Skip to content

isms

What Does ISMS Software Cost? Pricing Models Compared

The license fee is only one of six cost blocks. This article sorts the DACH market into three price tiers and shows what comes on top for rollout, internal effort, training, and operation.

By · Published 10 September 2026 · 20 min read

ISMS software in the DACH market ranges from roughly €50 to well over €1,000 per month. The license fee is only one of six cost blocks: rollout and migration, internal effort, training, optional consulting, and ongoing operation come on top. Communicating prices transparently matters to us, which is why ours are public on our website: with KaitoSec you start at €240 per month with annual billing.

What makes up the cost of ISMS software?

The cost of ISMS software consists of six blocks: license, rollout and data migration, internal staff effort, training, optional consulting, and ongoing operation including scaling with user count. The license fee is the only block vendors show on a pricing page. Often it is not the largest.

The first block is the license, the recurring amount per month or year, usually tiered by user count, company size, or feature scope. It is also the least transparent item in this market, because every vendor defines for itself which user roles and which intensity of use are tied to which license. That coupling varies so widely that two license fees of the same size can include entirely different rights.

The second block is the rollout including data migration. Risk registers, control lists, and evidence almost always sit in spreadsheets or a legacy system and must be transferred into the new data model. Some vendors bill this as a one-off setup package, others spread it across the license.

This block swings more than any other. It stays small when there is little existing material and grows large when an extensive legacy system has to be replaced. What drives it is rarely the technical transfer but the coordination: workshops, clarifying ownership, deciding what gets carried over at all. A low license fee can be consumed entirely by a demanding migration block. In purely financial terms, a fresh build is therefore often cheaper than migrating an accumulated estate.

The third block is the internal staff effort: the hours information security officers, IT, and the business units spend on maintenance, evidence handling, and coordination. This block appears in no quote and is the largest item in many projects.

Organizations building this capability for the first time, with no such role in place, need to budget for a specialist position: an information security officer is a job of its own with a salary of its own. That item is only indirectly tied to the tool, though, because it arises from the task rather than from the software. The role can also be bought in as an external service, for example under a vCISO model.

The fourth block is training for users, from onboarding the core team to recurring awareness work across the workforce.

The fifth block is optional consulting, for example for protection requirement assessments or drafting policies.

The sixth block is ongoing operation, with support, updates, and scaling as user numbers or sites grow. For cloud instances it usually stays low, because operation and updates sit with the vendor. For on-premise installations it can run considerably higher, because infrastructure, maintenance windows, and updates fall to your own team. How much of that is already covered by the license differs from vendor to vendor and belongs in the quote.

Not included are the costs of certification itself. Auditor, certification body, and support through the audit fall due independently of the software and are the subject of the cost of an ISO 27001 certification. This cost calculation covers the software and its operation only.

That separation decides whether a comparison holds up. A quote including the rollout measures something different from a pure license fee, unless it is clear what each contains. Two "prices" in the same market therefore often do not mean the same thing.

How many blocks arise depends on scope. KaitoSec brings ISMS, BCMS, DSMS, and AISMS together on a shared data model; anyone running several separate systems calculates rollout, training, and operation per system. Which management systems converge is shown on the platform system map.

What price tiers exist for ISMS software in the DACH market?

ISMS software in the DACH market spreads across three price tiers: functionally narrow tools from around €50 per month, mid-market platforms between roughly €200 and €600 per month, and enterprise suites with four-figure monthly amounts. The tier says a great deal about the audience a tool was built for and rather little about its feature scope.

A note first: free entry plans

Below the three tiers sit permanently free plans. KaitoSec Free covers one framework (ISO 27001), up to 50 controls, and one user. That is a way in, not a price tier of its own: it lets you see how a management system is structured before requesting a budget.

Tier 1: functionally narrow tools from around €50 per month

This tier starts at around €50 per month. For that you typically get a single license or seat, one standard family, little to no automation, and no real multi-user operation. In practice this is a tool for the first level of maturity: a few templates, a handful of checklists, a structured filing system. It is not a deep management system, and it does not claim to be one.

For one person documenting a single framework in a small organization, that is enough. Where the tier ends is purely a question of function: as soon as several people work on the same data at once, as soon as a second standard joins, as soon as evidence has to be reproducible for an audit.

Tier 2: mid-market platforms between €200 and €600 per month

Mid-market companies buy predominantly in this tier, roughly €200 to €600 per month. The markers are several frameworks, multi-user operation, asset and policy management, and unlimited controls.

At KaitoSec, the Standard plan starts at €240 per month with annual billing and at €290 per month with monthly billing: 3 frameworks, unlimited controls, asset and policy management, 10 users plus 50 guests. Professional starts at €575 per month with annual billing and includes all four systems (ISMS, BCMS, DSMS, AIMS), KaitoSec AI, threat analysis, vendor management, Trust Center, and SSO/SAML for 40 users; with monthly billing, Professional sits above this band at €690. All of these figures are in the published prices.

