: https://www.cisapp.eu/en/roadmap/import-ia-questionnaires

#### The problem

Every customer sends its own Excel file. Vendor security teams answer the same questions dozens of times a year.

#### What changes

- **Direct import** of the customer's file, no retyping.
- **AI-drafted answers**, sourced from your previous answers and documents.
- **Three-pane review**: question, draft, evidence. Accept, edit or reject.
- **Progress tracking** through to export in the original format.

#### Who it's for

Vendors flooded with security questionnaires, and buyers who want faster, better-evidenced answers.

### CISO dashboard

Key indicators, peer-benchmarked scores and critical vendors up front, to read your posture at a glance.

- Theme: Platform
- Date: Jul 2026
- Link: https://www.cisapp.eu/en/roadmap

### In-app notifications and browser alerts

A notification center in the app and browser alerts so you never miss a vendor response, a deadline or an access request.

- Theme: Platform
- Date: Jul 2026
- Link: https://www.cisapp.eu/en/roadmap

### Processing register and data breach register

Keep your GDPR processing register and your breach register in the platform, linked to your vendors, with authority notification guided step by step.

- Theme: Compliance
- Date: Jul 2026
- Regulations: RGPD
- Link: https://www.cisapp.eu/en/roadmap/registre-rgpd-violations

#### The problem

The processing register and the breach register often live in spreadsheets, far from the vendors that actually handle the data. When an incident hits, nobody can quickly tell who is affected or what to notify.

#### What changes

- **Processing register**: each processing activity is documented in the platform and linked to the vendors involved, both ways.
- **Breach register**: every incident is logged with its history and severity level.
- **Guided notification**: preparing the notification to the authority happens step by step.
- **Declared sub-processors**: the data processing agreement and downstream sub-processors show on the vendor record.

#### Who it's for

DPOs and legal teams, working with security and procurement.

### Assessments from the vendor side

Answer your clients' assessments and compare your vendors in a matrix to decide faster.

- Theme: Assessments
- Date: Jul 2026
- Link: https://www.cisapp.eu/en/roadmap

### Document explorer with TLP sharing levels

Browse, preview and classify your sensitive documents by TLP sharing level, with a view of the storage space used.

- Theme: Platform
- Date: Jul 2026
- Link: https://www.cisapp.eu/en/roadmap

### Internal vendor notes

Timestamped, attributed notes on every vendor record to keep track of discussions and decisions.

- Theme: Platform
- Date: Sep 2026
- Link: https://www.cisapp.eu/en/roadmap

### Projects and action plans

Track your projects and the action plans coming out of vendor assessments in one place, with tasks, owners and priorities.

- Theme: Platform
- Date: Sep 2026
- Link: https://www.cisapp.eu/en/roadmap/projets-plans-d-action

#### The problem

Follow-up actions after a vendor assessment get lost in spreadsheets and messages. Nobody knows who owes what, or by when.

#### What changes

- **One place** for your internal projects and the action plans that come out of assessments.
- **Board view** with tasks, owners, priorities and comments.
- **Connected to the rest of your setup**: vendors, scopes, risks, incidents and exemptions linked to each project.
- **Privacy tracking**: personal data involved, impact assessment status and retention period on each project.
- **Role-based access**: everyone sees and edits only what concerns them.

#### Who it's for

Security, compliance and procurement teams who need to turn assessment findings into actions tracked through to closure.

## In progress

### Cyber news feed

A feed of cyber and regulatory news on your dashboard, with the option to add your own sources.

- Theme: Platform
- Link: https://www.cisapp.eu/en/roadmap

### End-to-end vendor assessment journey

A single journey covers selecting a new vendor, comparing several candidates and recurring monitoring of the vendors already in place.

- Theme: Assessments
- Regulations: NIS2, DORA, ISO-27001
- Link: https://www.cisapp.eu/en/roadmap/parcours-evaluation-fournisseur

#### The problem

Assessing a vendor isn't a one-off: you compare before signing, assess at contracting, then reassess on a schedule. Those three moments often live in different tools.

#### What changes

- **Selection**: compare several candidates on the same criteria before choosing.
- **Contracting**: the chosen assessment follows the selected vendor.
- **Monitoring**: recurrence set by criticality, automatic reminders.

#### Who it's for

Procurement and security teams who must show continuous oversight of their third parties (NIS2, DORA, ISO 27001 A.5.19-5.22).

### Exposed attack surface

Discover the domains and assets your organization exposes on the Internet, verify you own them, and follow scan progress live.

