GRC software for ISO 27001, BSI IT-Grundschutz, NIS2 & DORA
The agentic GRC tool for ISMS,
risk management and compliance
KaitoSec connects policies, risks, controls and evidence in one data model for Word rotation pauses on focus or touch.information security, business continuity, data protection, supplier and AI management.Compliance teams work up to 6x faster than with legacy GRC or spreadsheets.
5,000+entities in the world model
The actual bottleneck
For compliance teams in the mid-market and critical infrastructure
Information security officer
„Our information domain lives in three Excel files. Which requirement is actually still open?“
Head of IT
„NIS2 expects the early warning within 24 hours. Where do I get the facts when it counts?“
Reporting deadlines run in hours, not weeks.
Managing director
„I have to approve the measures and oversee the implementation, and I can be held liable for it. How do I see where we actually stand?“
Management approves, oversees and is liable.
Import & check
One data model for ISMS, BCMS, DSMS, supplier and AI management
KaitoSec reads spreadsheets, GRC exports, identities, cloud, CMDB, monitoring and documents into one world model. KaitoSec checks them against the method and turns every gap into a task with an owner and a date.
- Identity & HR
- CMDB & IT documentation

- Cloud platforms
- Monitoring & network
- Documents & collaboration
- API, import & export

KaitoSec
- ISMSInformation domain · protection needs
- GRCRegisters · risks · controls
- BCMSBIA · recovery plans
- DSMSPrivacy · RoPA · DPIA
- TPRMSuppliers · third-party risk
- AUDITAudits · evidence
- Identity & HR
- CMDB & IT documentation

- Cloud platforms
- Monitoring & network
- Documents & collaboration
- API, import & export

KaitoSec
- ISMSInformation domain · protection needs
- GRCRegisters · risks · controls
- BCMSBIA · recovery plans
- DSMSPrivacy · RoPA · DPIA
- TPRMSuppliers · third-party risk
- AUDITAudits · evidence
A Grundschutz register is imported from Excel. KaitoSec checks the information domain along the Grundschutz phases. Findings appear: protection needs not assessed, Bausteine not modelled, evidence missing. The register is adopted, 38 Bausteine are assigned, and findings become tasks with owners and dates.
Measured, not estimated
Up to 6x faster than legacy GRC
38–4914–23
Person-days, summed over six steps
And the BCMS runs on a head start: the same data carries emergency management.
Every person-day saved is budget. Run your own numbers
Create and group assets
5–8 PD · conventional2–3 PD · KaitoSecDetermine protection needs
4–5 PD · conventional1–2 PD · KaitoSecCollect requirements
4–5 PD · conventional1–2 PD · KaitoSecModelling (Grundschutz)
5–6 PD · conventional1–2 PD · KaitoSecIT-Grundschutz check
10–15 PD · conventional3–7 PD · KaitoSecRisk analysis
10 PD · conventional6–7 PD · KaitoSec
Measured in our tests. Varies by step and data situation.
Capabilities
From policy to audit-ready evidence
01 One register
Applications, processes, vendors, AI. Captured once.
Every row is classified as it is recorded and has a named owner. The same register feeds the risk register, the RoPA and the BIA.
Asset managementInventory · 1,284 records
Classified on discovery| Asset | Owner | Classification | Systems served |
|---|---|---|---|
| Payments APIInternal service | Platform Engineering | Restricted | ISMS · BCMS · DSMS |
| Customer portalPublic web application | Product | Public | ISMS · DSMS |
| Primary databasePostgreSQL cluster | Platform Engineering | Restricted | ISMS · BCMS · DSMS |
| StripeVendor · payment processor | Finance | DPA signed | DSMS · ISMS |
| Support copilotAI component · embeddings | Customer Operations | AI · high risk | AIMS · DSMS |
02 Overlap
One control, several obligations.
The mapping runs through OSCAL and is curated by KaitoSec. What stands for ISO 27001 counts for NIS2 and DORA too.
Full mappingCoverage from existing controls
of ISO 27001 requirements met by controls you already run for the other systems.
Frameworks: ISO 27001, BSI IT-Grundschutz, NIS2 and DORA
BCMS
Business continuity
ISO 22301 · DORA
ISMS
Information security
ISO 27001 · BSI · NIS2
DSMS
Data protection
GDPR / DSGVO
AIMS
AI governance
ISO 42001 · EU AI Act
Early access feedback
“We replaced three spreadsheets and a shared drive with one system. ISO 27001 and NIS2 finally live in the same place, and the readiness view shows exactly what is still open.”
- Systems replaced
- Time to first register
- Frameworks live
More from the early access
“Genuinely intuitive. We started without a training session and the team found its way around immediately.”
“Every requirement is explained in subject terms, right at the field. For the first time the whole team understands why a control is needed.”
“Simple mode takes the fear out of it for the departments. For the audit I switch to expert mode, same data.”
Free check
Does NIS2 apply to you? Check it in five minutes.
The applicability check walks through sector, size and special cases and gives you the classification with next steps. Free.
Frequently asked questions about GRC software
What is GRC software?
GRC software brings governance, risk management and compliance into one system: requirements from standards and laws, the controls derived from them, risks and evidence. KaitoSec goes one step further by running ISMS software, BCMS, DSMS and AIMS on one shared data model.
Which standards and laws does KaitoSec support?
KaitoSec supports ISO 27001, BSI IT-Grundschutz, NIS2, DORA, TISAX, ISO 22301, GDPR, ISO 42001 and the EU AI Act. Through compliance mapping, one implemented control counts toward every relevant requirement.
How is KaitoSec different from verinice, HiScout or Excel?
Traditional GRC tools manage documents; KaitoSec connects processes, owners and evidence while AI agents prepare routine work. The GRC tool comparison shows the differences by category, and migration from verinice, HiScout and eramba is part of onboarding.
How quickly can an ISMS be operational with KaitoSec?
An ISMS can start with its first register within a week, while KaitoSec onboarding is designed for one day. In our measurements, the effort for an IT-Grundschutz build fell from 38–49 to 14–23 person-days; use the ROI calculator for your case.
Where is KaitoSec data hosted?
KaitoSec data hosting is located in Germany. The product is developed in Germany, is GDPR-compliant and carries the TeleTrusT ‘IT Security made in Germany’ trust mark. See integrations and data flows for technical details.
Get started
Want to save time too?
No more Excel registers and tool graveyards. Bring us the process everyone else gets stuck on. We’ll show you live what’s possible.
- Onboarding
- Migration
- Demo length


