HomeAbout UsPricingContact Us
FrameworksISO, SOC 2, NIST & more, explainedBlogArticles from the security deskDocumentationProduct guides & how-tosAPIBuild on the Platform APIMCP integrationConnect your AI to your workspaceEducationCSFaaS Pro, free for teachingFrequent questionsAnswers, straight
Log inBook a demo
HomeAbout UsPricingContact Us
Resources
FrameworksBlogDocumentationAPIMCP integrationEducationFrequent questions
Log inBook a demo
Ready when you are

Be audit-ready by default.

Start free with six frameworks, thirty policies, and one living picture of your security program.

Get started freeTalk to an expert

Cyber Security Framework as a Service: governance, risk and compliance, run from one living platform.

Compliance insights, monthly. No spam.

Product

PlatformPricingRequest a demoAccess CSFaaS

Resources

FrameworksBlogDocumentationAPIMCP integrationEducation programFrequent questions

Compare

Vanta pricingDrata pricingSecureframe pricingDrata vs VantaVanta competitorsDrata competitors

Company

About usContact usDarkProtect, managed services

Legal

Privacy policyTerms & conditions
CSFaaS is operated by Darkprotect (GIB) Limited, registered in Gibraltar (company number 125185). Registered office: Sovereign Place, 117 Main Street, GX11 1AA, Gibraltar.© 2026 CSFaaS, All rights reserved.All systems operational
Built for the work between audits

Compliance that stays ready.

Run frameworks, risks, policies, vendors, evidence and audits in one calm workspace. Every owner knows what is next. Every answer keeps its proof.

Start free Book a demo
No credit card · Full platform · Free for your first 2 users
G2★★★★★4.8/5on G2
I2S2NCN40+frameworks
100+integrations
app.csfaas.com Live
General Dashboard Profile
Audit Audit
Frameworks Frameworks
Policies & Controls Policies Controls
Risks Demands Risks Remediation
Catalogs Third Parties Systems
Integrations Integrations
Forms Forms
Evidences Evidences
Databases Databases Prompts
Settings Settings
Activity logs Activity logs
Workspace / DashboardSecurity program Live posture
Framework coverageImplementation across active standards3 active
ISO 27001v2022
76/93
SOC 2v2022In audit
38/51
NIST CSFv2.0
135/173
79%
Overall coverage249 / 317

elements implemented

2 of 3 audit-ready
Controls92%

320 of 348 implemented

Policies18 / 20

Current and approved

Risk registryRisk Heat Map
Current⌄
Impact
54321
121121111
12345
Likelihood
Open risks1311 placed
Critical risks3At or above appetite
Pending response5+2 vs Jul
Portfolio postureCurrent
52%Current exposure↓ 16 pts
62%Responses set8 of 13
Top critical risks3 open
RSK-021Third-party service outage→
RSK-018Privileged account misuse→
RSK-014Recovery target missed→
  • Very low
  • Low
  • Moderate
  • High
  • Very high

2 unassessed

Needs attentionNext work4 items
Supplier reviewDue in 3 days→
Access control policyApproval pending→
Backup evidenceOwner requested→
One program, every framework

Do the control once. Carry it forward.

Map one control to every obligation it satisfies. The owner, implementation and proof stay shared—even as the framework list grows.

Shared control · AC-04Privileged access review Implemented

Review elevated access, confirm accountable owners and retain the same proof for every mapped requirement.

OwnerJohn DoeSecurityReview cadenceQuarterlyNext · 30 Sep 2026EvidenceQ3 access review.pdfAttached · 18 Aug 2026
Reuse
ISO 27001A.5.18 · Access rights Inherited from AC-04
Owner, implementation and evidence remain shared.Explore 40+ frameworks
The framework library

40+ frameworks, ready out of the box.

I2ISO 27001S2SOC 2NCNIST CSFNNIS2DDORACCyFun
I2ISO 27001S2SOC 2NCNIST CSFNNIS2DDORACCyFun
The operating system for GRC

One workspace from scope to proof.

