# DataGuard > The European leader in security and compliance software — one platform for ISO 27001, TISAX®, SOC 2, GDPR, NIS2 and the EU AI Act. DataGuard, the European leader in security and compliance software, is trusted by more than 4,000 organizations across 50+ countries. Its all-in-one platform helps businesses manage security risks, fast-track certifications, and comply effortlessly with industry frameworks including ISO 27001, TISAX®, SOC 2, GDPR, NIS2, and the European AI Act. By combining AI and automated workflows with tailored expert consultancy, DataGuard reduces the time and costs of building robust Information Security and Compliance Management Systems (ISMS & CMS). Founded in 2018, DataGuard has offices in Munich, Berlin, London, Stockholm, and Vienna, a team of 250+ experts, and a growing network of partners. ## Product - [Product Overview](https://www.dataguard.com/product/): Single-page overview of the combined Security & Compliance Platform — modules, AI automation, expert support, and outcomes. - [Security Platform](https://www.dataguard.com/product/security/): All-in-one ISMS for ISO 27001, TISAX®, SOC 2 & NIS2; covers risk, controls, assets, and audit readiness. - [Compliance Platform](https://www.dataguard.com/product/compliance/): Centralized privacy & compliance hub for GDPR, EU AI Act and whistleblowing — DPIAs, RoPA, DSRs, consent. - [Frameworks & Policies](https://www.dataguard.com/product/frameworks-policies/): Pre-built framework packages and policy templates that get programs certification-ready in weeks, not months. - [Risk Management](https://www.dataguard.com/product/risk-management/): Identify, assess, and treat security and privacy risks with a single, audit-ready risk register. - [Asset Management](https://www.dataguard.com/product/asset-management/): Inventory and classify information assets and link them directly to risks, controls, and owners. - [Controls](https://www.dataguard.com/product/controls/): Map, monitor, and evidence controls across multiple frameworks from a single source of truth. - [Third-Party Risk Management](https://www.dataguard.com/product/third-party-risk-management/): Onboard, assess and continuously monitor vendors and processors to manage supply-chain risk. - [DPIA & Risk Assessment](https://www.dataguard.com/product/dpia-risk-assessment/): Guided Data Protection Impact Assessments and privacy risk scoring aligned with GDPR Art. 35. - [Data Mapping & RoPA](https://www.dataguard.com/product/data-mapping-ropa/): Build and maintain a Record of Processing Activities and visualize data flows across the business. - [Data Subject Request Management](https://www.dataguard.com/product/data-subject-request/): Intake, workflow and audit trail for DSARs at scale, with built-in SLA tracking. - [Consent Management](https://www.dataguard.com/product/consent-management/): Capture, store, and prove granular marketing and processing consent across web and product touchpoints. - [Cookie Management](https://www.dataguard.com/product/cookie-management/): Compliant cookie banner and preference center for GDPR, ePrivacy, and TTDSG with auto-scanning. - [Whistleblowing](https://www.dataguard.com/product/whistleblowing/): Secure, anonymous reporting channel that meets the EU Whistleblower Directive. - [Employee Training & Awareness](https://www.dataguard.com/product/employee-training/): DataGuard Academy delivers role-based security and privacy training to keep all staff audit-ready. - [Reporting & Visualization](https://www.dataguard.com/product/reporting-visualization/): Live dashboards and exportable reports to communicate program status to execs, boards and auditors. ## Frameworks & Policy Templates - [ISO 27001](https://www.dataguard.com/frameworks/iso-27001/): Pre-built ISO 27001:2022 framework with Annex A controls, policies, and audit-ready evidence. - [NIS2](https://www.dataguard.com/frameworks/nis2/): Operationalize NIS2 with mapped controls, incident reporting workflows, and supply-chain risk coverage. - [TISAX®](https://www.dataguard.com/frameworks/tisax/): Tailored to the automotive supply chain (VDA ISA) with templates that get you to assessment readiness fast. - [GDPR](https://www.dataguard.com/frameworks/gdpr/): End-to-end GDPR program — RoPA, DPIAs, DSRs, consent, breach & vendor management in one platform. - [EU AI Act](https://www.dataguard.com/frameworks/eu-ai-act/): Classify