Catalog Manager: Your Central Compliance Platform
Structured management of compliance catalogs for systematic, traceable IT compliance. From BSI IT-Grundschutz to ISO 27001 to custom requirements – all in one system.
- €0 entry plan for 12 months
- ISO 27001 · BSI IT-Grundschutz · TISAX · NIS2
- Made in Germany

Why Catalog Manager?
Central Compliance Platform
Manage BSI IT-Grundschutz, ISO 27001, TISAX®, and custom catalogs in one unified system. No media breaks, no duplicate maintenance.
7 Object Types for Complete Coverage
Building blocks, requirements, measures, threats, vulnerabilities, damage scenarios, and controls – the complete compliance model.
Reusability & Efficiency
Create catalogs once and use them in risk analyses, protection needs assessments, and measure implementation. Saves time and increases consistency.
Audit-Ready Documentation
Transparent traceability of all requirements, measures, and controls for audits and certifications.
Responsibilities & Roles
Clear assignment of responsibilities at building block and requirement level. Flexibly combine framework defaults and internal roles.
Versioning & Change Journal
Track all changes to catalogs with automatic change journal and version management.
Key Takeaways at a Glance
BSI, ISO 27001, TISAX®, and custom catalogs in one system
Complete compliance model from building blocks to controls
Reusable catalogs accelerate risk analyses and implementation
Standard catalogs plus custom catalogs with versioning
Supported Frameworks & Standards
The Catalog Manager supports all common frameworks and standards as well as custom catalogs:
ISMS & Information Security
BSI IT-Grundschutz (Building blocks/requirements; incl. B3S/industry-specific standards)
ISO/IEC 27001, 27002 - Internationally recognized standards
TISAX® - Automotive-specific security standard
SOC 2 - Service Organization Controls
Business Continuity & Emergency Management
BSI 200-4 - Emergency management according to BSI
ISO 22301 - Business Continuity Management
AI & Other Management Systems
ISO 42001 - AI Management System
ISO 9001 - Quality Management
Custom Catalogs - Company-specific requirements
Upon request, we provide you with relevant standard catalogs and migrate existing content.
Typical Use Cases
Introduce New Technology
Review relevant standard catalogs, add specific threats and vulnerabilities, define measures, and seamlessly integrate everything into your risk analysis and ISMS processes.
Audit Preparation
Assign standard catalogs, compare actual measures, identify and prioritize gaps, and centrally bundle all evidence and controls for successful certification.
Standardize Protection Needs Assessment
Use questionnaires to standardize protection needs. Define questions per protection goal with clear evaluation criteria for normal, high, and very high.
Cross-Framework Compliance
Reference different frameworks simultaneously. For example, use ISO 27001 as the main framework but derive threats and measures from IT-Grundschutz.
Ready for Systematic Compliance?
Getting started is free: the free/Basic plan is €0 for 12 months.