Vigilant Software
Vigilant Software is a UK-based compliance software vendor that sells documentation toolkits, gap analysis tools, e-learning, and professional services for ISO 27001, GDPR, PCI DSS, DORA, and AI governance frameworks to SMBs, mid-market, and enterprise organisations across the UK, Europe, Ireland, and the US.
- Company typePrivate
- Founded2005
- HeadquartersCambridge, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Vigilant Software does
Vigilant Software, founded in 2005 and headquartered in Cambridge, United Kingdom, is a private compliance software vendor operating within the broader GRC Solutions ecosystem. The company sells pre-built documentation toolkits, gap analysis tools, e-learning courses, and related professional services to organisations pursuing certification or regulatory compliance across frameworks including ISO 27001, GDPR, PCI DSS, Cyber Essentials, ISO 22301, ISO 27701, ISO 27017/27018, ISO 42001, and the EU Digital Operational Resilience Act (DORA). Its primary customers are UK, European, and US-based organisations of varying sizes — from individual practitioners and SMBs buying templates on the e-commerce storefront to mid-market and enterprise clients engaging the company for consultancy, DPO-as-a-Service, and audit support. No parent company, ownership structure, or investor base is disclosed in the available data.
The product portfolio is template-driven rather than platform-native: documentation toolkits (ISO 27001, GDPR, PCI DSS, Cyber Essentials) provide pre-built policies, procedures, and audit artefacts; gap analysis tools (ISO 27001, GDPR, Cyber Essentials, ISO 22301, ISO 27701, DORA) enable self-service readiness assessment; the CyberComply portal aggregates compliance tracking; and a dedicated eLearning platform delivers staff awareness courses across multiple frameworks. The underlying technology is described in functional rather than architectural terms — there is no disclosed proprietary stack, no public APIs, no SDKs, and no AI/ML capability. The company does sell AI governance templates (AI Policy Template, AI Tools Use Policy Template, ISO 42001 standard), but these are documentation artefacts about AI governance, not AI capabilities deployed internally.
The business model combines subscription revenue from annual template and training licences (e.g., AI Policy Template £30 Year 1 / £5 thereafter, Cloud Security FastTrack £195 / £50), one-time / perpetual licence revenue from higher-tier toolkits (e.g., Cyber Security Governance & Risk Management Toolkit £895), professional services income (DPO-as-a-Service, UK/EU Representative Services, consultancy for NIS2, DORA, SOC 2, ISO 27001), and sale of official standards and books. Go-to-market is hybrid: self-service e-commerce on the GRC Solutions storefront targets SMBs and individual buyers, inside phone sales across UK (+44), Ireland (+353), and the US (+1) cover mid-market enquiries, a 'Get a Quote' channel addresses enterprise engagements, and a formal Channel Partner Programme plus Affiliate Programme extend reach globally. Operations span the UK (regional HQ), Ireland (Dublin), and the United States; the company employs between 11 and 50 people and discloses no revenue, funding history, or executive team in the source material.
Vigilant Software firmographics
Firmographics- Name
- Vigilant Software
- Website
- https://vigilantsoftware.co.uk
- Company type
- Private
- Founded year
- 2005
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Vigilant Software is a UK-based compliance software vendor that sells documentation toolkits, gap analysis tools, e-learning, and professional services for ISO 27001, GDPR, PCI DSS, DORA, and AI governance frameworks to SMBs, mid-market, and enterprise organisations across the UK, Europe, Ireland, and the US.
- Ownership category
- akta.pro rank
Vigilant Software industry classification
Industry- Product category
- Governance, Risk and Compliance (GRC) Software
- NAICS
- Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO)
- akta.pro secondary industries
- Security Awareness, Training & Compliance Attestation (HDADAIAJ), Governance, Risk & Compliance (GRC) & Security Management (EDAOAIAG), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
Keywords
Where Vigilant Software is headquartered
LocationHeadquarters
- HQ city
- Cambridge
- HQ country
- United Kingdom
- HQ region
- Europe
Offices3 records
Markets served
Vigilant Software business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations
Revenue model
- Software and Documentation Toolkits: Sale of annual subscription and perpetual license documentation toolkits covering standards such as ISO 27001, GDPR, PCI DSS, Cyber Essentials, and ISO 22301. These toolkits provide pre-built policy and procedure templates for compliance purposes.
