Free online trainings
01
Sep
Introduction to Risk & Compliance Use Cases – Advanced

Compliance Management Software

Import any framework as a CSV. Map every requirement to the controls, policies and projects you already have. Prove it to an auditor.

Flat annual fee · Unlimited users · Self-hosted or SaaS · Open source

Every framework, included

  • ISO 27001
  • ISO 27002
  • NIS2
  • DORA
  • SOC 2
  • PCI-DSS v4
  • NIST CSF 2.0
  • NIST 800-53
  • NIST 800-171
  • GDPR
  • HIPAA
  • HITRUST
  • CIS Controls v8
  • TISAX
  • CMMC 2.0
  • FedRAMP
  • SWIFT CSF
  • Cyber Essentials
  • ISO 22301
  • ISO 42001
  • ENS
  • C5
  • CPS 230

70+ ready-to-import packages, plus any custom framework you upload as a CSV. No per-framework fees.

Browse all compliance packages

What you actually get

  • A library of compliance requirements you can assign, track and report on
  • Link each requirement to policies, internal controls, projects and documented exceptions
  • Automated and manual control testing, with scheduled audits
  • Dynamic status that warns you before a deadline is missed
  • Reports auditors accept, including Statements of Applicability
  • Weekly notifications to the person who owns each item

Six steps, per requirement

  1. 01Read the requirement
  2. 02Identify the owner
  3. 03Decide whether it applies — if not, log a documented exception
  4. 04Define the solution: a policy, an internal control, or both
  5. 05Reuse a solution you already have, wherever possible
  6. 06If it does not exist yet, create a project and link it

One solution, many problems

An internal control such as endpoint encryption can satisfy three compliance requirements, mitigate two risks and cover one data flow at the same time.

If your organisation has 500 problems — 300 compliance requirements, 100 risks, 100 data flows — you do not need 500 solutions. You need about 60 to 100.

500 problems60–100 solutions

NIS2

NIS2 entered into force in January 2023. Member states were required to transpose it into national law by 17 October 2024, and they did so in twenty-seven different ways — several of them late. National implementation and enforcement timelines still vary.

Article 21 lists ten security measures. Most companies already do six or seven of them, and cannot prove it. That is the work.

What this does not do

GRC tools do not make an organisation compliant. The same is true of project management and accounting tools. They facilitate the work.

Specifically, eramba is not a vulnerability management tool and not an authentication service. It documents and tests the controls around those things. That is not the same thing, and we would rather say so here than in a sales call.

Try it before you talk to anyone

The Community edition is free, self-hosted, with no user limit and no time limit. Import a compliance package and see how it works with your own requirements.

Download the free edition

Pricing

Community

Free

Self-hosted. No user limit, no time limit.

Download

Enterprise on-premises

from 2500€/year

Runs on your infrastructure, with support and updates.

See pricing

Enterprise SaaS

from 5000€/year

Hosted and operated by eramba, in the EU.

See pricing

Flat annual price. Unlimited users, unlimited data, every module included. Your bill does not grow with your team.

Need more detail?

Tell us what you are trying to comply with and we will send you something useful. No sales sequence.