AI systems, document obligations, and prepare governance for the EU AI Act roll-out. ## Who DataGuard Is For - [Customers](https://www.dataguard.com/customers/): Filterable hub of 4,000+ customers and case studies across industries, sizes, and frameworks. - [Enterprise Solution](https://www.dataguard.com/solutions/enterprises/): Multi-entity, multi-framework programs for global enterprises, with SSO, RBAC, and dedicated experts. - [SME Solution](https://www.dataguard.com/solutions/small-and-medium-sized-enterprises/): Bundled platform + advisory for SMEs to cut compliance costs by up to 50% and close key risks in 8 weeks. - [About Us](https://www.dataguard.com/about-us): DataGuard's story, leadership, offices (Munich, Berlin, London, Stockholm, Vienna), and 250+ experts. ## Solutions & Consultancy - [ISO 27001 Consultancy](https://www.dataguard.com/iso-27001-consultancy/): Expert-led ISO 27001 implementation combining the platform with hands-on consultants from gap assessment to certification. - [GDPR Consultancy](https://www.dataguard.com/en-gb/gdpr-consultancy): UK-focused GDPR consultancy package combining software with ongoing advisory from certified privacy experts. - [NIS2 Compliance](https://www.dataguard.com/frameworks/nis2/): End-to-end NIS2 readiness with mapped controls, risk management, and incident reporting workflows. - [Outsourced DPO Services](https://www.dataguard.com/outsourced-dpo-services/): Certified external Data Protection Officer acting as your contact to supervisory authorities, running DPIAs, training and breach response. - [Security Experts](https://www.dataguard.com/platform/security-experts/): Expert security support to strengthen programs, prepare for audits, and operationalize ISO 27001, TISAX®, SOC 2, and NIS2. ## ISO 27001 — Guides - [ISO 27001 Overview](https://www.dataguard.com/iso-27001/): Pillar page explaining what ISO 27001 is, who needs it, and how to approach implementation. - [ISO 27001 Requirements](https://www.dataguard.com/iso-27001/requirements/): Clauses 4–10 and Annex A controls explained, with practical implementation notes. - [ISO 27001 Benefits](https://www.dataguard.com/iso-27001/benefits/): Business case for ISO 27001 — sales acceleration, risk reduction, customer trust. - [ISO 27001 Certification](https://www.dataguard.com/iso-27001/certification/): Step-by-step certification path — gap assessment, Stage 1 & Stage 2 audits, surveillance audits. - [ISO 27001:2022 Transition Guide](https://www.dataguard.com/iso-27001/2022/): What's changed in the 2022 revision (93 Annex A controls, 4 themes) and how to transition. - [ISO 27001 Audit](https://www.dataguard.com/iso-27001/audit/): How internal and external ISO 27001 audits work, what auditors check, and how to prepare. - [ISO 27001 Costs](https://www.dataguard.com/iso-27001/certification/cost/): Breakdown of the main cost drivers behind ISO 27001 certification. - [ISO 27001 Risk Assessment](https://www.dataguard.com/iso-27001/risk-assessment/): Practical guide to identifying, evaluating, and treating information security risks in an ISO 27001 ISMS. ## NIS2 — Guides - [NIS2 Framework Overview](https://www.dataguard.com/nis2/): Pillar page on NIS2 scope, obligations, deadlines, and the 10 cybersecurity measures. - [NIS2 Requirements](https://www.dataguard.com/nis2/requirements/): Detailed breakdown of NIS2 obligations for "essential" and "important" entities. - [NIS2 Implementation](https://www.dataguard.com/nis2/implementation/): Practical roadmap to implement NIS2 controls, governance, and incident reporting. - [NIS2 Checklist](https://www.dataguard.com/nis2/checklist/): Self-assessment checklist to gauge NIS2 readiness across people, processes, and technology. - [NIS2 Certification](https://www.dataguard.com/nis2/certification/): How NIS2 conformity is demonstrated and the role of ISO 27001 in proving compliance. - [NIS2 Mapped to ISO 27001 Controls](https://www.dataguard.com/nis2/iso-27001-mapping/): Side-by-side mapping showing how ISO 27001 controls satisfy NIS2 obligations. ## SOC 2 — Guides - [SOC 2 Overview](https://www.dataguard.com/soc-2/): Pillar page on SOC 2 Trust Services Criteria, Type 1 vs Type 2. - [SOC 2 Requirements](https://www.dataguard.com/soc-2/requirements/): Detailed walkthrough of SOC 2 criteria across security, availability, confidentiality, and privacy. - [SOC 2 Compliance Software