- The build option (Excel, SharePoint, custom scripts) is initially cheap and flexible but becomes a maintenance nightmare beyond a certain complexity with high manual effort.
- Specialized ISMS tools save time long-term on risk assessment, document management, measure tracking, and audit preparation, but cost license fees and require onboarding.
- The decision depends on company size, ISMS maturity level, available IT resources, and certification goals.
- Hybrid approaches often work best in practice: a specialized tool for core management, supplemented by existing systems for sub-processes.
- The hidden costs of the build option (maintenance, knowledge transfer, auditability) are systematically underestimated. For the build option, calculate all costs over three years, not just the first year.
The Excel Trap: Why This Topic Matters More Than It Sounds
Almost every ISMS in a mid-market company starts with Excel. This is understandable: Excel is available, the learning curve is zero, and it is perfectly adequate for the first steps. You create a risk assessment as a spreadsheet, track measures in another worksheet, store policies as Word documents on the network drive, and manage training records in a third file.
Six months later, you have 15 files in four different folders, three of them with the suffix "_v2_final_corrected." The ISM spends half a day per week manually synchronizing data between spreadsheets. The risk assessment is no longer current because the last update was two months ago and nobody knows for certain which version is current. The external auditor asks about the relationship between a risk and the corresponding measure, and you need ten minutes to find the right row in the right spreadsheet.
This is not an exaggeration. It is the normal state in organizations that run their ISMS with off-the-shelf tools. And it is the point at which the question "build vs. buy" shifts from a theoretical consideration to an operational necessity.
What "Build" and "Buy" Mean
Before we dive into the analysis, let us clarify the terms.
Build: Custom Development and Off-the-Shelf Tools
"Build" does not mean you program your own ISMS software. It means you combine and adapt existing tools to represent the ISMS processes. Typical build variants:
- Excel and Word: The basic variant. Risk assessment as a spreadsheet, policies as Word documents, measure tracking as another spreadsheet.
- SharePoint and Microsoft 365: SharePoint lists for risks and measures, Power Automate for workflows, Teams channels for communication, OneDrive for document management.
- Confluence and Jira: Policies as Confluence pages, measures as Jira tickets, dashboards for the overview.
- Custom development: An internally developed tool, for example a web application or database solution tailored exactly to your own processes.
- Hybrid solutions: A combination of several of the above approaches, often evolved rather than planned.
Buy: Specialized ISMS Software
"Buy" means you use a dedicated tool specifically designed for operating an ISMS. These tools represent the core ISMS processes: risk assessment, measure management, document management, audit management, training records, and reporting.
The range extends from lean solutions tailored to SMEs to comprehensive GRC platforms (Governance, Risk, Compliance) that cover not only ISMS but also data protection, IT governance, and compliance management.
The Build Option in Detail
Advantages of the Build Approach
No additional license costs. If you already have Microsoft 365 or Atlassian licenses, using them for the ISMS incurs no direct additional costs. This is a strong argument, especially in budget-sensitive environments.
Maximum flexibility. You can adapt the tools exactly to your processes. If your risk assessment process uses an unusual methodology or you need industry-specific additional fields, you are not bound by a tool's specifications.
Familiar environment. Employees already know Excel, SharePoint, or Confluence. Onboarding time is minimal, and you do not need training for a new tool.
Quick start. You can begin immediately. No procurement, no implementation, no configuration. On day one of the ISMS project, you create the first Excel spreadsheet and start working.
Disadvantages and Hidden Costs
Manual data linking. The biggest problem with the build option is the lack of linkage between different ISMS processes. In a specialized tool, a risk is automatically linked to the associated assets, measures, and controls. In Excel, you must maintain these links manually. This costs time, is error-prone, and makes audit preparation cumbersome.
Version chaos. Who has the current version of the risk assessment? Is the policy on the network drive still current, or is there a newer version in the ISM's email inbox? Without a dedicated versioning system for ISMS documents, chaos ensues — and it becomes embarrassing in an audit.
No audit trail. ISO 27001 and other standards expect you to trace who made which change to a document or risk assessment and when. Excel does not offer this. SharePoint offers rudimentary versioning but not a complete audit trail.
Scaling problems. What is still manageable with 30 risks and 50 measures becomes unwieldy with 100 risks and 200 measures. Excel spreadsheets with hundreds of rows and dozens of columns are no longer an effective management instrument.
