Skip to Content
Our product · Prism GRC

Compliance, right inside your Odoo.

NIS2, ISO 27001, CyFun: Prism GRC tells you where you stand, what is left to do, and who is on it. In the tool your team already uses, with no extra software.

CyFunISO 27001NIS2
GRC
My Tasks
Certification 2.0
Risk Management
Compliance Management
Assets
Configuration
47
CM
Good morning,
Claire Martin
Monday, 12 October 2026
19
Open
3
Late
4
To Approve
My GRC Tasks
7 categories
Risk Assessments
Risk assessments lifecycle
4
4
Open
1
Late
2
To Approve
18
Done
View All
Risk Treatments
Mitigation & treatment actions
3
3
Open
0
Late
1
To Approve
9
Done
View All
Incidents
Security & operational incidents
1
1
Open
0
Late
0
To Approve
6
Done
View All
Design Effectiveness
Control design evaluations
3
3
Open
1
Late
12
Done
View All
Operating Effectiveness
Control operating evaluations
0
Open
0
Late
27
Done
View All
Control Testing
Control testing & evidence
2
2
Open
0
Late
14
Done
View All
Policies
Policy approvals & reviews
1
1
Open
0
Late
1
To Approve
8
Done
View All
The Prism GRC home screen, inside Odoo.

Your situation

Click to jump straight to what concerns you.

How it works

Three steps from uncertainty to a clear plan.

You don't need to be a cybersecurity expert to get started. The tool guides you question by question.

01

Assess

A guided assistant asks a few questions about your organisation and measures your maturity level: beginner, intermediate or advanced.

02

Plan

The framework's controls are preloaded. You see the gaps, assess your risks and get a prioritised roadmap.

03

Manage

Every action is assigned to a person, with a due date. Evidence is centralised and the dashboard shows your progress.

NIS2

Does NIS2 apply to you? Start by knowing where you stand.

The directive requires risk management, incident handling and business continuity measures. In Belgium, the CCB relies on the CyFun framework to structure these requirements. Prism GRC turns them into concrete actions.

  • Preloaded CyFun controls
  • Gaps ranked by priority
  • Progress visible to management
Am I concerned by NIS2?
1/3
In which sector does your organisation operate?
Highly critical sectors
Energy
Transport
Banking
Financial market infrastructures
Health
Drinking water
Waste water
Digital infrastructure
ICT service management
Public administration
Space
Other critical sectors
Postal and courier services
Waste management
Chemicals
Food
Manufacturing
Digital providers
Research
None of these sectors
ISO 27001

Prepare the ISO 27001 audit without a mountain of files.

The 93 Annex A controls are organised by theme. You document your policies, attach evidence and track progress until audit day.

  • Statement of Applicability kept up to date
  • Risk register and treatment plans
  • Evidence attached to each control
Evidence for your customers

A security questionnaire? The answers are already there.

More and more customers ask their suppliers to prove their security level. Your policies and evidence are centralised: you answer in a few hours instead of a few weeks.

  • Policies and procedures in one place
  • Dated and versioned evidence
  • A sales argument against your competitors
Why in Odoo

Compliance lives where your company already works.

A separate GRC tool often ends up forgotten. Built into Odoo, it becomes part of everyday work.

No extra software

No new subscription, no new login to remember.

Your existing users

Odoo's teams and access rights are reused.

Assets you already know

Equipment, suppliers and employees are already in Odoo.

Built-in reminders

Compliance tasks land in everyone's activities.

FAQ

Your questions about Prism GRC.

The easiest way is to see the tool in a demo.

Which frameworks are covered?

CyFun, ISO 27001 and NIS2. Controls are preloaded and you can add your own internal requirements.

Do we need to use Odoo already?

Prism GRC runs inside Odoo. If you don't use it yet, we can set up an Odoo environment dedicated to compliance.

Does the tool replace an auditor?

No. It prepares you for the audit and saves you time, but certification is still issued by an accredited body.

How long does it take to get started?

After the demo, we open a test environment. The setup assistant gives you a first assessment in a single session.

Let's talk about your business.

Thirty minutes to understand your situation and see whether we can help. No commitment, no jargon.

WhereBased in Belgium · we work wherever you are
Send us a message