Skip to content

Compare

KaitoSec vs Kertos

Kertos covers a broad certification catalogue but carries no business continuity. NIS2 requires it in Article 21, and KaitoSec runs it as a full BCMS next to the ISMS.

Kertos is a German compliance automation platform for the DACH market. Its framework library covers GDPR, NIS2, the EU AI Act, ISO 27001, ISO 42001, ISO 27701, SOC 2, TISAX and C5. Business continuity is missing, although NIS2 demands it in Article 21 and KRITIS operators have to evidence it. BSI IT-Grundschutz is missing as well.

FeatureKaitoSecKertos
ISO 22301YesNo
BSI IT-GrundschutzYesNo
ISO 27001YesYes
TISAXYesYes
SOC 2YesYes
GDPRYesYes
NIS2YesYes
ISO 42001YesYes
BSI C5 attestationYesYes
Four management systems on one data modelYesNo
On-premise deploymentYesNo
DACH-based, German-speaking advisoryYesYes

Last reviewed in August 2026 against Kertos's public product information at kertos.io. Product scopes change, so ask both vendors about the rows that decide your case.

When KaitoSec can be a good fit

01

Continuity runs in the same system

A certificate does not keep operations running, and NIS2 Article 21 asks for business continuity in the same breath as incident handling. KaitoSec runs a full BCMS under ISO 22301 in the same data model as ISMS, DSMS and AIMS: BIA, recovery strategies, BC plans, exercises and their findings. Kertos carries no business continuity, so a supplier failure or a site outage is handled outside the platform.

02

One system that satisfies several frameworks

KaitoSec models assets, processes, risks and controls once, and each control counts towards every framework whose requirement it meets. You maintain one set of records instead of one per certification, and the management review covers all four systems at once.

03

Drafts from the connected context

KaitoSec drafts risk treatments, evidence notes, policy reviews and BIA entries from records that are already in the workspace, not from a blank page. People review and approve; KaitoSec AI shortens the way there.

04

BSI IT-Grundschutz as a first-class framework

Federal and state authorities, KRITIS operators and their suppliers often require BSI IT-Grundschutz. Kertos does not carry it. KaitoSec maps Basis-, Standard- and Kern-Absicherung into the same control catalogue as ISO 27001 and NIS2, so one mapping serves both audits.

05

Platform and advisory from one vendor

Advisory is optional in KaitoSec; the platform is built to run without it. When you book it, gap analysis, implementation support and certification support sit in the same engagement as the platform, with one point of accountability from kickoff through the first surveillance audit.

06

The work after the certificate

Most teams stall after the audit, where the PDCA cycle is supposed to keep the system alive. KaitoSec runs management reviews, internal audits, improvement actions and surveillance preparation in the same system the certificate was built in, so the next audit starts from a maintained state.

When Kertos can be a good fit

01

Fewer moving parts for a cloud-native team

Kertos has the smaller surface. A SaaS company whose customers ask for ISO 27001, SOC 2, TISAX and a GDPR record, and nothing from the German public sector, spends less time in configuration and onboarding than in a four-system workspace.

02

A shorter path for a narrow scope

If ISO 27001 and data protection are the whole requirement and continuity is handled elsewhere, Kertos gets there with less product to learn. A smaller scope is a legitimate reason to pick a smaller system.

FAQ

Does Kertos offer a BCMS?

Not in its published framework library, which covers GDPR, NIS2, the EU AI Act, ISO 27001, ISO 42001, ISO 27701, SOC 2, TISAX and C5. Ask directly whether BIA, RTO and RPO, recovery plans and exercises are in the current offer. KaitoSec runs that work in the same data model as the ISMS, so a critical process carries both its controls and its recovery plan.

What does "one management system vs a stack of frameworks" mean in practice?

Kertos implements ISO 27001 and adjacent frameworks in parallel, each with its own workflow. KaitoSec models your assets, processes, risks and controls once and then satisfies whichever frameworks each control maps onto. It shows up when the second framework arrives: you extend a model instead of starting a project.

Does Kertos support BSI IT-Grundschutz?

No. The published library covers GDPR, NIS2, the EU AI Act, ISO 27001, ISO 42001, ISO 27701, SOC 2, TISAX and C5, and BSI IT-Grundschutz is not among them. For federal and state authorities, KRITIS operators and their suppliers that is often the deciding row. KaitoSec ships Basis-, Standard- and Kern-Absicherung mapped to the same controls as ISO 27001 and NIS2.

Is on-premise deployment available?

Kertos publishes no on-premise option; verify current deployment models, data flows and tenant separation with them directly. KaitoSec offers on-premise in the Enterprise plan, and the hosting and operating path is agreed as part of the scope.

How does pricing compare?

Ask both for the same scope and compare the total, not the licence: frameworks in use, users, implementation effort, advisory days and the hours your team spends operating the system afterwards. KaitoSec publishes list prices per user below the Enterprise plan; advisory is quoted separately because it is optional.

If ISO 27001 is our only requirement, is KaitoSec oversized?

With a single framework and no continuity requirement, the difference between the two products is small and comes down to workflow and advisory. It grows the moment a second framework, a BCMS or Grundschutz enters the scope, because that is where parallel workflows turn into parallel record-keeping. Judge it on the scope you will have in two years.

Can we move from Kertos to KaitoSec later?

Yes, after an export and a mapping test. Existing controls, policies and evidence are checked against the KaitoSec model first, then scope, gaps and cutover are agreed before anything is imported. Teams usually run both in parallel until the first internal audit passes in the new system.

Check this against your own scope

A matrix shows what a product covers. Your audit asks about your frameworks, your deployment constraints and your team size. Bring those and we go through the rows that decide your case.