- E-Learning and Training Courses: Sale of e-learning staff awareness courses and instructor-led training programmes covering GDPR, Cyber Security, ISO 27001, DORA, PCI DSS, ISO 22301, ISO 9001, AI, and Business Continuity. Offered on an annual subscription basis.
- Gap Analysis Tools: Sale of self-service gap analysis tools for standards such as ISO 27001, GDPR, Cyber Essentials, ISO 22301, ISO 27701, and DORA, enabling organisations to assess their compliance readiness.
- Professional Services: Provision of professional services including DPO-as-a-Service (UK only), UK and EU Representative Services under GDPR, and broader consultancy services for NIS2, DORA, SOC 2, and ISO 27001 compliance.
- Standards and Books: Sale of official standards documents (ISO 27001, ISO 42001, ISO 22301, ISO 20000, ISO 27701) and associated GRC/cyber security books and publications.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | AI Policy Template — Annual subscription: £30 Year 1, £5 thereafter |
| Subscription | Annual | AI Tools Use Policy Template — Annual subscription: £30 Year 1, £5 thereafter |
| Subscription | Annual | CCTV Data Protection Policy — Annual subscription: £35 Year 1, £1 thereafter |
| Subscription | Annual | Cloud Security FastTrack Toolkit (ISO 27017 & ISO 27018) — £195 Year 1, £50 thereafter |
| Unit Pricing | Pay-as-you-go | Cyber Essentials Gap Analysis Tool — £19.95 one-time |
| Unit Pricing | Pay-as-you-go | Cyber Security Governance & Risk Management Toolkit — £895.00 |
| Unit Pricing | Pay-as-you-go | CyberComply — £299.50 |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels6 records
Vigilant Software product offering
Product offeringCore offering
Vigilant Software sells pre-built compliance documentation toolkits, self-service gap analysis assessment tools, staff awareness e-learning courses, official standards publications, and a centralised cloud compliance management platform (CyberComply), targeting organisations seeking to achieve and maintain compliance with frameworks such as ISO 27001, GDPR, PCI DSS, Cyber Essentials, DORA, NIS2, SOC 2, ISO 42001 and ISO 22301. The company also bundles professional services including DPO-as-a-Service, EU/UK Representative Services, and broader compliance consultancy.
Product overview
Vigilant Software offers a portfolio of GRC (Governance, Risk, and Compliance) software products and documentation toolkits designed to help organizations achieve and maintain regulatory compliance. The product range includes documentation templates (AI Policy Template, AI Tools Use Policy Template, CCTV Data Protection Policy), comprehensive documentation toolkits (Cloud Security Toolkit for ISO 27017/27018, Cyber Security Governance & Risk Management Toolkit, Cyber Security Toolkit), compliance management platforms (CyberComply, CyberComply Portal), gap analysis tools (Cyber Essentials Gap Analysis Tool, ISO 27001 Gap Analysis Tool, GDPR Gap Analysis Tool, ISO 27701 Gap Analysis Tool, DORA Gap Analysis Tool), and eLearning platforms (GRC eLearning Platform). The core offerings center on pre-built documentation templates and toolkits that organizations use to implement compliance frameworks, supplemented by assessment tools and professional services including DPO-as-a-Service.
Differentiator
Problem solved
Functional benefit
Products and services
- Artificial Intelligence (AI) Policy Template Annual subscription documentation template for establishing organisational AI governance frameworks and acceptable use guidelines. Targets organisations implementing AI governance policies.
