Changelog
What changed in the platform, newest first.
#CyberLearn courses are live
Security awareness courses for your team, in English, Dutch and French. Order a course on its course page; once it is active, you add each person and they get their own link.
Read moreMSP partners can give courses to their clients
As an MSP partner you can assign #CyberLearn courses to the client organisations you manage, at the partner price.
New templates reach existing organisations
Organisations set up earlier now get new templates too. If a page you already have gets a newer version, you see a notice and your page stays as it is.
Policy templates and CyFun guidance checked against the sources
We went through the policy templates and the guidance on CyberFundamentals controls and removed figures and claims we could not trace to a source. References to the GDPR and the AI Act were checked against the official texts and corrected.
Disconnecting an integration removes its data
When you disconnect an integration, the register entries it added are removed, and a sync that was still running can no longer write them back.
Passwords are stored more securely
Resetting a password now also signs you out on your other devices.
See per control what an integration proves
The page of a connected integration now shows, per control, what the data proves: which users or devices meet it and which exceptions are named.
Download a backup of your organisation
Organisation owners can download a full backup from Settings. It is a copy for your own records, separate from an audit export.
Out of scope, with a reason
Mark an asset out of scope and give the reason, which the auditor reads. Rules can keep whole groups of items out of scope, including items that future imports bring in.
Who is responsible for each control
Record for each control who carries it: the MSP, the client, or shared.
One supplier list
The supplier register now shows the suppliers from the asset register. Add, edit or remove a supplier in one place and it changes in both.
Installed software from NinjaOne, grouped by product
The asset register now lists the software installed on your own devices, imported from NinjaOne. Releases are grouped under their product, older releases that are still installed are flagged, and you can mark two entries as the same product.
Clearer access confirmation emails
The confirmation email you receive when you sign in now explains what it is and what each button does. It also names a contact person for questions.
App available in English, Dutch and French
Choose your language for the whole app: settings, workflows, charts and forms.
Meet Patch and Norm
Patch guides you through audits and suggests next steps in the app. Norm is an independent CyFun assessor that checks your compliance.
Risk assessment page redesigned
See your organization's risks, the controls that address them and the machines not yet covered. You can add internal risks and follow progress on one screen.
Generate a Statement of Applicability
The app lists your controls and shows which apply to your organization's size and CyFun level.
Two-factor authentication (optional)
Add a security key or an authenticator app to your account as a second step when you sign in.
Demo organization comes filled
The demo now has a filled risk register, improvement roadmap and asset inventory to look through.
Control page shows one list of work
See what needs doing, which controls cover it and which machines are still missing, in one list.
Controls validated by your connected tools
Once your systems are connected, the platform checks which controls are backed by the tools you have installed.
Learn articles show their CyFun level
Each security article now shows which CyFun level it relates to and links to the controls that need that topic.
Policy template library
Download ready-to-use policy templates for all CyFun levels, including access control, risk management and disaster recovery. Templates are available in English, Dutch and French.
GDPR and AI Act policy templates
New templates for the GDPR record of processing activities, breach response, processor agreements and AI risk management, in all three languages.
Statement of work generator for partners
MSP partners can create a scope of work and a nulmeting report for a customer and export it as a proposal or an internal handover document.
CyFun nulmeting report for partners
Run a baseline assessment for a customer and get a report of the starting point, in the language the organization has chosen.
Nulmeting report in your language
The baseline report is now available in English, Dutch or French, following the organization's language choice.
Work with GDPR and the AI Act next to NIS2
Switch between active frameworks in settings and manage GDPR, EU AI Act and NIS2 compliance in one view.
Better policy suggestions from the AI assistant
The AI assistant now suggests the most relevant of your existing policies for each control.
Mark entities out of scope
Exclude specific devices, users or locations from your compliance scope and see which controls remain covered.
Coverage matrix by device
See which controls cover each device, user or location, and spot the gaps.
Do-it-yourself compliance report
Order a pre-drafted NIS2 scope and baseline report. Start free with the quick check, or subscribe for the full report with quarterly updates.
See missing devices by name
Audit readiness now lists the devices or users your scope does not cover, instead of only a number.
Upload compliance evidence
Attach policy documents, meeting notes or screenshots directly to a control.
Import asset lists from a spreadsheet
Import devices that have several names or IDs, plus departments, locations and teams. You can adjust the column mapping before you import.
Detail page per device or user
See the controls, requirements and coverage that apply to one specific device or user.
Control status badges
Each control shows whether its status is calculated automatically, confirmed manually or overridden.
Co-branded microlearning for MSPs
Send weekly compliance topics to your customers' staff with your own logo and cartoons. Includes an editor, preview, delivery tracking and subscriber management.
NinjaOne backup and device data in one integration
NinjaOne backup and device management data now come in through a single integration card. You choose which parts to import.
Signed audit bundles
Exported audit bundles are now digitally signed, so your auditor can verify that they are authentic.
Try the platform with a demo
Explore a demo environment with sample data and a guided tour. It resets itself, so you cannot break anything.
Learning paths by role
The Learn hub now has separate tracks for SME owners, MSP practitioners and enterprise teams.
Integration overview
See all available integrations in one place: what data each one imports, which controls it covers and which ones are already active.
