Skip to content

GRC software for ISO 27001, BSI IT-Grundschutz, NIS2 & DORA

The agentic GRC tool for ISMS,
risk management and compliance

KaitoSec connects policies, risks, controls and evidence in one data model for Word rotation pauses on focus or touch.information security, business continuity, data protection, supplier and AI management.Compliance teams work up to 6x faster than with legacy GRC or spreadsheets.

5,000+entities in the world model

The actual bottleneck

For compliance teams in the mid-market and critical infrastructure

Information security officer

„Our information domain lives in three Excel files. Which requirement is actually still open?“

Head of IT

„NIS2 expects the early warning within 24 hours. Where do I get the facts when it counts?“

Reporting deadlines run in hours, not weeks.
Directive (EU) 2022/2555 (NIS2), Art. 23

Managing director

„I have to approve the measures and oversee the implementation, and I can be held liable for it. How do I see where we actually stand?“

Management approves, oversees and is liable.
Directive (EU) 2022/2555 (NIS2), Art. 20

The tool-category comparison

Import & check

One data model for ISMS, BCMS, DSMS, supplier and AI management

KaitoSec reads spreadsheets, GRC exports, identities, cloud, CMDB, monitoring and documents into one world model. KaitoSec checks them against the method and turns every gap into a task with an owner and a date.

KaitoSec brings identity, CMDB, cloud, monitoring, document and interface data together, linking it to information domains, registers, BIA, RoPA, third-party risk, audits and evidence.
  • Identity & HRMicrosoft Entra IDMicrosoft IntuneMicrosoft DefenderPersonio
  • CMDB & IT documentationi-doitMatrix42Docusnap 365
  • Cloud platformsAWSMicrosoft AzureGoogle Cloud
  • Monitoring & networkPRTGmacmon NACWeb Discovery
  • Documents & collaborationSharePoint OnlineConfluenceJiraMicrosoft Teams
  • API, import & exportREST APIExcel & CSVOSCAL

KaitoSec

  • ISMSInformation domain · protection needs
  • GRCRegisters · risks · controls
  • BCMSBIA · recovery plans
  • DSMSPrivacy · RoPA · DPIA
  • TPRMSuppliers · third-party risk
  • AUDITAudits · evidence
  • Identity & HRMicrosoft Entra IDMicrosoft IntuneMicrosoft DefenderPersonio
  • CMDB & IT documentationi-doitMatrix42Docusnap 365
  • Cloud platformsAWSMicrosoft AzureGoogle Cloud
  • Monitoring & networkPRTGmacmon NACWeb Discovery
  • Documents & collaborationSharePoint OnlineConfluenceJiraMicrosoft Teams
  • API, import & exportREST APIExcel & CSVOSCAL

KaitoSec

  • ISMSInformation domain · protection needs
  • GRCRegisters · risks · controls
  • BCMSBIA · recovery plans
  • DSMSPrivacy · RoPA · DPIA
  • TPRMSuppliers · third-party risk
  • AUDITAudits · evidence
From current state to working state

A Grundschutz register is imported from Excel. KaitoSec checks the information domain along the Grundschutz phases. Findings appear: protection needs not assessed, Bausteine not modelled, evidence missing. The register is adopted, 38 Bausteine are assigned, and findings become tasks with owners and dates.

Measured, not estimated

Up to 6x faster than legacy GRC

38–4914–23

Person-days, summed over six steps

And the BCMS runs on a head start: the same data carries emergency management.

Every person-day saved is budget. Run your own numbers

  1. Create and group assets

    5–8 PD · conventional
    2–3 PD · KaitoSec
  2. Determine protection needs

    4–5 PD · conventional
    1–2 PD · KaitoSec
  3. Collect requirements

    4–5 PD · conventional
    1–2 PD · KaitoSec
  4. Modelling (Grundschutz)

    5–6 PD · conventional
    1–2 PD · KaitoSec
  5. IT-Grundschutz check

    10–15 PD · conventional
    3–7 PD · KaitoSec
  6. Risk analysis

    10 PD · conventional
    6–7 PD · KaitoSec

Measured in our tests. Varies by step and data situation.