Tier 3: enterprise suites from four-figure monthly amounts

Above that, four-figure monthly amounts begin; vendors in this tier publish no reliable list prices. Audit costs frequently come separately here.

Buyers in this tier are corporate groups with many sites, their own GRC team, and custom integrations. For mid-market companies this is usually not the right answer, but the tier explains why price research on the web varies so widely. This tier too has quote-on-request offers, with unlimited users and an on-premise option.

What the price tier tells you about the software, and what it does not

The tiers sort the market by audience, not by quality. A second-tier tool can go deeper functionally than a third-tier one, and the reverse happens just as often.

The reason is how old the underlying architecture is. Some of the more expensive systems date from a time when a management system was conceived mainly as a document repository: many fields, many forms, few connections between records. Such systems serve their purpose but push a lot of work back onto their users, because every relationship between asset, risk, control, and evidence is established by hand. Newer platforms build those relationships into the data model, and frequently sit one price tier lower while doing so.

KaitoSec sits in the second tier on price and is built for mid-market companies. Functionally, the platform brings four management systems together on one shared data model, so a single control pays into several frameworks at once. That depth is independent of the price tier.

In those cases the price reflects market position, sales model, and target audience rather than feature scope. For your own selection that means the price tier narrows the field but does not decide it. Whether a tool fits you is answered by comparing value against price, and that starts with the question of how much recurring work the system actually takes off your hands.

The first two price tiers were compiled from the publicly visible pricing pages of vendors common in the DACH market, as of September 2026. Where a vendor publishes no price, no figure was included. For the third tier there is accordingly no compiled figure; the order of magnitude comes from quotes and market observation, not from published list prices. All amounts stated are net plus statutory VAT (terms). Our own prices are set out in full on the pricing page.

Why do so many vendors publish no price at all?

A considerable share of ISMS software vendors in the DACH market publish no price at all, only a contact form, as a review of the publicly visible pricing pages in September 2026 shows. To compare, you first have to obtain quotes and have the assumptions behind them disclosed. Without those assumptions, two quotes cannot be sensibly set against each other, even when both name a figure.

The reasons are usually understandable. Prices scale individually with user count and booked modules, rollout effort depends on the maturity of the organization, and many firms sell through quotes rather than self-service. A vendor serving very different customer sizes genuinely struggles to find a defensible figure for the home page.

For the buyer, a problem remains. Before the first conversation there is no budget range, a shortlist by price is not possible, and the quotes obtained differ not only in the total but above all in what they include. Holding a quote with a migration project and three frameworks against one with a pure license produces no statement.

What to ask for in the quote

Four commercial line items make two figures comparable:

  • Price per user and price for each additional user, shown separately
  • Rollout and migration as a one-off item, separate from the license
  • Minimum contract term and price adjustment clause in full wording
  • Whether support and training are included or billed separately

Once these details are on the table, the comparison becomes arithmetic instead of guesswork. If one is missing, the amount named is only a ballpark.

KaitoSec publishes the full price list including additional users, AI quotas, and consulting day rates.

What does rolling out ISMS software cost on top of the license?

The rollout is a one-off cost block alongside the license: taking over data from predecessor systems or Excel, building the information domain, mapping existing controls onto the new control set, and training everyone involved. How high it turns out depends above all on how structured the starting material is, not on the tool chosen.

The four line items

The data takeover brings assets, risks, controls, and documents from Excel lists, wikis, or a predecessor tool into the structure of the new software. Building the structure defines the information domain, assigns assets, and names owners. The mapping clarifies which already practiced measures contribute to which controls. The briefing makes sure the people involved then work with it.

The starting material decides the effort. A well-maintained Excel landscape with clear owners is quickly taken over, an accumulated file share without owners is not. A switch from a predecessor tool runs differently from a first-time build: in a switch, structures exist and must be translated, in a first-time build they only come into being. What matters when changing tools is therefore translating existing structures, a question separate from the selection decision that precedes it.

What KaitoSec offers for this

For the briefing, the price overview lists in-house training from €1,200 per day for up to 20 participants, individual modules from €600, and packages with a 15% to 20% discount. Admin training is included in Professional and Enterprise.

Consulting is optional. KaitoSec is built to be operated without it. Those who buy it anyway find a remote day rate from €1,150, a vCISO retainer from €576 per month, and fixed-price packages for a gap analysis, a NIS2 check, and certification support.

These rates are published list prices. What is actually billed in a specific project depends on seniority and scope and falls outside such bands in both directions.

What internal effort arises alongside license and rollout?

