CISO Assistant is a governance, risk, and compliance platform for managing cybersecurity programs. It includes more than 150 cybersecurity frameworks, standards, and regulations, and teams can add custom frameworks. Risk capabilities include ISO 27005 and EBIOS RM methods, cyber risk quantification, and business impact analysis. Audit tools support campaigns, evidence management, findings tracking, audit logs, and reminders. A dedicated third-party risk module handles supplier and partner evaluations, ownership assignment, and remediation monitoring. Listed connections include Jira and ServiceNow for ticketing and asset synchronization, Kafka for event streaming, and outgoing webhooks. Automation options include a REST API, CLI, and MCP support for compatible AI assistants or agents. Community is free, self-hosted, and allows unlimited users with community support. Pro is available as SaaS or on-premises; the Pro SaaS plan is listed at €39.00 EUR per month when billed annually. A free 30-day cloud trial requires no credit card. Pro on-premises can run inside the customer perimeter, including air-gapped environments.
Who it is for
CISO Assistant suits cybersecurity teams handling frameworks, risk work, audits, and supplier assessments. The vendor describes Pro SaaS for small teams and Pro on-premises for mid-sized and large teams.
What is good
- Includes more than 150 frameworks and supports custom ones.
- Risk features include quantification and business impact analysis.
- Third-party module tracks evaluations and remediation.
- Free self-hosted Community plan has unlimited users.
- 30-day cloud trial requires no credit card.
What to know first
- Community plan provides community support.
- SCIM provisioning is a Pro feature.
- Pro SaaS is €39.00 EUR per month when billed annually.
Freedom251 review
CISO Assistant: the full review
CISO Assistant covers framework management, risk, audits, and third-party assessments, with both self-hosted and SaaS or on-premises options. The free Community tier is self-hosted; Pro SaaS is billed annually at €39.00 EUR per month, and a 30-day cloud trial is available.
Overview
CISO Assistant is a cybersecurity governance, risk and compliance platform for organizations coordinating controls, assessments and remediation across a security program. It is best suited to teams juggling multiple frameworks, audits or supplier reviews. Its main advantage is breadth paired with flexible deployment; the trade-off is that paid plans have different seat, storage and hosting terms to weigh before committing.
For teams that need a focused audit workflow or a single-framework tool, this breadth may be more than necessary. It is a stronger fit when compliance, risk and third-party oversight need to sit alongside one another.
Key features
Frameworks and risk
The platform covers more than 150 cybersecurity frameworks, standards and regulations and allows custom frameworks. Examples include NIS2, DORA, ISO 27001, SOC 2, GDPR, NIST CSF, HIPAA, CMMC, PCI DSS, ISO 22301, ISO 42001, TISAX and IEC 62443. Control mapping, evidence collection, risk assessments and remediation workflows connect requirements to follow-up work, making the breadth useful for teams handling overlapping obligations rather than just checking off one standard.
Risk management supports ISO 27005 and EBIOS RM, cyber risk quantification and business impact analysis. That combination gives teams a way to connect compliance work with business exposure; organizations that only need a narrow checklist may not benefit from the extra scope.
Audits and third parties
Audit campaigns, evidence management, findings tracking, audit logs and reminders support preparation and follow-through. A dedicated supplier and partner module adds evaluations, ownership assignment and remediation monitoring. This makes CISO Assistant relevant to teams that need to track external-party risk as part of the same program, though the combined scope may be unnecessary for companies seeking only a lightweight audit tool.
Integrations and automation
Jira and ServiceNow support ticketing and asset synchronization; Kafka supports event streaming, and outgoing webhooks provide another way to connect processes. A REST API, CLI and MCP support integration and automation, including connections to compatible AI assistants or agents. These options suit teams with established workflows to connect, but they matter less to organizations looking for a standalone tracker.
Identity and deployment security
SAML and OIDC single sign-on, role-based access control and multi-factor authentication support access management; SCIM provisioning is reserved for Pro. Pro can run as SaaS or on-premises, including inside a customer perimeter or in an air-gapped environment. The vendor says SaaS tenants use isolated application instances and separate storage volumes, with TLS 1.3 in transit and disk-level encryption at rest. Intuitem says its security program aligns with NIST CSF and OWASP ASVS, uses ISO 27001 certified hosting providers and includes annual independent penetration testing.
Pricing
The free Community plan costs 0.00 EUR per free, billed forever. It is self-hosted, allows unlimited users and includes community support under AGPLv3. That is a substantial starting point for teams able to manage their own installation, but it does not include Pro support or Pro-only SCIM provisioning.
