Compliance, right inside your Odoo.
NIS2, ISO 27001, CyFun: Prism GRC tells you where you stand, what is left to do, and who is on it. In the tool your team already uses, with no extra software.

Your situation
Click to jump straight to what concerns you.
Three steps from uncertainty to a clear plan.
You don't need to be a cybersecurity expert to get started. The tool guides you question by question.
Assess
A guided assistant asks a few questions about your organisation and measures your maturity level: beginner, intermediate or advanced.
Plan
The framework's controls are preloaded. You see the gaps, assess your risks and get a prioritised roadmap.
Manage
Every action is assigned to a person, with a due date. Evidence is centralised and the dashboard shows your progress.
Does NIS2 apply to you? Start by knowing where you stand.
The directive requires risk management, incident handling and business continuity measures. In Belgium, the CCB relies on the CyFun framework to structure these requirements. Prism GRC turns them into concrete actions.
- Preloaded CyFun controls
- Gaps ranked by priority
- Progress visible to management
Based on your answers, your organisation would be considered an essential entity.
- Put cybersecurity risk-management measures in place, for example with the CyFun framework.
- Report significant incidents to the CCB, with an early warning within 24 hours.
- Your management approves the measures, follows training and is accountable for them.
- Register with the CCB and have your compliance assessed regularly.
Based on your answers, your organisation would be considered an important entity.
- Put cybersecurity risk-management measures in place, for example with the CyFun framework.
- Report significant incidents to the CCB, with an early warning within 24 hours.
- Your management approves the measures, follows training and is accountable for them.
- Register with the CCB. Supervision takes place after an incident or when non-compliance is suspected.
Based on your answers, your organisation is not in scope. Your customers may still ask you for security guarantees if they are concerned themselves.
- Check what your customers require: the directive also covers their supply chain.
- A recognised framework such as CyFun or ISO 27001 reassures them.
Prepare the ISO 27001 audit without a mountain of files.
The 93 Annex A controls are organised by theme. You document your policies, attach evidence and track progress until audit day.
- Statement of Applicability kept up to date
- Risk register and treatment plans
- Evidence attached to each control
A security questionnaire? The answers are already there.
More and more customers ask their suppliers to prove their security level. Your policies and evidence are centralised: you answer in a few hours instead of a few weeks.
- Policies and procedures in one place
- Dated and versioned evidence
- A sales argument against your competitors
Compliance lives where your company already works.
A separate GRC tool often ends up forgotten. Built into Odoo, it becomes part of everyday work.
No extra software
No new subscription, no new login to remember.
Your existing users
Odoo's teams and access rights are reused.
Assets you already know
Equipment, suppliers and employees are already in Odoo.
Built-in reminders
Compliance tasks land in everyone's activities.
Your questions about Prism GRC.
The easiest way is to see the tool in a demo.
Which frameworks are covered?
CyFun, ISO 27001 and NIS2. Controls are preloaded and you can add your own internal requirements.
Do we need to use Odoo already?
Prism GRC runs inside Odoo. If you don't use it yet, we can set up an Odoo environment dedicated to compliance.
Does the tool replace an auditor?
No. It prepares you for the audit and saves you time, but certification is still issued by an accredited body.
How long does it take to get started?
After the demo, we open a test environment. The setup assistant gives you a first assessment in a single session.
Let's talk about your business.
Thirty minutes to understand your situation and see whether we can help. No commitment, no jargon.