Back to updates
New releaseJul 27, 2026

isms-builder v1.37.1

Self-hosted Information Security Management System — ISO 27001, NIS2, GDPR/DSGVO, BSI IT-Grundschutz

Share

ISMS Builder Banner

ISMS Builder

Self-hosted Information Security Management System — open source, no cloud required

CI Tests License: AGPL-3.0 Node.js Version

📖 Wiki — Docker-Image-Nutzung & Umgebungsvariablen, Architektur & Module, FAQ, Mitwirken (DE/EN)


⚠️ Security Warning: Fake repositories and copies distributing malware

ISMS Builder has no packaged "releases", installers, or downloadable ZIP files — the only legitimate source is this repository, cloned or downloaded directly from GitHub as plain source code. We are aware of at least one malicious repository impersonating this project (fake README, fake "Download" button linking to a ZIP disguised as a screenshot, containing a Windows malware loader — .cmd → .exe → Lua-DLL payload chain). Do not download or run any "isms_builder" ZIP/installer/exe from anywhere other than this repository. If you find a suspicious repo or site impersonating this project, please open an issue or a discussion so we can flag it.


Status: Active development — not yet a finished product. The core modules are functional and in use, but some features are incomplete and the platform is still growing. Contributions, feedback and real-world testing are very welcome — that is exactly why this was open-sourced.


🛡️ Related project: NIS2 Quick-Check — a free, standalone NIS2 self-check (10 domains × 5 questions, all 27 EU member states, all 24 EU official languages). Runs entirely in the browser, no backend, no install. Not part of ISMS Builder and not required to use it — just a companion tool for a quick first orientation.


What is ISMS Builder?

ISMS Builder is a self-hosted web platform for managing an Information Security Management System (ISMS). It covers the full compliance lifecycle — from policy authoring to audit evidence — for ISO 27001:2022, NIS2, GDPR/DSGVO, BSI IT-Grundschutz and other frameworks.

No cloud. No SaaS fees. Your data stays on your server.

Designed for SMEs, IT teams, and consultants who need a real ISMS tool without a five-figure vendor contract.


Intended Use and Scope

This project began as a working tool for a single ISMS practitioner and grew from there. It is open source because the work may be useful to others — not because it is a commercial product in disguise. Being explicit about that helps you decide whether it fits your situation.

What it is built for. A small ISMS team — often one person, sometimes a handful — that authors and maintains the documentation of a management system: policies, risks, assets, controls, evidence. The number of people who need an account is expected to stay small. Reaching a large audience works without accounts: policy acknowledgements are sent as token-based links, so recipients read and confirm a document without ever logging in, and without appearing in any user list.

What it expects of you. ISMS Builder is self-hosted, and everything that follows from that is yours: deployment, TLS, hardening, backups, updates, access control, and the data protection obligations for whatever you store in it. The project ships a reasonable default configuration, not a managed service.

What it is not. There is no hosted SaaS offering, no commercial support contract, and no service-level agreement. It is not a multi-tenant hosting product. It does not certify you against any standard, and it is not legal advice — it helps you organise and evidence the work, but the assessment remains yours and your auditor's.

Who maintains it. One person, alongside a full-time job. Issues and discussions are read and answered, usually within days; security reports are prioritised. Feature requests are welcome and genuinely shape the roadmap, but they compete for limited evenings. If your organisation depends on a fixed timeline or guaranteed response, a commercial vendor is the honest recommendation — and that is not a reason to avoid the project, only a reason to plan realistically.


Screenshots

LoginDashboard
LoginDashboard
Statement of ApplicabilityRisk Management
SoARisks
GDPR & DatenschutzAsset Management
GDPRAssets
Guidance & DokumentationReports
GuidanceReports

Run npm start and open https://localhost:3000 to explore the full demo dataset locally.


Feature Overview

Categories