Pro SaaS costs 39.00 EUR per month, billed annually, per contributor, with 100 readers included and 10 GB of storage. An unlimited-seat option is available. This suits smaller teams wanting a hosted service, but the contributor-based price and storage allowance need to be considered as participation and evidence volumes grow. The separate Storage Bundle costs 960.00 EUR per year for an additional 100 GB.
Pro On-premises costs 2400.00 EUR per year, billed annually, per instance, for 1–5 seats at the listed price; volume discounts are available. It suits organizations that need to keep deployment within their own perimeter, but larger teams should account for the volume pricing rather than treating the listed price as an unlimited-seat rate.
Unlimited Seats SaaS costs 8500.00 EUR per year for unlimited users and standard compute resources. SecNumCloud Instance - Unlimited costs 14500.00 EUR per year for unlimited users, SecNumCloud certified hosting and a dedicated node. These options make the seat model clearer for larger teams, with the latter adding a specific hosting and infrastructure configuration. Custom pricing is available for specific deployment needs, customization, proprietary framework integration and professional services.
A free 30-day cloud trial requires no credit card, and trial data can be migrated to production. Pro subscriptions include priority support; customer success management is listed from six seats. The trial offers a practical way to assess the hosted workflow, while the forever-free plan is the longer-term option for self-hosting with community support.
Platforms
CISO Assistant supports API, Linux, self-hosted and web use. Community is self-hosted, while Pro is offered as SaaS or on-premises. Air-gapped on-premises deployment is a meaningful option for organizations that cannot use a connected hosted service, but it also makes the hosting choice central to plan selection.
Who it's for
Pro SaaS is positioned for small teams, while Pro on-premises is suited to mid-sized and large teams. The free Community tier is a fit for organizations prepared to self-host and rely on community support. Larger groups should compare the contributor-based SaaS arrangement, unlimited-seat SaaS and per-instance on-premises pricing against their seat needs; teams with specialized deployment or integration requirements can seek a custom quote.
Pros and cons
- Pros: More than 150 frameworks plus custom-framework support can serve programs working across several standards and regulations.
- Pros: Risk, audit and third-party modules bring assessments, evidence, findings and remediation into a wider compliance program.
- Pros: Self-hosted, SaaS and on-premises choices include an air-gapped deployment path for organizations with strict perimeter requirements.
- Pros: A forever-free, unlimited-user Community plan lowers the cost of trying a self-managed setup.
- Cons: Community is self-hosted and has community support, so it is less suitable for teams that require vendor priority support.
- Cons: Pro SaaS charges per contributor and includes 10 GB storage, which can make seat and evidence growth relevant to budgeting.
- Cons: The listed Pro On-premises price covers 1–5 seats per instance, so it is not a simple flat-price option for larger teams.
- Cons: Unlimited-seat SaaS and SecNumCloud hosting have substantially higher annual prices than the entry SaaS rate.
Alternatives
ComplianceOS is worth considering for teams that prioritize an open-source Community edition under the MIT license, with 30+ frameworks and 1000+ pre-built controls. Choose OpenGRC if self-hosting and full source-code access in its free Community plan are central requirements. Strike Graph may suit a team starting with its free Launch plan for SOC 2 security TSC, limited policy templates and cloud-provider and office-suite combinations. Unicis is another freemium web option.
ComplyGlobal is another freemium web option. NAVEX EthicsPoint Incident Management is a paid option for web, iOS and Android. AuditBoard (now Optro) offers paid flexible plans with unlimited stakeholder licenses and tailored services. IsoMetrix is a paid web, iOS and Android alternative.
Compare more options in Compliance Management Software and Governance, Risk and Compliance Software.
Verdict
CISO Assistant is a strong choice for organizations that need one cybersecurity GRC platform to coordinate frameworks, risk, audits and supplier assessments, especially when self-hosting or on-premises deployment matters. Its broad coverage and free unlimited-user Community tier are the clearest reasons to choose it. Look elsewhere if the need is limited to a single workflow, or if a per-contributor SaaS price and storage allowance do not fit the expected scale.
CISO Assistant plans and pricing
All plansCompared on compliance management software
- Free plan
- Yes
- Frameworks supported
- NIS2, DORA, ISO 27001, SOC 2, GDPR, NIST CSF, HIPAA, CMMC, PCI DSS, ISO 27005, EBIOS RM, ISO 22301, ISO 42001, TISAX, IEC 62443
- Control mapping
- Yes
- Evidence collection
- Yes
- Risk assessments
- Yes
- Remediation workflows
- Yes
- Vendor risk management
- Yes