Capabilities

From policy to audit-ready evidence

01 One register

Applications, processes, vendors, AI. Captured once.

Every row is classified as it is recorded and has a named owner. The same register feeds the risk register, the RoPA and the BIA.

Asset management

Inventory · 1,284 records

Classified on discovery
assets.caption
AssetOwnerClassificationSystems served
Payments APIInternal servicePlatform EngineeringRestrictedISMS · BCMS · DSMS
Customer portalPublic web applicationProductPublicISMS · DSMS
Primary databasePostgreSQL clusterPlatform EngineeringRestrictedISMS · BCMS · DSMS
StripeVendor · payment processorFinanceDPA signedDSMS · ISMS
Support copilotAI component · embeddingsCustomer OperationsAI · high riskAIMS · DSMS

02 Overlap

One control, several obligations.

The mapping runs through OSCAL and is curated by KaitoSec. What stands for ISO 27001 counts for NIS2 and DORA too.

Full mapping
78%

Coverage from existing controls

of ISO 27001 requirements met by controls you already run for the other systems.

ISO 27001 · BSI Grundschutz · NIS2 · DORA · ISO 42001

Frameworks: ISO 27001, BSI IT-Grundschutz, NIS2 and DORA

  • BCMS

    Business continuity

    ISO 22301 · DORA

  • ISMS

    Information security

    ISO 27001 · BSI · NIS2

  • DSMS

    Data protection

    GDPR / DSGVO

  • AIMS

    AI governance

    ISO 42001 · EU AI Act

Early access feedback

“We replaced three spreadsheets and a shared drive with one system. ISO 27001 and NIS2 finally live in the same place, and the readiness view shows exactly what is still open.”
Information security lead · Early access
Systems replaced
3 spreadsheets
Time to first register
Under a week
Frameworks live
ISO 27001 · NIS2

More from the early access

“Genuinely intuitive. We started without a training session and the team found its way around immediately.”
Head of IT · Early access
“Every requirement is explained in subject terms, right at the field. For the first time the whole team understands why a control is needed.”
Information security officer · Early access
“Simple mode takes the fear out of it for the departments. For the audit I switch to expert mode, same data.”
Managing director · Early access

Free check

Does NIS2 apply to you? Check it in five minutes.

The applicability check walks through sector, size and special cases and gives you the classification with next steps. Free.

Frequently asked questions about GRC software

What is GRC software?

GRC software brings governance, risk management and compliance into one system: requirements from standards and laws, the controls derived from them, risks and evidence. KaitoSec goes one step further by running ISMS software, BCMS, DSMS and AIMS on one shared data model.

Which standards and laws does KaitoSec support?

KaitoSec supports ISO 27001, BSI IT-Grundschutz, NIS2, DORA, TISAX, ISO 22301, GDPR, ISO 42001 and the EU AI Act. Through compliance mapping, one implemented control counts toward every relevant requirement.

How is KaitoSec different from verinice, HiScout or Excel?

Traditional GRC tools manage documents; KaitoSec connects processes, owners and evidence while AI agents prepare routine work. The GRC tool comparison shows the differences by category, and migration from verinice, HiScout and eramba is part of onboarding.

How quickly can an ISMS be operational with KaitoSec?

An ISMS can start with its first register within a week, while KaitoSec onboarding is designed for one day. In our measurements, the effort for an IT-Grundschutz build fell from 38–49 to 14–23 person-days; use the ROI calculator for your case.

Where is KaitoSec data hosted?

KaitoSec data hosting is located in Germany. The product is developed in Germany, is GDPR-compliant and carries the TeleTrusT ‘IT Security made in Germany’ trust mark. See integrations and data flows for technical details.

Get started

Want to save time too?

No more Excel registers and tool graveyards. Bring us the process everyone else gets stuck on. We’ll show you live what’s possible.

Onboarding
1 day
Migration
Your source
Demo length
30 minutes