ISO 27001 NIS2 GDPR DORA Monte Carlo

WF ISMS — information security management that actually gets things done

A complete ISMS for ISO 27001, NIS2, GDPR and DORA in one place. Built-in AI and quantitative risk analysis with Monte Carlo give leadership numbers in SEK — not colours. From 2,995 SEK/month with 30 days free trial.

WF ISMS Dashboard
WF ISMS Riskhantering
WF ISMS Compliance

What does WF ISMS cover for compliance?

See your compliance status at a glance. Track implementation progress, open risks, active incidents and audit findings — all in real-time KPIs.

12Frameworks in parallel
93ISO 27001 Annex A controls
100%Swedish data residency
WF ISMS Dashboard

What is included in WF ISMS for full compliance?

Risk Management

Identify, assess and treat IT risks with a complete risk register. Categorize by type, assign risk levels and owners, and map each risk to the relevant framework — ISO 27001, NIS2 or GDPR.

Risk Management
Policies

Policies & Documents

Manage all your security policies with version control, approval workflows and framework mapping. Track which policies are approved, under review or need updating.

Security Controls

Pre-mapped controls for ISO 27001 Annex A, GDPR and NIS2. Track implementation status, assign responsible owners and monitor compliance progress across all frameworks simultaneously.

Controls
Incidents

Incident Management

Report, investigate and resolve security incidents with full traceability. Track severity, status and resolution across your organization. From phishing attacks to data breaches — everything documented.

Asset Register & Suppliers

Maintain a complete register of IT assets with classification and criticality. Assess supplier risks with DPA tracking and security evaluations. Know exactly what you have and who has access.

Assets
Audits

Audits & Reviews

Plan and track internal audits, external reviews and certification audits. Map each audit to the relevant framework and follow up findings with structured action plans.

Reports & Compliance Status

Generate compliance reports for ISO 27001, NIS2 and GDPR with one click. Export as PDF or send via email. Management review dashboards give leadership the complete picture.

Reports
Training

Training & Notifications

Track staff security training — awareness, compliance, technical and onboarding. Get real-time notifications for open risks, critical incidents and upcoming deadlines so nothing falls through the cracks.

Monte Carlo simulation built in — risk in SEK, not colours

WF ISMS is one of few ISMS platforms with built-in Monte Carlo simulation — the same method used by insurers, banks and the NIST FAIR model. Run thousands of simulations and report risk to leadership in real numbers.

Annual loss in SEK

Annual Loss Exposure (ALE) per risk and total portfolio in SEK — comparable across businesses and reporting cycles.

P50 / P95 / P99

See the "normal year" vs the "1-in-20 year" vs the tail risk. Percentile-based reporting that leadership can act on.

Loss Exceedance Curve

The probability that losses exceed each given level — board-ready visualisation of tail exposure.

Top-N Pareto analysis

Which 20% of risks account for 80% of exposure? Focus mitigation where it actually matters.

Treatment ROI

When is a security investment worth it? Return on investment and payback time calculated automatically.

Rust-based engine

A custom Rust simulation engine returns blazing-fast results — typically under one second even for large portfolios.

Hybrid mode lets you keep qualitative analysis (5×5 matrix, high/medium/low) for the broad screen of all 50+ risks, and quantitative analysis (SLE, ARO, ALE in SEK) for the 10 most important.

AI that accelerates reporting — in Swedish

Built-in AI helps you draft the documents that take the most time: audit readiness reports, risk treatment plans, control gap analyses and management overviews. The AI interprets your actual risk data and suggests sharp wording — you edit, approve and export.

  • Audit readiness report — are we ready for certification?
  • Risk treatment plan (ISO 27001 §6.1.3)
  • Control gap analysis across all frameworks
  • Management overview and Board Pack
  • NIS2 Compliance Snapshot
  • Custom prompts per organisation (Enterprise)
AI-generated ISMS reports

Built for organisations that take responsibility seriously

Approval workflows

Approval workflows for policies, BCP plans and security analyses with named reviewers and full traceability.

Tasks linked to evidence

Tasks and assignments linked to risks, controls and audit findings. Everyone knows what to do and when.

Complete audit log

Full audit log — who changed what, when and from where. Mandatory for ISO 27001 and NIS2 reporting.

Continuity planning (BCP/DRP)

BCP and DRP with RTO/RPO, test schedules and contact lists — directly tied to ISO 22301 and DORA requirements.

Swedish Protective Security Act

Built-in support for organisations under the Swedish Protective Security Act: SSA, SUA, classification and personnel vetting.

Webhooks & API

HMAC-signed webhooks with SSRF protection, REST API and SSO for integration into existing security stacks.

Why is compliance no longer optional in 2026?

With NIS2, GDPR and increasing cyber threats, every organization needs a structured approach to information security. An ISMS gives you control, traceability and a clearer basis for compliance work.

Regulatory compliance

Meet the requirements of ISO 27001, NIS2, GDPR and SOC 2 with pre-mapped controls and structured processes. Demonstrate compliance to auditors, customers and partners.

Reduce risk proactively

Identify and treat risks before they become incidents. A structured risk register with owners and action plans gives your leadership team full visibility and control.

Win customer trust

More and more customers require their suppliers to demonstrate information security. An ISMS shows that you take security seriously and gives you a competitive advantage in procurement.

