Product Roadmap

Product direction for Nisium — what is available today and what we are building next.

Last updated: June 2, 2026 · Version 1.0

Priorities change as we learn from customers and regulators. Timelines are indicative — see Terms for contractual commitments.

This roadmap reflects our current direction for Nisium. Priorities and timelines may change — nothing here is a contractual commitment. See our Terms of Service for binding terms.

Available today

Capabilities in active development or production rollout:

AreaDescription
-------------------
Gap analysisNIS2 control catalog, assessments, and remediation tracking
Incident centerWizard workflows, reporting timelines, and exports
Evidence lockerUploads, SHA-256 hashing, metadata, retention, legal hold
Vendor riskQuestionnaires, magic-link access, scoring, passport flows
Executive dashboardCompliance posture widgets and role-based views
IdentityCognito authentication with MFA; SAML for essential entities
EU hostingTarget production region AWS eu-central-1

In progress

Near-term focus areas:

AreaDescription
-------------------
Production hardeningContainerized deploy, CI/CD, and observability on AWS
NotificationsIn-app and email reminders for deadlines and approvals
Audit packsExport bundles for audits and regulatory submissions
CERT-BG workflowsStructured reporting artifacts and inbound email parsing

On the horizon

Longer-term themes under consideration:

AreaDescription
-------------------
AI assistanceRAG-driven control guidance and incident narrative support (with PII masking)
Deeper integrationsSIEM and ticketing connectors (scope TBD)
Bulgarian UI polishExpanded in-product Bulgarian coverage
Enterprise featuresAdvanced retention policies, subprocessor portal, assurance programs

How we prioritize

  1. Security and tenant isolation — never compromised for convenience.
  2. Regulatory workflows — incident deadlines, evidence integrity, and auditability.
  3. Operator efficiency — dashboards, vendor portal, and clear RBAC.
  4. EU data residency — production data remains in the EU.

Share feedback

We build Nisium for essential and important entities in Bulgaria and the EU.

This document is effective as of June 2, 2026. Material changes will be posted on this page.