- Theme: Mapping
- Regulations: NIS2
- Link: https://www.cisapp.eu/en/roadmap/surface-d-attaque-exposee

#### The problem

You can only protect what you know. Between forgotten subdomains, services exposed by mistake and fragile email configurations, the surface visible from the Internet often exceeds what teams have in mind.

#### What changes

- **Automatically discovered inventory**: exposed domains and assets listed in one place.
- **Scans limited to your assets**: a scan only runs once you have verified that you own the domain.
- **Live progress**: discovery and scans update on screen without a reload.
- **Readable reports**: findings, including email security, are presented clearly.

#### Who it's for

CISOs and security teams who need to demonstrate control over their exposure (NIS2, art. 21).

### Vendor mapping at scale

A smooth map of all your vendor relationships, built for hundreds of third parties, with filters by criticality and tier.

- Theme: Mapping
- Regulations: DORA
- Link: https://www.cisapp.eu/en/roadmap

## Up next

### NIS2 compliance management

Find out whether NIS2 applies to you, measure your gap against the Article 21 measures, track your action plan and link vendor assessments to the supply chain security requirement.

- Theme: Compliance
- Date: Q4 2026
- Regulations: NIS2
- Link: https://www.cisapp.eu/en/roadmap/conformite-nis2

#### The problem

NIS2 greatly widens the number of organisations in scope, and many still don't know whether they're concerned, or where to start. Supply chain security is one of the required measures, and often the hardest to demonstrate.

#### What changes

- **Know whether you're in scope**: a guided path determines whether you're an essential or important entity.
- **A clear diagnosis**: where you stand on each required security measure, and what's left to do.
- **A tracked action plan**: every gap becomes an action with an owner and a deadline.
- **Your vendors already count**: assessments run in CISAPP feed straight into the supply chain requirement.
- **Ready on incident day**: notification deadlines (24 h, 72 h, 1 month) are tracked for you.

#### Who it's for

Essential and important entities, and the suppliers they ask for guarantees.

### DORA register of information

Generate the register of information required by DORA straight from your vendor registry and mapping.

- Theme: Compliance
- Date: Q4 2026
- Regulations: DORA
- Link: https://www.cisapp.eu/en/roadmap

### Custom dashboards

Build your own dashboards with historical indicators, targets and ready-made templates (CISO, DPO, Procurement, executive, NIS2), then export them or schedule delivery.

- Theme: Platform
- Date: Q4 2026
- Link: https://www.cisapp.eu/en/roadmap/tableaux-de-bord-personnalises

#### The problem

The CISO, the DPO, procurement and the executive committee don't ask the same questions. Yet they all want the same thing: to know whether things are getting better, and where to act first.

#### What changes

- **Your indicators, your dashboard**: build it in a few clicks from ready-made widgets.
- **Trends over time**: every indicator shows where it's heading, not just today's value.
- **Templates for every role**: CISO, DPO, procurement, executive committee, NIS2. Use them as they are or adapt them.
- **From number to action**: one click on an indicator opens the list of items behind it.
- **Reports that send themselves**: PDF export and scheduled delivery to management.

#### Who it's for

CISOs, DPOs, procurement leads and executives who steer third-party risk and compliance.

### Application inventory

Tell apart the applications of a single vendor, the activities that rely on them, their owning teams and the data they process, so each can be assessed and tracked separately.

- Theme: Mapping
- Date: Q1 2027
- Link: https://www.cisapp.eu/en/roadmap/applications

#### The problem

A vendor is more than a single line: the same publisher may provide your payroll tool and your CRM, with very different uses and risks. Thinking only at vendor level hides what matters.

#### What changes

- **An inventory of the applications you use**: which service, used by which team, for which activity.
- **Criticality at the right level**: each application inherits the importance of the activities it supports.
- **Targeted assessments**: assess one specific application rather than the whole vendor.
- **A more accurate map**: your organisation, your activities, the applications and the vendors behind them.

#### Who it's for

CISOs, CIOs and third-party risk owners who want to know exactly what depends on what.

### AWS, Jira, Slack and GitLab connectors

Your cloud and code evidence flows in on its own, action plans land in your tracking tools and alerts reach your team where it already works.

- Theme: Integrations
- Date: Q1 2027
- Link: https://www.cisapp.eu/en/roadmap/connecteurs-supplementaires

#### The problem

Security evidence already lives in your tools: your cloud configuration, your code repositories, your tickets. Copying it into a questionnaire or a spreadsheet takes time, and it's out of date the next day.