Thirteen connected modules run on the same living model of your organisation. Scope the program, operate the work and arrive at proof without rebuilding context between tools.

01 / 13
01Frameworks

Import a framework. Inherit the work.

Deploy ISO 27001, SOC 2 or NIST in minutes: controls, owners and maturity tracking included. Cross-mapping carries every implemented control into the next framework you adopt.

  • Controls cross-mapped between frameworks, so nothing is done twice
  • Version diffs imported automatically (2013 → 2022 remapped for you)
  • Implemented → partially → not applicable, tracked per element
See frameworks in action
app.csfaas.com Live
GeneralDashboardProfile
AuditAudit
FrameworksFrameworks
Policies & ControlsPoliciesControls
RisksDemandsRisksRemediation
CatalogsThird PartiesSystems
IntegrationsIntegrations
FormsForms
EvidencesEvidencesReviews
DatabasesDatabasesPrompts
SettingsSettings
Activity logsActivity logs
ISO/IEC 27001:2022, Annex A93 controls · 4 owners · evidence linked
94% covered
A.5.1Policies for information securityImplemented100%
A.8.12Data leakage preventionPartially implemented64%
A.8.16Monitoring activitiesNot implemented28%
A.5.19Supplier relationships securityNot applicable0%
Coverage by domain
Organizational91%
People88%
Physical76%
Technological68%
Versions
v2022ISO/IEC 27001:2022Active
v2013ISO/IEC 27001:2013Archived
Diff imported, 31 controls remappedAuto
One shared operating layerContext moves. Traceability stays.
Activity trailComments & ownershipAPI & MCPRole-based access
Integrations

Connect the stack you already trust.

Bring evidence into the same workspace through native connectors for core cloud, identity and engineering systems. Extend everything else through the CSFaaS API and MCP—without breaking the audit trail.

Amazon Web Services·Native evidence connector
Bring your own AI

Ask the program. Keep the guardrails.

Connect Claude, ChatGPT, Gemini, Mistral or any MCP-capable client to live CSFaaS context. The same row-level permissions still decide what each person can see and do.

  • OAuth connection with one-click revocation
  • Read-only by default; write access is explicit and audited
  • Every answer stays grounded in the user’s live workspace access
Explore MCP
Live program query

Which controls need attention before our ISO 27001 audit?

OAuthUser-scoped accessLive evidenceRequest logged
Governed answer3 controls need attention3 live citations
AC-04Access reviewDue 4dBC-02Recovery evidenceMissingTP-07Supplier reviewDue 8d
Built for the whole team

Compliance is a team sport.

Give security, legal, IT, leadership and external reviewers one shared place to move the program forward—without turning everyone into a GRC specialist.

  • Live presence and collaborative editing
  • Comments, mentions and a personal action inbox
  • Clear ownership without spreadsheet chasing
See how teams work together
NadiaSecurityIsaacITLeaLegalAriReviewer
Shared controlAC-04 · Privileged access reviewIn review

Confirm privileged accounts, owner approval and quarterly review evidence.

OwnerNadia · SecurityAssignedEvidenceAccess review · Q2AttachedReviewAri · Independent reviewReady
3 people here nowReview readiness82%
Evidence attachedAccess export · just now@Nadia clause approvedComment resolvedNadiaIsaacAri
Your workspace, your rules

Switch off everything you don’t need.

Under six core sections sit 155 capability-level choices. Start with a sensible shape, then keep only the workflows, fields and scoring logic your organisation actually uses.

  • Tailor 155 capabilities across the working program
  • Configure risk matrices, levels and review rhythms
  • Adapt catalogs without breaking shared traceability
Explore the platform
Workspace framingFeatures Live for everyone
Risk matrixChoose your depth
Catalog vocabularyMake every label yours
StatusesTypesLevels
4 sections shown to your team124 / 155 capabilities
Pricing

Free for everyone. Pay only as your team grows.

