01
Who runs the tool that carries your compliance
eramba runs self-hosted or hosted by eramba. Either way the operating questions stay with you: updates, backups, patching and availability of the GRC tool itself. KaitoSec runs as a managed service, with on-premise available in the Enterprise plan where policy requires it.
02
The German frameworks eramba does not carry
eramba covers ISO 27001, general GDPR and adjacent international frameworks. BSI IT-Grundschutz and TISAX are not in it, and building them by hand means maintaining a control catalogue and its cross-references yourself. KaitoSec carries both natively and maps them to ISO 27001 and NIS2 where the requirements overlap.
03
Advisory in German, from the same vendor
eramba is a tool you configure and run yourself; the enterprise plan adds support, not advisory. KaitoSec offers German-speaking gap analysis, implementation support and certification support as a named mandate, optional and separately priced, so an organisation without a dedicated CISO still has someone to ask.
04
Four management systems on one data model
eramba ships risk, compliance, audit, policy and incident modules, each holding its own data. KaitoSec runs BCMS, ISMS, DSMS and AIMS on one data model: a risk identified in the ISMS becomes a BC scenario, and a critical asset feeds both control selection and recovery planning.