#### What changes

- **AWS**: your cloud configuration becomes up-to-date evidence, no screenshots needed.
- **GitLab**: the same checks as GitHub, for teams working on GitLab.
- **Jira**: remediation actions go straight into your teams' backlog, and their progress flows back into CISAPP.
- **Slack**: the alerts that matter (vendor incident, expired evidence, assessment received) reach your channels.

#### Why these first

They're the tools that bring the most evidence and save the most time day to day. More will follow throughout the year.

### Vendor-customer document exchange

A document space for each relationship: request a document with a due date and reminders, track its validity and share it once with several customers.

- Theme: Assessments
- Date: Q1 2027
- Link: https://www.cisapp.eu/en/roadmap/echange-documents

#### The problem

Attestations, certificates, data processing agreements: your vendors' documents are scattered across inboxes, questionnaires and shared folders. Nobody notices when a certificate expires.

#### What changes

- **A Documents space for each vendor**: everything they've sent you, in one place.
- **Request, remind, receive**: a request with a due date and automatic reminders.
- **Expiry alerts**: when a document is about to expire, the renewal request goes out on its own.
- **For suppliers, share once**: the same document for several clients, with a clear list of who has access and until when.

#### Who it's for

Procurement and security teams on the client side, and suppliers who share documents with several clients.

### Enhanced crisis management

Regulatory notification deadlines, playbooks by incident type, structured post-mortems and impact analysis when a vendor is affected.

- Theme: Compliance
- Date: Q1 2027
- Regulations: NIS2, DORA
- Link: https://www.cisapp.eu/en/roadmap/gestion-de-crise-v2

#### The problem

When an incident hits, everything happens in the first few hours: who does what, do you need to notify the authority, and by when? Without preparation, you improvise under pressure.

#### What changes

- **Regulatory deadlines in plain sight**: NIS2, DORA, GDPR. CISAPP tells you whether to notify, whom, and by when.
- **Ready-made action plans**: the steps to follow for each type of incident (ransomware, data leak, vendor failure).
- **Practise before the real thing**: crisis exercises with a scenario and a debrief.
- **Impact visible at once**: an incident at a vendor shows the activities and applications affected.
- **Learn from every incident**: a structured post-incident review at closure.

#### Who it's for

CISOs, crisis teams and organisations subject to NIS2 or DORA.

### Group and subsidiary management

Run a group and its subsidiaries from one account: dedicated roles, perimeters, shared vendors and consolidated views, with strict isolation between subsidiaries. Enterprise plan only.

- Theme: Platform
- Date: Q1 2027
- Link: https://www.cisapp.eu/en/roadmap/groupe-filiales

#### The problem

In a group, each subsidiary manages its vendors on its own. The same provider gets five different questionnaires, and group security has no overall picture without stitching spreadsheets together by hand.

#### What changes

- **One group view, autonomous subsidiaries**: each subsidiary keeps its own vendors, teams and data. The group sees everything; subsidiaries don't see each other.
- **A shared vendor register**: a provider used by several subsidiaries is assessed once, and every entity benefits.
- **Common rules**: questionnaires, policies and risk methodology are published by the group and applied everywhere.
- **One login**: your people move from one subsidiary to another with the same account and the group's company sign-in.
- **Consolidated indicators**: compare subsidiaries and spot the vendors several entities depend on.

#### Who it's for

Groups and multi-entity companies, and their group security, compliance and procurement teams. Included in the Enterprise plan.

### Evidence linked to questionnaire answers

Back an answer with live evidence from your CISAPP tools or connectors instead of a static file. The customer sees a dated, verified attestation.

- Theme: Assessments
- Date: Q1 2027
- Regulations: NIS2, ISO-27001
- Link: https://www.cisapp.eu/en/roadmap/preuves-liees-aux-reponses

#### The problem

In a questionnaire, a "yes" is only worth the evidence behind it. Today you attach a PDF that starts ageing the moment it's sent, and the client has no way of knowing whether it's still current.

#### What changes

- **Living evidence**: back an answer with a result from CISAPP's tools or your connected tools, always up to date.
- **The right evidence, suggested**: for each question, CISAPP proposes what you already have.
- **A trust badge**: your client can tell verified evidence from a plain statement.
- **Never out of date**: when evidence is about to expire, you hear about it before your client does.
- **You stay in control**: the client sees a dated attestation, not the sensitive details.

#### Who it's for

Suppliers who want to convince faster, and clients who want answers they can rely on.