The full GRC platform is free for your first 2 users. After that it is a flat €79 per user, with optional add-ons for full audit history and extra storage. Connect your own AI over MCP, included with every seat. No per-framework fees, no hidden tiers.

Free

Everything included, for up to 2 users.

Free
Get started free
  • 2 users included
  • Unlimited frameworks, policies & audits
  • Unlimited risks, demands & remediation
  • Unlimited third parties, systems & forms
  • 7-day activity history
  • Full data portability via API
  • Bring your own AI (API & MCP), included
  • 5 GB secure storage
Most chosen

Pro

For your whole team. The first 2 users are always free.

€79/ user / month
Get started
  • Everything in Free, for your whole team
  • Unlimited members (first 2 free)
  • Add or remove seats anytime
  • Priority support

Enterprise

Tailored to your organization

Custom
Contact us
  • Unlimited users, policies, frameworks, assets, and evidence storage
  • Enterprise SSO integration (Microsoft Entra ID, Google Workspace, Okta, and custom identity providers)
  • Advanced connectors and automated evidence collection (AWS, Azure, GitHub, Jira, and more)
  • Custom integrations and feature development tailored to your compliance requirements
  • Dedicated instance, flexible deployment options, and enhanced security controls
  • White-glove onboarding, priority support, and dedicated compliance guidance
Compare every feature in detail
DarkProtect

Prefer experts to run it for you?

Our operating partner DarkProtect deploys and runs CSFaaS end to end: the platform, the program and the people behind it.

Meet DarkProtect
Managed Compliance

CSFaaS deployed and operated for you: continuous evidence, live posture.

Risk & Compliance Advisory

ISO 27001, SOC 2, NIST CSF, GDPR, DORA and NIS2 programs that pass review.

Security Assessments

Penetration testing, cloud and configuration review, and threat modeling.

Virtual CISO

Senior security leadership on demand: strategy, reporting and ownership.

Questions, answered

The short version.
No sales fog.

If your question is not here, book a demo and bring the awkward version. Those are usually the useful ones.

Can we start with one framework and add more later?

Yes. CSFaaS is designed around one shared control library, so the work you complete for one framework can be reused wherever requirements overlap.

Does CSFaaS replace our auditor or security team?

No. It gives them a cleaner operating system: live ownership, evidence, review history and audit workflows. You can run it yourself or pair it with DarkProtect services.

How is workspace data isolated?

Workspace separation is enforced in PostgreSQL through row-level security. Evidence is stored privately and served through time-limited signed links.

Can our AI tools work with the platform?

Yes. The Platform API and OAuth-enabled MCP server expose the same governed workspace data and respect each user’s live permissions.

What does it cost to try?

The full platform is free for the first two users, with no credit card required. Pro is €79 per additional user each month, or €790 yearly.

Why CSFaaS

Built for the work behind every audit.

01

Multi-Tenant Architecture

Manage multiple workspaces, clients, and business units with complete data isolation.

02

Multi-Framework Compliance

Streamline compliance across ISO 27001, NIST, GDPR, and 40+ frameworks automatically.

03

Real-Time Insights

Data-driven decisions with live dashboards, analytics, and audit-ready reports.

04

No Vendor Lock-In

Full data portability: pull everything over the API anytime, integrate seamlessly, scale without restrictions.

05

Scalable & Growth-Ready

Perfect for startups to enterprises, including managed service providers.

06

Role-Based Governance

Built-in collaboration tools with granular permissions and real-time workflows.

07

Full Customization

Tailor policies, workflows, and controls to meet your specific requirements.

08

Transparent Pricing

Start free, scale affordably, no hidden costs or surprise fees.

09

Always Up-to-Date

Continuous updates with new frameworks and evolving compliance features.

From the library

Latest compliance insights.

Frameworks decoded, regulations translated, practice over theory, from the team behind the platform.

Browse all articles
Your next audit can feel different

Make the next audit boring.

Put the program, the work and the proof in one place. Start with two users free, or bring us your current stack for a focused walkthrough.

Start free Book a demo