Continuous improvement

An ISMS is not a one-time project. With built-in audit tracking, management reviews and KPI dashboards, your security work improves systematically over time.

How is your compliance data protected and kept private?

WF ISMS is built with security at its core. All data is encrypted at rest and in transit. The platform runs on our own servers in our own facilities in Stockholm — no third-party cloud, no external access.

  • AES-256 encryption at rest and in transit
  • Swedish servers in our own facilities
  • No third-party cloud or external access
  • Role-based access control
  • Complete audit log for all actions
  • GDPR compliant by design
WF ISMS

Get started in under 15 minutes

From registration to audit-ready report — in four easy steps.

1

Create account

Register your organization. No installation, no credit card.

2

Map your organization

Add assets, risks, policies and controls.

3

Implement controls

Map controls to frameworks, assign owners and upload evidence.

4

Follow up & report

Generate management reports, SoA and audit evidence as PDF.

Choose the right plan for your organization

All plans include a 30-day free trial. No credit card required to get started.

Starter

2 995 kr / month
or 32,950 SEK/year — save 8.3%

For small organisations and consultants who need a structured document repository.

  • ✓ Risks, policies, controls, incidents
  • ✓ GDPR Art. 30 records
  • ✓ Encrypted file attachments
  • ✓ Up to 5 users, 200 MB storage
Start free trial

Enterprise

19 995 kr / month
or 219,950 SEK/year — save 8.3%

For larger organisations that need quantitative risk analysis, advanced AI and unlimited scale.

  • ✓ Everything in Professional
  • ✓ Monte Carlo with PERT/Lognormal/Beta
  • ✓ Advanced AI incl. Board Pack & NIS2 Snapshot
  • ✓ Custom prompts per organisation
  • ✓ Unlimited users and storage
  • ✓ White-label
Start free trial

Need custom configuration? For banks, public authorities and critical infrastructure we offer dedicated implementation, integration and services — contact us for a quote.

Verified for Swedish operations and data storage

Webbfabriken is a verified member of Based in Sweden — a quality mark initiated by Bahnhof, one of Sweden's largest and most trusted internet operators. The mark is reserved for Swedish cloud providers with operations and data storage in Sweden. For you, this means clearer jurisdiction, a shorter delivery chain and an external guarantee that systems and information are actually handled in Sweden.

Operations in Sweden Data stored in Sweden Systems and operations in Sweden Clearer control and accountability
Read about Based in Sweden
Based in Sweden

External quality mark — verified by Bahnhof — for companies that want to know where their data resides, who runs the systems and which regulatory framework applies from the outset.

Are you affected by the NIS2 directive in Sweden?

The EU NIS2 directive introduces new cybersecurity requirements for many organizations. If you operate in critical sectors or provide essential services, you likely need to comply. WF ISMS helps you map requirements, implement controls and demonstrate compliance.

Ready to take control of your compliance?

Contact us to book a demo of WF ISMS and see how we can help your organization.

Frequently asked questions about WF ISMS

What is the difference between ISO 27001 and NIS2?
ISO 27001 is an international standard for information security management that organisations can certify against. NIS2 is an EU directive that places legal requirements on the security of essential and important entities. WF ISMS supports both frameworks with shared control mapping.
How does WF ISMS help me get certified?
WF ISMS helps you document and follow up all requirements in ISO 27001:2022 with full Annex A coverage (93 controls). The platform generates audit-ready reports such as Statement of Applicability (SoA), risk assessments and management reviews — everything the auditor needs to see.
Can I use WF ISMS for GDPR compliance?
Yes. WF ISMS includes GDPR Art. 30 records of processing, DPIA assessments, processing registers with legal basis and security measures. You can also track personal data incidents with NIS2-compliant reporting.
How much does an ISMS tool cost?
WF ISMS starts from 2,995 SEK/month for small organisations and consultants (Starter, up to 5 users). Professional is 7,995 SEK/month for mid-sized companies and Enterprise is 19,995 SEK/month with Monte Carlo simulation and advanced AI. Annual billing saves 8.3% across all tiers. All plans include 30 days free trial without credit card.
How secure is the platform itself?
WF ISMS uses AES-256-GCM encryption for all uploaded files and secrets, TOTP two-factor authentication with recovery codes, role-based access control (RBAC), CSRF/HSTS/CSP hardening, rate limiting per IP and user, brute-force protection with global IP lockout and full audit log. All data is stored in Sweden with separate databases per organisation (multi-tenant).
Which frameworks are supported beyond ISO 27001?
WF ISMS supports 12 frameworks in parallel: ISO 27001:2022, ISO 9001, ISO 18788, ISO 22301, NIS2, GDPR, PSC.1, SOC 2, PCI DSS, DORA, MSB frameworks and the Swedish Protective Security Act. Controls can be mapped to multiple frameworks simultaneously.
What is quantitative risk analysis and Monte Carlo?
WF ISMS is one of few ISMS systems with built-in Monte Carlo simulation — the same method used by insurers, banks and the NIST FAIR model. You set probability distributions for frequency and impact, the system runs thousands of simulations and reports Annual Loss Exposure (ALE) in SEK, P50/P95/P99 percentiles, Loss Exceedance Curves, top-N analysis (Pareto) and treatment ROI. The Rust-based simulation engine returns results in under a second.

Describe what you want to secure or investigate

We help you choose the right protection level, right product or the right next security step.

We usually reply within one business day.