Product Roadmap
See what's built and what's next.
The development roadmap is organized into the following phases, focusing on core functionality, integrations, and intelligent automation.
Q2–Q3 2025
Phase 1
virtual-CISO (vCISO) App Foundation
Core launch scope for the virtual-CISO application and foundational app modules.
Key Deliverables
vCISO Application
Virtual-CISO application with core modules for governance, assets, tools and security posture
Documents Manager
Document repository with MSSP hub template adoption, semantic indexing of content, and documents linkable as control evidence
Onboarding & Documentation
User onboarding journey and complete platform documentation
Technical Focus
- Core module architecture of the vCISO application
- Document management service with storage and semantic search
Q4 2025
Phase 2
MSSP Integration & Incident Management application
Focus on MSSP enablement and Incident Response automation.
Key Deliverables
MSSP Multi-tenant Access
Dedicated console for managed service providers
Incident Management
Enhance the platform with an Incident Management solution, for Incident Response workflows and automation
Technical Focus
- Multi-tenant architecture implementation
- Incident Response workflows and automation
- Advanced workflow automation
Q1–Q2 2026
Phase 3
Tools integrations, AI services and advanced reporting
Focus on tech tools integrations, AI services, reporting, and enterprise controls.
Key Deliverables
GraphRAG Knowledge System
A GraphRAG for contextual and automated security assistance
AI Assistant
An intelligent AI agent for security recommendations and automations (e.g. security assessment auto-completion, or third party surveys auto-completion)
External Tool Integration
Ten first-party connectors live across security tools and CMDBs
Enhanced Reporting
Posture, gap and remediation-plan analytics, with per-tenant exports
Enterprise Features
Advanced role management and audit capabilities
Technical Focus
- API development for third‑party integrations
- Enterprise‑grade security and compliance
Q3–Q4 2026
Phase 4
Regulatory coverage and operational capabilities
Focus on European regulatory coverage, identity governance and new operational capabilities.
Key Deliverables
Identity and access
Identity and access governance, integrated with the systems already in use across the organisation
Risk management
Asset and service criticality, risk assessment and treatment in a single path
Document lifecycle
Approval, versions and visibility, to show who approved what and when
Compliance calendar
Deadlines, periodic reviews and reminders in a single view
More evidence from the tools in use
Broader integrations to collect configuration, continuity and recovery evidence automatically
CyberOps application
A new application for security operations, alongside vCISO and Incident Handler
Incident management
Incident qualification and exercises, within the Incident Handler application
Cyber Resilience Act
The reporting obligations the regulation introduces from September 2026
Technical Focus
- Domain models reusable across multiple regulatory frameworks
- A wider connector family
Q4 2026 – Q1 2027
Phase 5
Future Considerations
Ideas we intend to explore and validate with users.
Looking Ahead
- Agentic AI framework integration
- Multi-agent architecture
- External communication channels integrations (e.g. MS Teams, Slack, Matrix, etc.)
- MCP server
- Enterprise SSO integration against the customer's identity systems
- Industry‑specific compliance modules
- CRA — secure development and SBOM, ahead of full application on 11 December 2027
- Further regimes: GDPR, DORA, AI Act, Data Act and others
Q2 2027 onwards
Phase 6
Future Considerations
Ideas we intend to explore and validate with users.
Looking Ahead
- Threat-intelligence-led GRC and governance
- GenAI-driven incident management
- Continuous attack surface analysis
- More external tools integrations
- Agentic AI skills and workflows
Your feedback is valuable
Share your priorities and help shape the future of resysto.
Timeline is subject to change based on user feedback and market demands. For the latest updates, follow our blog or contact us at support@resysto.io.