Kertos automates compliance framework by framework with ISO 27001 at the centre. KaitoSec runs BCMS, ISMS, DSMS and AIMS as one management system.
| Feature | KaitoSec | Kertos |
|---|---|---|
| BCMS (ISO 22301): business continuity | ||
| Integrated four-system management | ||
| ISMS (ISO 27001, BSI Grundschutz, TISAX, SOC 2) | ||
| DSMS (GDPR, ISO 27701) | ||
| AIMS (ISO 42001) as a full management system | ||
| NIS2 and DORA in the same data model | ||
| On-premise deployment | ||
| DACH-based, German-speaking experts |
Where KaitoSec wins
A certificate does not keep operations running. KaitoSec runs a full BCMS (ISO 22301) inside the same data model as the ISMS, DSMS, and AIMS: BIA, recovery strategies, BC plans, exercises, lessons learned. Kertos has no BCMS. When a supplier fails or a site goes down, that gap is where the operating model collapses.
Kertos's multi-framework story is a stack of single-purpose framework workflows. KaitoSec is one integrated management system that satisfies multiple frameworks where the substance overlaps. One data model, one maintenance burden, four defensible systems.
Kertos's AI sits next to its ISO and GDPR workflows. KaitoSec's agents run across BCMS, ISMS, DSMS, and AIMS together. Risk treatments, evidence collection, policy reviews, and BIA work happen in one model, not four parallel ones.
Federal agencies, KRITIS operators, and their supply chain often require BSI IT-Grundschutz. Kertos does not cover it. KaitoSec maps Grundschutz baseline, standard and core protection profiles into the same control catalogue as ISO 27001 and NIS2. One mapping, both audits.
Kertos sells software; Expert Support is an add-on, not a mandate. KaitoSec ships the platform, the gap analysis, the implementation work, and the certification companion as one engagement. One point of accountability from kickoff to passed audit, then through the next surveillance cycle.
Kertos is optimised for the path to the certificate. The Plan-Do-Check-Act cycle that keeps an ISMS alive afterwards is where most teams stall. KaitoSec runs management reviews, internal audits, improvement actions, and surveillance prep in the same system the certificate was built in. The cert is where the engagement begins, not where it ends.
Kertos has invested deeply in ISO 27001 and GDPR workflows. For a team whose scope ends at those two frameworks, the experience is polished and the time-to-certificate is real.
Kertos has built recognition in the German mid-market and a credible expert plus automation combination. The gap is scope (no BCMS, no integrated four-system model), not capability inside their lane.