Internal staff effort is usually the largest cost block for ISMS software and the only one that no pricing page discloses. It arises from maintaining controls, handling evidence, assessing risks, and coordinating with the business units. BSI-Standard 200-2 therefore recommends recording investment costs and staff effort separately for every measure.

The effort is spread across recurring tasks: maintaining the information domain, collecting evidence and keeping it current, assessing risks, tracking measures, preparing the management review, and clarifying with the business units who delivers which contribution. This work comes around every year, whatever tool sits underneath.

BSI-Standard 200-2, chapter 9.2 on cost and effort estimation, says on this:

„Da das Budget zur Umsetzung von Sicherheitsmaßnahmen praktisch immer begrenzt ist, sollte für jede zu realisierende Maßnahme festgehalten werden, welche Investitionskosten und welcher Personalaufwand dafür benötigt werden. Hierbei sollte zwischen einmaligen und wiederkehrenden Investitionskosten bzw. Personalaufwand unterschieden werden.“ (translation: "Since the budget for implementing security measures is practically always limited, it should be recorded for every measure to be realized which investment costs and which staff effort are needed for it. A distinction should be made here between one-off and recurring investment costs and staff effort.")

The separation between one-off and recurring items is therefore not busywork but a methodological recommendation from the BSI. The same passage points to an interaction: saving on technical security measures often means permanently more staff input, and saving on staff accumulates growing security deficits.

The market figures show where the bottleneck sits. According to ENISA, NIS Investments 2025, information security accounts for 9% of IT budgets on the EU average, the median of this spending is €1.5 million, and 70% of organizations name compliance as the most important investment driver.

According to ENISA, NIS Investments 2024, 89% of organizations expected additional security staff for NIS2 implementation, and 59% of SMEs reported difficulties recruiting. What is scarce is not the license budget but the time of the people who run the ISMS. A tool that takes manual work off their hands saves at exactly this bottleneck.

Anyone weighing how much to carry internally and how much to buy in externally finds the calculation in the cost comparison between NIS2 consulting and doing it yourself.

How do user count, modules, and AI usage change the running costs?

The running costs of ISMS software rise along three axes: the number of users, the number of frameworks covered, and the use of automated functions. At KaitoSec, every additional user costs €29 per month. The jump from three frameworks to all four management systems leads from the Standard plan to Professional.

The first axis is the user count. Standard includes 10 users and 50 guests, Professional 40 users, every further user €29 per month (see the price overview).

In a comparison, the definition is decisive. Reading business units, auditors, and external service providers count as users in one model and as guests in another. The quote has to answer this question before you lay monthly prices side by side.

The second axis is scope. Free covers one framework (ISO 27001, up to 50 controls, one user), Standard three frameworks, Professional all four management systems (ISMS, BCMS, DSMS, AIMS) including vendor management, Trust Center, and SSO/SAML. Every additional axis shifts the plan, not the unit price: a fourth management system means a different plan, not an added module.

The third axis is automation. The AI quotas are 100 calls per month in Standard, 500 in Professional, and 2,000 in Enterprise. Beyond that, billing is usage-based, and add-on packages start at €50.

Operation runs on ISO 27001 certified servers of Hetzner Online GmbH in Germany, and the data does not leave the EU. Enterprise additionally offers an on-premise option. In the public sector this point is cost-relevant, because self-hosting produces infrastructure and operating costs of its own.

Two levers lower the price without negotiation: 20% for nonprofit organizations, and annual instead of monthly billing. The latter pushes the monthly price in Standard to €240 instead of €290 and in Professional to €575 instead of €690, around 17%. For your own calculation across several years, the ROI calculator helps.

How do you compare two quotes that cost the same?

When two ISMS quotes cost the same, scope decides. Check how many frameworks are included in the price, whether they sit on a shared data model, how many people are allowed to work in it, and what rollout comes with it. Six questions to the quote make the difference visible.

The point behind this is plain: at the same monthly price, one solution covers one standard family and another covers several standards on a shared data model. That is a test criterion you can apply to any quote, not a verdict on the vendor.

Why scope hangs on the data model becomes clear in daily work. A control that contributes to ISO 27001, BSI IT-Grundschutz, and NIS2 at the same time is maintained once and evidenced once on a shared data model. Separate systems produce the same evidence several times over. That does not show up in the license but in the hours spent internally.

Six questions to put to both vendors:

  1. Which frameworks are included in the price, and what does another one cost?
  2. Do these frameworks sit on one data model, or are they separate modules with their own maintenance?
  3. How many people are allowed to work in it, and who counts as a user at all?
  4. Is the rollout included, and with what scope of services?
  5. What does operation cost in the third year, with the user count expected by then? What is meant is the total cost of ownership, not the entry price.
  6. Where does the data sit, and who operates it?

