
condignum typical implementation process:
Initial Assessment & Scoping: Organizations define cybersecurity needs and select relevant modules; requirements are mapped to standards and organizational context.
Platform Setup: Condignum team provisions a cloud or on-premises environment, configures dashboards, and sets user roles; integration options with third-party tools are enabled.
Data & Questionnaire Preparation: Users provide input via automated questionnaires and upload necessary documentation; the platform calibrates technical scan settings for IT infrastructure.
Automated Assessments: System runs vulnerability scans and processes questionnaire responses, generating a baseline Cyber Security Rating and report.
Result Review & Action Planning: Stakeholders review findings via dashboards, identify gaps, and prioritize remediation and compliance tasks with expert support.
Condignum is highly customizable to fit specific business needs across different industries and organizational sizes. Its modular design enables organizations to select only the features and risk management modules that match their unique cybersecurity maturity and compliance priorities, from foundational assessments to advanced threat modeling and third-party risk.
Users can tailor questionnaires, assessment workflows, and vulnerability scans to specific regulatory frameworks (such as ISO/IEC standards or industry regulations), ensuring assessments and controls genuinely reflect internal policies, asset types, and regional compliance obligations. The platform supports custom dashboard widget configuration, allowing stakeholders to track relevant risks, tasks, and deadlines without clutter or unnecessary information.
Integration capabilities further enable adaptation, as Condignum provides API-driven connectivity and plugin-based architecture for seamless inclusion of existing IT, asset management, ticketing, and cybersecurity platforms. Content packs—including checklists, hardening guides, and risk catalogs—are updated or refined with guidance from both internal and specialist expert teams to mirror emerging threats and sector-specific requirements.
Condignum provides onboarding, training, and support to help new users deploy and maximize the platform’s value. During implementation, organizations benefit from dedicated consulting by Condignum’s expert security specialists who guide initial setup, requirements mapping, and customization—ensuring a rapid and successful transition. The platform’s logical structure and intuitive user interface make it accessible even for those without deep cybersecurity expertise, allowing users to quickly learn operations without extensive external resources.
Customers receive access to a live help desk, email/phone support, and a continually updated online knowledge base/FAQ section for troubleshooting and best practices. Condignum’s support services also include user-centric dashboards with guided widgets that explain upcoming tasks and system status, along with direct integration assistance for linking Condignum to the existing IT landscape. Ongoing support further includes periodic updates to hardening guides, content packs, regulatory checklists, and responsive consulting to keep the platform aligned to emerging needs and threats.
Condignum protects data using layered technical and organizational controls aligned with GDPR and established security standards, focusing on confidentiality, integrity, and availability throughout the platform lifecycle.
Encryption in transit: All website and platform traffic is secured via TLS, indicated by HTTPS and the browser lock icon, to prevent interception during transmission.
Processor agreements and vetted hosting: Customer data is stored with contracted processors under GDPR Article 28 data processing agreements, ensuring audited, compliant hosting environments.
Technical and organizational measures (TOMs): Controls are implemented to prevent accidental or unlawful manipulation, loss, destruction, or unauthorized access, consistent with GDPR Article 32 expectations.
Data minimization and retention limits: Only necessary data is collected and retained for as long as required by purpose or legal obligations, reducing exposure risk.
Access control and ISMS alignment: Practices align with ISO/IEC 27001-style information security management, emphasizing role-based access, incident handling, and continuous improvement.
User rights and governance: Data subject rights are supported (access, rectification, erasure, restriction, portability, objection), with clear contact channels for exercising rights and escalation to the Austrian DSB if needed.
Condignum delivers cloud-based updates on a rolling cadence, with minor improvements and content pack refreshes pushed continuously and larger feature releases delivered periodically without customer-side maintenance windows or manual installs. Updates cover new modules or use cases (for example, NIS2 readiness, ISO 27001:2022 mappings, Cyber Trust Austria workflows), security-controls enhancements, and refreshed hardening guides and risk catalogs maintained by specialist teams. Changes are managed centrally in the SaaS platform, so customers receive new capabilities automatically; administrators can review what changed inside the platform’s dashboards and adjust workflows, controls, and policies accordingly.
Condignum’s policy on data ownership and portability is designed to ensure that customers retain clear rights over their information and can manage or migrate their data securely at any time. Customers always remain the sole owners of any data uploaded to or generated within the Condignum platform, including assessment results, documentation, risk catalogs, and compliance records.
The company explicitly adheres to GDPR requirements regarding data subject rights, granting customers the option to access, rectify, restrict, or erase their data and, importantly, to transfer their data to another system should they discontinue service or require migration for any reason. Condignum’s processes are structured to make exporting of all relevant information straightforward and secure—commonly via standard formats or by request through dedicated support channels—so organizations never face a lock-in or loss of proprietary risk, compliance, or security data.
Condignum’s terms for contract renewal and cancellation generally follow standard SaaS software practices, allowing for both flexibility and clear user rights.
Contracts renew either automatically for a new term (such as one year), or through a negotiated agreement before the current term expires. Customers are usually notified ahead of renewal deadlines, with a defined window (e.g., 30 to 90 days) to provide written notice if they do not wish to continue. This notice period allows customers to avoid unintentional auto-renewal and to negotiate changes in their service or contract details if necessary.
For cancellations, either party can terminate the agreement by providing written notice within the specified notice period before the next renewal or billing cycle. In the event of early termination by the customer before the end of the committed period, the agreement often stipulates that all outstanding fees for the remainder of the term become immediately due, and prepaid amounts may not be refunded unless explicitly stated otherwise.
Condignum software meets several key compliance standards crucial for modern cybersecurity and regulatory risk management. Most notably, it is designed to support organizations in achieving and maintaining GDPR compliance, providing full alignment with European data protection law for privacy, user rights, and secure processing of personal data.
The platform is built to map organizational processes and risk management functions to ISO/IEC standards, including ISO/IEC 27001 for Information Security Management, ISO/IEC 31000 for Risk Management, and ISO/IEC 27005 for Cybersecurity Risk Management. Condignum also supports ISO 27701 for Privacy Information Management, further strengthening its credentials for handling PII and compliance-oriented controls.
Beyond these widely recognized standards, Condignum facilitates compliance with the European NIS Directive and NIS2 requirements for operators of essential services—offering modules and qualified audit support to verify correct implementation of NIS controls in line with regional cyber resilience and sectoral risk mandates.

condignum
By Condignum GmbH