Concrete steps in audit readiness
Audit readiness now shows specific steps per control, highlights the top 5 quick wins, gives AI action hints and lets you link evidence in bulk.
Aikido endpoint risk detection
Vulnerability data on endpoints from Aikido Security now feeds your assessment, so you can see which devices are exposed and need fixing.
Audit bundle export and re-import
Export your compliance data as a bundle for your auditor. When they send feedback back, import it into your wiki to keep tracking it.
Control health dashboard
See the CMMI maturity score of every control on your dashboard and in the audit readiness list, and follow progress toward level 3.
SentinelOne endpoint detection
Endpoint detection and response data from SentinelOne now feeds your assessment, so you can compare it with your declared scope.
Audit readiness snapshots
Save a snapshot of your compliance status at any time and compare snapshots over weeks and months.
Language selector
Choose English, Dutch or French in Settings for policies, assessments, reports and framework guidance.
Microsoft 365 device sync
Connect your Microsoft 365 tenant once. Devices, security scores and audit logs then fill in answers to your intake questions.
Access and roles
The new Access tab lets you invite team members, give them a role (Owner, Auditor or Viewer) and control who sees what.
Audit readiness export to Excel
Export the audit readiness report as an Excel file with control status, maturity levels and an evidence summary to share with your auditor.
Policy wizard with AI drafting
Start from any control in your assessment and answer questions about your scope. The AI drafts the policy section by section, and you review and adjust each part before accepting it.
Improve policies in place with the assistant
Click Improve on a policy or procedure page and the assistant rewrites the section based on your scope and the control requirements. You accept or reject each edit inline.
Assessment hub with three views
View your assessment as a matrix, a Kanban board by status or a roadmap by priority.
AI assistant for compliance
Ask the assistant about NIS2, CyFun, your policies and your evidence. Answers show the framework sources they rely on.
Search and Documents tab
Press Cmd+K to search your policies, controls and evidence. The new Documents tab shows your compliance library as a tree.
Earlier changes
Controls grouped by function
See all your security controls in one view and browse them by function group to check your status.
Team chat
Talk with your team inside the app about your compliance work.
Team invitations
Invite colleagues to your workspace and manage their roles. New members start with a guided assessment.
Onboarding starts with the assessment
Setup now begins with your organization's assessment, so you find out where you stand first.
Document library and control templates
Start from ready-made procedures, policies and plans for your sector and framework, customize them and track their completion.
Scope and coverage tracking
See which devices, departments or locations each control applies to.
White-label branding
Add your own logo and brand colors. Your clients see your brand throughout the interface.
PDF report export
Export compliance reports and assessments as PDF files to share with stakeholders, auditors and authorities.
Evidence page redesigned
The evidence section now focuses on verification, with actions inline and a clearer layout showing what to do next for each control.
Plain-language assessment options
The dropdowns in the assessment now describe each option in plain language.
Evidence records scope and source
An evidence entry can now say which devices or entities it applies to and where it comes from.
Guided workflow with Navigator
The new Navigator walks you through your compliance work step by step, with plan pages that show what to do and in what order.
Feedback from inside the app
Send feedback from the app about what works and what does not.
Import devices and infrastructure from a spreadsheet
Upload a CSV file to import devices and infrastructure. Columns are matched to fields automatically.
Cyber-readiness check
A short guided assessment that shows where your cybersecurity stands today and what needs attention.
Controls as a searchable wiki
Your controls are now organized as a searchable wiki, with the evidence and procedures inside each control page.
Safer magic-link sign-in
Passwordless sign-in now also asks for a 4-digit code, so a forwarded or shared link is not enough to get into your account.
Organizations can be deleted again
Deleting an organization now removes it together with all its data.
Activity log
See who changed what and when across controls, checklists and entities. You can search, filter and add remarks.
Incidents dashboard
Track incidents in a dedicated dashboard with a chat-style log of what happened, who was involved and how it was resolved.
Accessibility improvements
Better support for screen readers, keyboard navigation and color contrast throughout the app.
Checklists with recurring tasks
Guided checklists replace the Evidence system. Set how often each control must be reviewed, and recurring checklists remind you when it is due.
Onboarding uses your own selections
Onboarding now works with the framework and controls you selected, so you can set up your compliance program step by step.
CyFun Basic framework
A lighter framework of 34 controls for small organizations that are starting with NIS2 compliance.
Manage your subscription in the app
See your current plan and the upgrade options, and switch plans without interrupting your work.
Automatic language detection
The app now detects your browser language and opens in it.
Manage team access and roles
Add team members, set their roles and permissions, and control how MSP partners access your organization.
Yearly billing option
Choose between monthly and yearly payment.
Partner onboarding portal
MSP partners can register and add customers themselves in a dedicated portal.
Sign in with magic links
No password needed: sign in with a secure link sent to your email. You can invite teammates with one click.
Comments and activity feed
Comment on tasks and evidence, and follow a live feed of changes in your organization.
Search bar and command palette
Find things with the search bar and move around with keyboard shortcuts.
Manage your IT inventory
Add your employees, devices, networks and workplaces. Search before you add, filter by type and edit details with simple forms.
Track networks and workplaces
Record your network infrastructure and workplace locations as part of your compliance inventory.