Question five can be worked through with a concrete figure. An additional user at KaitoSec costs €29 per month (price overview). If the team grows by five people, that is €5,220 extra over three years. Every quote should be able to answer the same calculation.

There are legitimate cases for each of the three price tiers. A one-person organization with one standard needs no platform, a corporate group with 40 sites will not be happy with the middle tier. This article answers the question of price, not the question of the winner.

If you want to check your own figures, user count, frameworks, and rollout effort can be worked through in a conversation.

What does the cost calculation look like for a company with 250 employees?

A company with 250 employees, an ISO 27001 goal, and NIS2 in scope pays around €5,820 for the software in the first year: the license on the Standard plan, five additional users, and one in-house training. Without additional users and without training it is €2,880. Internal staff effort comes on top and appears in no quote.

The following calculation is assembled from published individual prices; it is a worked example, not a quote. All amounts come from the price overview.

  • Standard plan, billed annually: €240 per month, so €240 × 12 = €2,880 per year. Included are three frameworks, unlimited controls, asset and policy management, 10 users, and 50 guests.
  • Five additional users for business units and IT: €29 × 5 × 12 = €1,740 per year.
  • One in-house training for the core team, up to 20 participants: from €1,200 one-off.
  • Total for year 1: around €5,820, of which €4,620 is recurring.
  • Without additional users and without training: €2,880 per year.

Not in this calculation is the internal staff effort. For a 250-person company there is no defensible, field-tested figure, and a made-up person-day number would be worthless. Work it out instead by the BSI's own method: record investment costs and staff effort for every planned measure, and separate one-off from recurring shares. The result is your figure, not that of some other company.

Also not included are the certification audit and the auditors' day rates. These items run separately from the software and are broken down in the cost of an ISO 27001 certification.

For municipalities and municipal companies, the hosting location comes in as a criterion of its own, because self-hosting produces additional infrastructure and operating costs that sit in no license fee; the possible operating models are shown in the overview for municipalities and public administration.

Frequently asked questions about the cost of ISMS software

What is the minimum an ISMS software costs?

Entry-level tools start at around €50 per month, but cover only one standard family and a single seat. KaitoSec offers a permanently free Free plan with one framework, up to 50 controls, and one user. For real multi-user operation, the market starts at around €200 per month, as of September 2026.

Is more expensive ISMS software automatically better?

No. In this market a higher price buys scope, not quality of outcome. The decisive question is how much recurring evidence work the tool actually takes off your hands: if you reassemble the same evidence for every audit, you pay the difference in working time, whatever the license costs.

Why do many vendors name no price on their website?

Because prices are calculated individually by user count, modules, and rollout scope, and because sales run through quotes instead of self-service. For buyers that means: without a quote there is no budget range and no defensible shortlist. Ask for a quote that shows price per user, included frameworks, and one-off rollout separately.

Do I need consulting on top, or is the software enough?

Consulting is optional and not part of the license fee. KaitoSec can be operated without it; anyone wanting support books it separately, according to the price overview remotely from €1,150 per day or as a vCISO retainer from €576 per month. Fixed-price packages for a gap analysis and a NIS2 check are also available.

What does an additional user cost?

At KaitoSec an additional user costs €29 per month in Standard and Professional according to the price overview; Standard includes 10 users and 50 guests, Professional 40 users. With other vendors, the amount depends on which roles count as users at all.

Isn't Excel enough for an ISMS?

For the first inventory yes, for permanent operation rarely. As soon as several people maintain the same controls, evidence has to be versioned, and a second standard joins, duplicate maintenance arises: the same measure sits in several files and is reassembled for every audit. Exactly this recurring effort, not the license fee, is the real cost block.

Are the costs of certification included in the software?

No, certification is paid separately. Auditor day rates, the certification body's fees, and the effort for audit preparation form a cost block of their own and sit in no software price. The software reduces the effort of handling evidence, but replaces neither the audit nor the certification body; the items are broken down in the separate article on ISO 27001 certification costs.

Sources

BSI, BSI-Standard 200-2: IT-Grundschutz-Methodik, chapter 9.2 „Kosten- und Aufwandsschätzung“, page 159. standard_200_2.pdf

ENISA, NIS Investments 2025, published 8 December 2025. What's driving cybersecurity investments and where lie the challenges

ENISA, NIS Investments 2024, published 22 November 2024. Navigating cybersecurity investments in the time of NIS 2

KaitoSec, price overview. All price, plan, training, and consulting details, checked on 9 September 2026

Price tiers: review of the publicly visible pricing pages of vendors common in the DACH market, as of September 2026.

  • isms
  • isms-software
  • kosten
  • preise
  • software-auswahl
  • mittelstand

Back to the blog