- Artificial Intelligence (AI) Tools Use Policy Template Annual subscription template for governing the use of AI tools within the organisation. Provides a ready-made policy artefact for organisations deploying or sanctioning AI tools.
- CCTV Data Protection Policy Annual subscription documentation template addressing data protection compliance requirements for CCTV surveillance systems, used by organisations operating video surveillance to meet GDPR and UK data protection obligations.
- Cloud Security FastTrack™ Toolkit – ISO 27017 & ISO 27018 Accelerated implementation toolkit providing pre-built documentation for organisations pursuing ISO 27017 (cloud security) and ISO 27018 (PII protection in public clouds) compliance.
- Cloud Security Toolkit – ISO 27017 & ISO 27018 Comprehensive documentation toolkit for ISO 27017 and ISO 27018 certification, covering cloud-specific security controls and PII handling requirements for cloud service providers and customers.
- ISO 27001 Documentation Toolkit Complete documentation package for ISO 27001 information security management system (ISMS) implementation and certification, providing pre-built policies, procedures and supporting documentation.
- GDPR Documentation Toolkit Documentation toolkit containing templates for GDPR compliance documentation and data protection policies, used by organisations pursuing GDPR compliance and accountability obligations.
- PCI DSS Documentation Toolkit Documentation toolkit providing templates for payment card industry data security standard (PCI DSS) compliance, targeting merchants, service providers and other entities handling cardholder data.
- Cyber Security Governance & Risk Management Toolkit Comprehensive governance, risk and compliance toolkit providing documentation for establishing cybersecurity management frameworks, governance structures and risk treatment processes.
- Cyber Security Toolkit Documentation toolkit covering cybersecurity policy and procedural requirements for organisational security programmes.
- CyberComply Portal Cloud-based centralised compliance management portal providing tracking and management of regulatory compliance requirements across multiple frameworks (Centralised compliance platform consolidating the CyberComply portal experience).
- Cyber Essentials Gap Analysis Tool Self-assessment tool for evaluating organisational readiness against Cyber Essentials certification requirements, sold as a one-time purchase for SMB and mid-market buyers.
- ISO 27001 Gap Analysis Tool Self-assessment tool for evaluating organisational readiness against ISO 27001:2022 information security management system requirements.
- GDPR Gap Analysis Tool Self-assessment tool for evaluating GDPR compliance maturity and identifying remediation requirements.
- ISO 27701 Gap Analysis Tool Self-assessment tool for evaluating privacy information management system compliance against ISO 27701 requirements.
- DORA Gap Analysis Tool Self-assessment tool for evaluating Digital Operational Resilience Act (DORA) compliance readiness for financial entities and ICT third-party providers.
- DPO as a Service Dedicated data protection officer service providing statutory DPO responsibilities for UK organisations that require an appointed DPO.
- GRC eLearning Platform Online learning management system delivering staff awareness and instructor-led compliance and governance training courses (ISO 27001, Cyber Security, GDPR, DORA, PCI DSS, AI, Business Continuity, ISO 9001 e-learning).
- Cyber Security Platform Cybersecurity management and certification tracking platform supporting organisational Cyber Essentials and broader cyber security programme management.
- Standards Publications (ISO 27001, ISO 42001, ISO 22301, ISO 20000, ISO 27701) Sale of official standards documents and associated GRC/cyber security books and publications through the e-commerce shop, enabling organisations to purchase the underlying standards their toolkits align with.
Companies that use Vigilant Software
Customer profileSegments1 record
Ideal customer profiles2 records
Vigilant Software technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Vigilant Software partnerships and signals
Strategic signalRecent moves6 records
Expansion highlights6 records
Vigilant Software competitors and assessment
Company assessmentDirect peers
- Drata: Automated GRC and compliance monitoring platform covering SOC 2, ISO 27001, HIPAA, and more; overlaps with Vigilant's gap analysis and documentation toolkit offerings but is positioned more toward continuous compliance automation.