Knowledge dependency. Who wrote the Excel macros? Who understands the SharePoint workflows? Who knows the linking logic? If the ISM leaves the company, their successor faces a system that only one person understood.
Maintenance effort. The initial creation is cheap, but ongoing maintenance is expensive. Every change to the risk assessment methodology requires manual adjustments to the spreadsheet. Every new reporting format requires new pivot tables or charts. The cumulative effort over three years often exceeds the cost of a dedicated solution.
The Buy Option in Detail
Advantages of Specialized ISMS Tools
Integrated process landscape. Everything is connected: risks are linked to assets and measures. Measures are linked to controls. Controls are linked to policies. This creates a consistent picture that you can demonstrate in an audit with just a few clicks.
Audit trail and traceability. Every change is logged. Who changed the risk assessment when? When was the policy last approved? Who marked the measure as implemented? This traceability is worth its weight in gold during an audit.
Standardized templates and frameworks. Good ISMS tools include templates for risk assessments, policies, and controls aligned with recognized standards like ISO 27001 or BSI IT-Grundschutz. This saves setup time and ensures you do not miss anything essential.
Automated reporting. Status reports, maturity analyses, open measures, risk overviews: the tool generates all of this at the push of a button. Instead of investing hours in creating a management report, you produce it in minutes.
Reminders and workflows. Due measures, upcoming reviews, expiring policies: the tool automatically reminds the responsible parties. In an Excel world, the ISM must manually monitor these deadlines and contact individuals.
Disadvantages and Risks
License costs. ISMS tools cost money. The price range extends from 200 euros per month for lean solutions to 5,000 euros and more per month for enterprise GRC platforms. These costs must be considered over the entire usage period.
Onboarding time. Every new tool requires onboarding. The ISM must understand and configure the tool. Risk owners must learn how to assess risks in the tool. Management must be able to read the dashboards. Plan for two to four weeks of onboarding before the tool is used productively.
Vendor lock-in. Your entire ISMS documentation, risk assessments, and measure history reside in one tool. If the vendor raises prices, discontinues operations, or develops the software in a direction you do not like, you have a problem. Look for export capabilities and open data formats.
Feature overload. Enterprise GRC platforms often offer so many features that a mid-market company uses only a fraction of them but pays the full price. And the tool's complexity can reduce user acceptance.
Customization limits. No tool fits your processes perfectly. In some cases, you must adapt your processes to the tool, not the other way around. This can be sensible (if the tool enforces best practices) or problematic (if it unnecessarily complicates your proven workflows).
Three-Year Cost Comparison
A fair comparison must consider total costs over at least three years, not just the acquisition costs in the first year. Here is a simplified calculation for a company with 150 employees.
Build Option (Excel and SharePoint)
| Cost Item | Year 1 | Year 2 | Year 3 | Total |
|---|---|---|---|---|
| License costs | 0 euros | 0 euros | 0 euros | 0 euros |
| ISM effort for tool maintenance | 200 hours | 150 hours | 150 hours | 500 hours |
| Reporting effort | 80 hours | 80 hours | 80 hours | 240 hours |
| Audit preparation (gathering data) | 40 hours | 30 hours | 30 hours | 100 hours |
| Error correction (broken links, version conflicts) | 30 hours | 40 hours | 50 hours | 120 hours |
| Total hours | 350 hours | 300 hours | 310 hours | 960 hours |
At an internal hourly rate of 60 euros, this results in personnel costs of approximately 57,600 euros over three years, plus the risk of errors, inconsistencies, and an audit finding due to insufficient traceability.
Buy Option (Specialized ISMS Tool)
| Cost Item | Year 1 | Year 2 | Year 3 | Total |
|---|---|---|---|---|
| License costs | 6,000 euros | 6,000 euros | 6,000 euros | 18,000 euros |
| Onboarding and configuration | 80 hours | 0 hours | 0 hours | 80 hours |
| ISM effort for tool maintenance | 60 hours | 50 hours | 50 hours | 160 hours |
| Reporting effort | 20 hours | 20 hours | 20 hours | 60 hours |
| Audit preparation | 15 hours | 10 hours | 10 hours | 35 hours |
| Total hours | 175 hours | 80 hours | 80 hours | 335 hours |
Personnel costs: approximately 20,100 euros. Plus 18,000 euros in license costs. Total costs: 38,100 euros over three years.
