What we're building for you
The CapGRC roadmap is driven by the real needs of our clients. Have a suggestion? Share it. The next features are the ones you request most.
Suggest a featureDelivered, 2024–2026
CapRISK : Risk management module
Centralized register, configurable risk matrix, treatment plans and indicators
CapCOM : Regulatory compliance module
Law 25, ISO 27001, PCI-DSS, GDPR, NIS2, DORA, multi-framework tracking and evidence
CapAUDIT : Internal audit module
Planning, work programs, audit assignments, exportable reports
CapPROSEC : Project security module
Project security engagement, phase activities, deliverables and action plans
CapTRISK : Third-party risk module
Vendor inventory, questionnaires, scoring and due diligence
CapPRP : Privacy officer obligations
Regulatory PIAs, confidentiality incident register with OPC/CAI notification, access requests and consents, Law 25, GDPR, PIPEDA
Notifications management
Alerts, reminders and multi-channel notifications (Teams, Slack, email) for GRC deadlines and events
Exceptions management
Control exceptions, approval workflow and traceable follow-up in the GRC program
SSO / SAML 2.0
Azure AD, Okta and Google Workspace integration
Azure DevOps integration
Synchronization with DevOps pipelines and project security assessment triggers
Microsoft Teams and Slack integrations
Alert, deadline and reminder notifications
REST API v1
Documented API, programmatic access to GRC data (on request)
MFA and granular RBAC
MFA available (mandatory for administrators) and role-based access control
Exclusive Canadian hosting
Redundant infrastructure, automatic backups, high availability
Bilingual FR/EN website
Articles, guides, glossary, ROI calculator, activation wizard and pricing
Q3–Q4 2026 (In development)
ICT incident management module
Operational register, classification, lifecycle, response plans and evidence, distinct from confidentiality incidents (CapPRP)
Enhanced executive dashboard
Advanced visualizations for management and the board, with PowerPoint and PDF export
Policy and document management
Publishing, versioning and read-acknowledgment tracking for security policies
Jira integration
Synchronization of action plans and audit findings with Jira tickets (beta)
SOC 2 Type II initiative
Strengthening Trust Services Criteria controls and audit preparation
Q4 2026 (Q2 2027 (Planned)
Artificial intelligence, GRC assistance
Scoring suggestions, prioritization and drafting assistance integrated with the risk register and frameworks
Vendor portal
Dedicated space for vendors to respond to questionnaires directly in CapGRC
Customizable reports
Report builder for GRC teams and management
Platform ISO 27001 program
ISO 27001 certification initiative for the CapGRC platform, alongside SOC 2
2028 and beyond (Vision)
GRC as a Service (GRCaaS)
Managed offering for organizations without internal GRC resources
Framework marketplace
Community library of frameworks and templates contributed by users
ESG module
Extension of the GRC program to environmental, social and governance criteria
A feature missing from this roadmap?
Submit your suggestion. Our product team reads all requests and incorporates them into quarterly planning.