- Vanta: Automated compliance platform for SOC 2, ISO 27001, HIPAA, and other frameworks; competes with Vigilant's gap analysis and documentation toolkits by offering continuous monitoring and evidence collection as an alternative to template-based approaches.
- IT Governance Ltd: UK-based GRC consultancy and tooling vendor that sells documentation toolkits, training, and consultancy across ISO 27001, GDPR, PCI DSS, and Cyber Essentials — overlapping almost entirely with Vigilant Software's product range, and widely believed to share parent/affiliate ownership within the GRC Solutions ecosystem.
- ISMS.online: UK-headquartered SaaS platform for ISO 27001 information security management system implementation, with pre-built templates, controls, and collaboration tools directly competitive with Vigilant's ISO 27001 documentation toolkit and CyberComply portal.
Emerging players
- Secureframe: Cloud-based compliance automation platform for SOC 2, ISO 27001, HIPAA, and PCI DSS; competes for the same SMB/mid-market compliance buyer Vigilant targets, but with a fully automated SaaS model.
- LogicGate Risk Cloud: GRC platform for risk and compliance workflows including ISO 27001 and SOC 2; overlaps with Vigilant's CyberComply portal for organizations seeking workflow-based GRC automation.
- Hyperproof: GRC operations platform covering multiple compliance frameworks with continuous control monitoring; overlaps with Vigilant's CyberComply portal but targets larger enterprise GRC programs.
Broad incumbents
- OneTrust: Broad trust intelligence and GRC platform covering privacy, security, ethics, and compliance; competes with Vigilant's GDPR, ISO 27001, and DPO-as-a-Service offerings as a much larger incumbent with enterprise focus.
- KnowBe4: Global leader in security awareness and compliance training, directly competing with Vigilant's e-learning staff awareness courses (GDPR, cyber security, ISO 27001, PCI DSS) at significantly greater scale.
- MetricStream: Enterprise GRC platform serving large regulated organizations across cyber, operational, and regulatory risk; competes with Vigilant's enterprise consultancy and CyberComply portal as a higher-end GRC incumbent.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Vigilant Software social profiles
Digital presenceVigilant Software financial estimates
Financial estimateRevenue estimate
Valuation estimate
Vigilant Software leadership team
Management profileNumber of profiles
Vigilant Software funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Vigilant Software M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Vigilant Software
What does Vigilant Software do?
Vigilant Software sells pre-built compliance documentation toolkits, self-service gap analysis assessment tools, staff awareness e-learning courses, official standards publications, and a centralised cloud compliance management platform (CyberComply), targeting organisations seeking to achieve and maintain compliance with frameworks such as ISO 27001, GDPR, PCI DSS, Cyber Essentials, DORA, NIS2, SOC 2, ISO 42001 and ISO 22301. The company also bundles professional services including DPO-as-a-Service, EU/UK Representative Services, and broader compliance consultancy.
When was Vigilant Software founded?
Vigilant Software was founded in 2005. It employs 11 to 50 people.
Where is Vigilant Software based?
Vigilant Software is headquartered in Cambridge, United Kingdom, in the Europe region.
How does Vigilant Software make money?
Five revenue lines are on record. Software and Documentation Toolkits are the primary driver. The others are E-Learning and Training Courses, gap Analysis Tools, professional Services and standards and Books.
Who are Vigilant Software's main competitors?
Direct peers on record are Drata, Vanta, IT Governance Ltd and ISMS.online. Emerging players are Secureframe, LogicGate Risk Cloud and Hyperproof. Broad incumbents are OneTrust, KnowBe4 and MetricStream.
Does Vigilant Software have an API?
No public API is recorded for Vigilant Software.
What industry is Vigilant Software in?
Vigilant Software's product category is Governance, Risk and Compliance (GRC) Software. Its primary akta.pro industry code is BPAHAFAO, Compliance Technology, GRC Platforms & Controls Automation Advisory, with a secondary code of HDADAIAJ, Security Awareness, Training & Compliance Attestation. Its NAICS code is 513210 and its SIC code is 7372.