### Enhanced Trust Center

Publish certifications, controls, subprocessors and FAQ, and share documents publicly, on request or under NDA. CISAPP customers get access in one click.

- Theme: Assessments
- Date: Q1 2027
- Link: https://www.cisapp.eu/en/roadmap/trust-center-evolue

#### The problem

Clients and prospects keep asking the same questions and requesting the same documents. Each request goes through an email, an internal sign-off and a manual send.

#### What changes

- **A security showcase in your colours**: certifications, controls in place, subprocessors and updates on a public page.
- **Documents under control**: open access, on request, or after accepting a non-disclosure agreement.
- **Requests handled in one click**: manual or automatic approval, time-limited access.
- **An FAQ that stays current**: fed by your approved answers.
- **Sales signals**: who visits your page, and which documents your prospects care about.

#### Who it's for

Software vendors and service providers who regularly answer security questionnaires.

### Multi-framework gap analysis

Measure your gap per framework, see what your ISO 27001 certification already covers for NIS2 or DORA, and get a prioritised remediation plan.

- Theme: Compliance
- Date: Q2 2027
- Regulations: NIS2, DORA, ISO-27001
- Link: https://www.cisapp.eu/en/roadmap/analyse-ecart-referentiels

#### The problem

You're ISO 27001 certified, and now you're asked for NIS2, then DORA. Starting from scratch each time makes no sense: much of the work is already done.

#### What changes

- **Credit for what you already have**: your existing measures are matched against the new framework's requirements.
- **What's missing, spelled out**: the list of gaps, requirement by requirement.
- **A prioritised plan**: actions ranked by impact and effort.
- **A report for management**: where you stand, and what's left to do.

#### Who it's for

CISOs and compliance leads who answer to several frameworks.

### Cyber Resilience Act compliance

For vendors of digital products: product inventory, SBOM, vulnerability tracking and reporting within CRA deadlines.

- Theme: Compliance
- Date: Q2 2027
- Link: https://www.cisapp.eu/en/roadmap/conformite-cra

#### The problem

The Cyber Resilience Act requires makers of digital products to know what their products are made of, fix their vulnerabilities and report the most serious ones within very short deadlines.

#### What changes

- **Your products and their components**: an up-to-date inventory, version by version.
- **The vulnerabilities that affect you**: spotted and tracked until they're fixed.
- **Guided reporting**: the 24 h, 72 h and 14-day deadlines tracked for you.
- **Your disclosure policy published**: straight on your Trust Center.

#### Who it's for

Software publishers and makers of connected products sold in the EU, and their clients who expect guarantees.

### Azure, Google Cloud, Scaleway, OVHcloud, Linear and Aikido connectors

All your clouds covered, European hosting providers included, your application vulnerabilities in one place and your action plans in Linear.

- Theme: Integrations
- Date: Q2 2027
- Link: https://www.cisapp.eu/en/roadmap/connecteurs-cloud-et-suivi

#### What changes

- **Azure and Google Cloud**: the same up-to-date evidence as AWS, whatever your cloud provider.
- **Scaleway and OVHcloud**: European hosting providers, for organisations that have chosen sovereignty.
- **Linear**: your remediation plans in your product teams' tool, with progress tracking.
- **Aikido**: your application vulnerabilities brought together with the rest of your security posture.

#### Who it's for

Teams working across several clouds, and those for whom European hosting is a requirement.

### Import answers from a Trust Center

Pre-fill an assessment from a vendor's Trust Center, with cited sources and answers pending validation.

- Theme: Assessments
- Date: Q2 2027
- Link: https://www.cisapp.eu/en/roadmap

### GDPR: DPIA, data subject requests and retention

Impact assessment workflow, data subject request register with deadlines, retention policies and a data map that flags transfers outside the EU.

- Theme: Compliance
- Date: Q2 2027
- Regulations: RGPD
- Link: https://www.cisapp.eu/en/roadmap/rgpd-avance

#### The problem

The record of processing activities often lives on its own, disconnected from the vendors and tools actually in use. The result: forgotten subprocessors, invisible transfers outside the EU and impact assessments that are hard to keep current.

#### What changes

- **A data map that reflects reality**: processing activities, applications, subprocessors and hosting countries in one place.
- **Guided impact assessments**: from the first screening to the DPO's opinion.
- **Transfers outside the EU spotted**: with their assessment prepared.
- **Data subject requests tracked**: public form, deadlines and template replies.
- **Inconsistencies flagged**: when a vendor's answer contradicts your record.