Guide](https://www.dataguard.com/soc-2/compliance-software/): Buyer's guide to SOC 2 compliance tooling and key vendor evaluation criteria. - [SOC 2 Certification](https://www.dataguard.com/soc-2/certification/): How a SOC 2 audit works, what auditors look for, and timeline expectations. ## GDPR — Guides - [GDPR Overview](https://www.dataguard.com/gdpr/): Pillar page covering GDPR principles, lawful bases, rights, and obligations. - [GDPR Compliance](https://www.dataguard.com/gdpr/compliance/): Practical guide to operationalizing GDPR compliance across people, processes and tooling. - [GDPR Software](https://www.dataguard.com/gdpr/software/): Overview of GDPR compliance software categories and how to choose the right platform. - [GDPR Fines](https://www.dataguard.com/gdpr/fines/): Notable GDPR fines, enforcement trends, and what triggers regulator action. ## EU AI Act — Guides - [EU AI Act Overview](https://www.dataguard.com/eu-ai-act/): Pillar page on EU AI Act scope, risk-tiering, obligations for providers and deployers. - [EU AI Act Timeline](https://www.dataguard.com/eu-ai-act/timeline/): Phased enforcement dates and what your AI governance program needs to deliver by when. ## Downloads - [ISO 27001 Toolkit](https://www.dataguard.com/downloads/iso-27001-toolkit/): Editable policy and process templates covering the full Annex A control set. - [ISO 27001 Documentation Checklist](https://www.dataguard.com/downloads/iso-27001-documentation/): Audit-ready checklist of every document and record required for ISO 27001 certification. - [ISO 27001 Implementation Roadmap](https://www.dataguard.com/downloads/iso-27001-roadmap/): Phase-by-phase plan from kick-off to Stage 2 audit, including milestones and owners. - [ISO 27001: Top 4 Most Failed Controls](https://www.dataguard.com/downloads/iso-27001-control/): Guide on the four controls auditors most often flag, with remediation steps. - [ISO 27001: Get Certified for the First Time](https://www.dataguard.com/downloads/iso-27001-get-certified-for-the-first-time/): E-book for first-time certifiers covering ISMS scoping, risk treatment, and audit prep. - [Data Privacy & Cookies Guide + Checklist](https://www.dataguard.com/downloads/cookie-downloads/): Practical guide and checklist to deploy a GDPR/ePrivacy-compliant cookie strategy. - [TISAX® Assessment Guide (DE)](https://www.dataguard.de/downloads/assessment-nach-tisax/): German-language guide to the TISAX® assessment process for automotive suppliers. ## Customer Success - [Customer Stories Hub](https://www.dataguard.com/customers/): Filterable index of customer case studies by industry, size, region, and framework. - [AppNavi](https://www.dataguard.com/customer/appnavi/): Tech / SMB / Germany (Security) — lean ISMS replaces an internal hire; ongoing effort down to 1–2 days/month, docs simplified 90%, ISO 27001 as a sales accelerator. - [Landmark Information Group](https://www.dataguard.com/customer/landmark/): Professional Services / UK (Compliance) — centralized privacy assessments, incidents and DSARs; replaced fragmented spreadsheets; always audit-ready. - [Cision](https://www.dataguard.com/customers/cision/): MarTech / Corporate (Compliance) — 40% more efficient data mapping, 3× faster cookie & consent, 10,000+ DSRs/year across 75,000 clients. - [Demodesk](https://www.dataguard.com/customers/demodesk/): SaaS / SMB (Compliance) — outsourced privacy program enabling a fast-growing SaaS to win enterprise customers without an in-house DPO. - [Applegreen](https://www.dataguard.com/customers/applegreen/): Hospitality / Ireland (Compliance) — privacy across 600+ locations in IE/UK/US centralized; one contact for RoPA, third-party risk, consent and retention. - [Aberdeen](https://www.dataguard.com/customers/aberdeen/): Professional Services (Compliance) — migration effort cut 50%; global privacy oversight across 23 countries from one platform. - [NBG Holding](https://www.dataguard.com/customers/nbg/): Manufacturing / SMB / Austria (Security) — ISO 27001 in under 12 months; central risk and asset management; faster security-questionnaire responses. - [Mistral Data](https://www.dataguard.com/customers/mistral-data/): Tech / SMB / UK (Security) — ISO 27001:2022 in 10 months; 120+ controls in an auditable ISMS with 2 people; unlocked rail-sector tenders. - [Behaviour Lab](https://www.dataguard.com/customers/behaviour-lab/): Financial Services / SMB / UK (Security) — ISO 27001 + GDPR achieved; Academy raised awareness; shortened client onboarding. - [vent.io](https://www.dataguard.com/customers/ventio/): FinTech / SMB / Germany (Security) — ISO 27001 in half the time vs consultants; passed audit first time; 100+ hours saved. ## Comparisons - [DataGuard Alternatives](https://www.dataguard.com/dataguard-alternative/): Comparison positioning DataGuard against other G2 leaders in the GRC / compliance category. ## Pricing - [Pricing & Plans](https://www.dataguard.com/pricing/): Overview of Base / Pro / Enterprise plans, included modules, and optional add-ons. ## Security & Trust - [Trust Center](https://trust.dataguard.com/): Self-serve portal to request ISO 27001/27701 certificates, SoA, pen-test summary, and sub-processor list. - [Privacy Policy](https://www.dataguard.com/privacy-policy/): DataGuard's own privacy notice describing how it processes visitor and customer personal data. - [Legal Notice](https://www.dataguard.com/en-gb/legal-notice/): Statutory legal notice (Impressum) with corporate details, registration and contact information. ## FAQs - [Which security and compliance frameworks does DataGuard support?](https://www.dataguard.com/): ISO 27001, TISAX®, SOC 2, GDPR, NIS2, and the EU AI Act — through a single platform combining pre-built frameworks, AI automation, and expert support. - [What pricing plans does DataGuard offer?](https://www.dataguard.com/pricing/): Three quote-based plans — Base (self-serve SaaS), Pro (platform + expert support, ISMS/privacy setup, data migration, External ISO), and Enterprise (large-scale, multinational or multi-framework). - [What add-ons can I purchase on top of a plan?](https://www.dataguard.com/pricing/): Consent & Preference Management, Cookie Management, Whistleblowing, Global Legal Analysis, Actionable Exposure Management, External Information Security Officer, and External Data Protection Officer. - [How fast can I become certified with DataGuard?](https://www.dataguard.com/frameworks/iso-27001/): Up to 75% faster than traditional approaches, with up to 75% of ISO 27001 documentation and workflows automated (e.g. ISO 27001 in 9–10 months for AppNavi and Mistral Data). - [How much manual work can DataGuard save my team?](https://www.dataguard.com/): Up to 40% of tasks automated; ISO 27001 customers save up to 100 hours and report ongoing effort of just 1–2 days per month. - [What is DataGuard's audit success rate?](https://www.dataguard.com/frameworks/iso-27001/): A 100% first-try pass rate in external ISO 27001 and TISAX® audits. - [Can DataGuard act as our outsourced Data Protection Officer (DPO)?](https://www.dataguard.com/outsourced-dpo-services/): Yes — external DPO services include DPIAs, ongoing monitoring, acting as contact for supervisory authorities, training, and privacy policies and breach plans. - [Can DataGuard act as our external Information Security Officer (ISO)?](https://www.dataguard.com/pricing/): Yes — available on the Pro plan and as an add-on. - [How do I know if NIS2 applies to my organization?](https://www.dataguard.com/nis2-checker): Use the free NIS2 Checker. NIS2 generally applies to "essential" and "important" entities in high-criticality sectors with 50+ employees or €10M+ revenue. - [What's the difference between SOC 2 Type 1 and Type 2?](https://www.dataguard.com/soc-2/): Type 1 assesses control design at a point in time; Type 2 evaluates operating effectiveness over 3–12 months. Most enterprise buyers require Type 2. - [What integrations does the DataGuard platform support?](https://www.dataguard.com/pricing/): Pre-built integrations and APIs across tools including Asana, Jira, HubSpot, Salesforce, and Mailchimp. - [How can prospects access DataGuard's own security & compliance documentation?](https://trust.dataguard.com/): Through the Trust Center — request ISO 27001 / 27701 certificates, the Statement of Applicability, pen-test summaries, and product security docs; reviewed within ~24 hours. ## Contact - [Book a Demo](https://www.dataguard.com/book-meeting/): Schedule a tailored platform demo and consultation with a DataGuard expert. - [Pricing & Get a Quote](https://www.dataguard.com/pricing/): Plan overview with a quote request form for Base, Pro, and Enterprise. - [Company / Contact](https://www.dataguard.com/about-us): Office addresses, leadership contacts, and general inquiry channels.