The difference of almost 20,000 euros may sound small, but it ignores the qualitative advantages: better audit results, fewer errors, higher user acceptance, and the ability to use the ISM for value-adding work instead of data maintenance. A tool like ISMS Lite costs ab 500 Euro pro Jahr oder als Einmalkauf für 2.500 Euro and thus falls well below the 6,000 euros per year in the above calculation, while providing an integrated process landscape with risk assessment, measure tracking, and audit trail.
Decision Matrix: What Fits Your Organization?
Not every organization immediately needs a specialized tool. And not every build approach is doomed to failure. The right decision depends on your specific situation.
Build makes sense when ...
- You are just starting with the ISMS and do not yet know the exact scope
- The company has fewer than 50 employees and the ISMS is manageable
- No budget is available for a tool and you first need to prove that an ISMS works
- You are managing only a handful of risks and measures
- No certification is sought and the ISMS primarily serves internal purposes
Buy makes sense when ...
- The company has more than 50 employees and the ISMS complexity is growing
- An ISO 27001 certification is sought or already in place
- Multiple people work on the ISMS and need a shared data foundation
- Regulatory requirements (NIS2, TISAX, DORA) demand traceable ISMS documentation
- The ISM spends more than half a day per week on tool maintenance instead of substantive work
Hybrid Approach as a Compromise
In practice, hybrid approaches often work best. You use a specialized tool for core management (risk assessment, measure tracking, document management) and retain proven tools for sub-processes. Training continues through your LMS. Technical measures are tracked in the IT ticket system and referenced in the ISMS tool. Policies are managed in the ISMS tool but published via the intranet.
The key is that one system serves as the "single source of truth" for ISMS status. Regardless of where the operational work takes place, the overall picture must come together in one place.
Selection Criteria for ISMS Tools
If you decide on the buy approach, you face a market overview with dozens of vendors. The following criteria help you with the selection.
Must-Have Criteria
- ISO 27001 coverage: The tool must represent the core processes of ISO 27001 (risk assessment, SoA, measure management, audit management, management review)
- Usability: If the tool is so complex that only the ISM can operate it, you have gained nothing. Risk owners and management must be able to work with it intuitively
- Export capabilities: You must be able to export your data at any time in open formats (CSV, PDF, JSON). This protects you from vendor lock-in
- Audit trail: Complete traceability of all changes with timestamp and user identification
- Hosting model: Cloud or self-hosted? Depending on industry and regulatory requirements, a self-hosted model may be necessary
Nice-to-Have Criteria
- Templates and frameworks: Included templates for ISO 27001, NIS2, BSI IT-Grundschutz save setup time
- API interface: For integration with existing systems (ticket system, CMDB, monitoring)
- Automated reminders: Due date notifications for measures, reviews, and policy updates
- Dashboard and reporting: Clear presentation of ISMS status for different audiences
- Multi-tenancy: Relevant if you want to manage multiple organizational units or locations separately
The Right Time to Switch
If you currently work with Excel and are considering switching to a specialized tool, timing matters. A switch in the middle of the hot phase of audit preparation is not a good idea. Nor is a switch when you are just starting with the ISMS and do not yet know which processes you need.
Good times to switch are after the first certification (when you know what you need), at the start of a new ISMS year (when you are updating the risk assessment anyway), or when a specific pain point tips the scales (the ISM spends too much time on data maintenance, the auditor criticizes traceability, new team members cannot understand the existing system).
Plan four to eight weeks for the migration. During this time, you transfer existing data, configure the tool, and train users. In parallel, you continue running the old system until the new tool is productive. A hard cutover is risky and unnecessary.
Further Reading
- ISMS-Software auswählen: Anforderungen, Vergleich und Entscheidungshilfe
- Self-hosted vs. Cloud: Was Compliance-Anforderungen für dein Hosting bedeuten
- Was kostet ein ISMS? Budgetplanung und ROI-Betrachtung
- ISMS-Dokumentation im Überblick: Was du wirklich brauchst
- ISMS-Projekt planen: Roadmap, Meilensteine und Ressourcen