#### Who it's for

DPOs and legal teams, working with security and procurement.

### Advanced risk management

Risk appetite, risk indicators tracked over time, risks suggested from your assessments and monitoring, then the full EBIOS RM method.

- Theme: Compliance
- Date: Q2 2027
- Regulations: ISO-27001
- Link: https://www.cisapp.eu/en/roadmap/risque-avance

#### The problem

A risk register updated once a year doesn't steer anything. You need to know what level of risk is acceptable, and see quickly when you drift from it.

#### What changes

- **Your risk appetite, made explicit**: by category, with an alert as soon as a risk goes beyond it.
- **Indicators that stay alive**: each risk tracked by indicators that update automatically.
- **Suggested risks**: drawn from vendor assessments, compliance gaps and external monitoring.
- **Clear reporting**: before and after treatment, and the trend over time for management.

#### Who it's for

Risk managers, CISOs and risk committees.

### Datadog, Azure DevOps, Confluence, Riot and Akamai connectors

Your monitoring, documentation and staff awareness become evidence, with no extra effort.

- Theme: Integrations
- Date: Q3 2027
- Link: https://www.cisapp.eu/en/roadmap/connecteurs-supervision-et-sensibilisation

#### What changes

- **Datadog**: your monitoring and log retention demonstrated continuously.
- **Azure DevOps**: remediation and code checks for Microsoft-based teams.
- **Confluence**: your documented policies and procedures, linked to the requirements they cover.
- **Riot**: your staff's security awareness as training evidence, expected by NIS2 among others.
- **Akamai**: the protection of your exposed applications reflected in your posture.

#### Who it's for

Organisations that want to prove what they already do, without producing extra paperwork.

## Exploring

### AI Act compliance

Register of the AI systems you use, risk classification and tracking of your deployer obligations.

- Theme: Compliance
- Regulations: AI-ACT
- Link: https://www.cisapp.eu/en/roadmap

### AI-assisted tailored monitoring

Cyber and regulatory monitoring filtered on your vendors, technologies and sector, with one-click actions.

- Theme: Platform
- Link: https://www.cisapp.eu/en/roadmap

### Browser extension

Reuse your answer library directly inside your customers' questionnaire portals.

- Theme: Assessments
- Link: https://www.cisapp.eu/en/roadmap/extension-navigateur

#### The problem

Some of your clients send their questionnaires through their own portals. Your existing answers can't be reused there: everything is done by hand, question by question.

#### What changes

- **Your answers on any portal**: CISAPP suggests the right answer from your library.
- **One-click insertion**: with the source of each suggestion.
- **A library that grows**: every approved answer is kept for next time.
- **Hours saved**: the same work is done once, whatever the portal.

#### Who it's for

Security, compliance and pre-sales teams on the supplier side.

### Connectors under consideration: Salesforce, Zendesk, Shopify, Sage…

These integrations are being considered next. Tell us which ones matter to you: your feedback sets the order.

- Theme: Integrations
- Link: https://www.cisapp.eu/en/roadmap/connecteurs-a-l-etude

#### Under consideration

- **Salesforce and Zendesk**: connect customer relationship and support to your security commitments.
- **Shopify, Mixpanel and Vercel**: cover the tools used by e-commerce, product and web teams.
- **Sage**: bring your vendors together with your purchasing data.
- **Zapier**: connect CISAPP to tools not yet on this list.

#### Your input matters

The order of these integrations depends on your needs. Talk to your CISAPP contact or book a demo.

### Continuous external vendor monitoring

Complement self-declared assessments with external signals continuously observed on your vendors' exposed surface.

- Theme: Assessments
- Regulations: NIS2
- Link: https://www.cisapp.eu/en/roadmap

### Recommended contract clauses

Based on a vendor's answers, CISAPP suggests suitable clauses, backed by the original answer and exportable for negotiation.

- Theme: Assessments
- Regulations: DORA, NIS2
- Link: https://www.cisapp.eu/en/roadmap/clauses-contractuelles

#### The problem

An assessment reveals a weakness at a vendor. Then what? Too often, the finding stays in the report and never makes it into the contract.

#### What changes

- **The right clause at the right time**: a weak answer triggers a recommendation for a suitable clause.
- **Every clause justified**: the answer that prompted it stays visible.
- **A ready-to-use library**: subcontracting, data location, incident notification, audit, reversibility, use of AI…
- **All the way to signature**: exportable clauses, tracked through contracting.

#### Who it's for

Procurement, legal and CISOs negotiating with vendors.
