01
Continuity runs in the same system
A certificate does not keep operations running, and NIS2 Article 21 asks for business continuity in the same breath as incident handling. KaitoSec runs a full BCMS under ISO 22301 in the same data model as ISMS, DSMS and AIMS: BIA, recovery strategies, BC plans, exercises and their findings. Kertos carries no business continuity, so a supplier failure or a site outage is handled outside the platform.
02
One system that satisfies several frameworks
KaitoSec models assets, processes, risks and controls once, and each control counts towards every framework whose requirement it meets. You maintain one set of records instead of one per certification, and the management review covers all four systems at once.
03
Drafts from the connected context
KaitoSec drafts risk treatments, evidence notes, policy reviews and BIA entries from records that are already in the workspace, not from a blank page. People review and approve; KaitoSec AI shortens the way there.
04
BSI IT-Grundschutz as a first-class framework
Federal and state authorities, KRITIS operators and their suppliers often require BSI IT-Grundschutz. Kertos does not carry it. KaitoSec maps Basis-, Standard- and Kern-Absicherung into the same control catalogue as ISO 27001 and NIS2, so one mapping serves both audits.
05
Platform and advisory from one vendor
Advisory is optional in KaitoSec; the platform is built to run without it. When you book it, gap analysis, implementation support and certification support sit in the same engagement as the platform, with one point of accountability from kickoff through the first surveillance audit.
06
The work after the certificate
Most teams stall after the audit, where the PDCA cycle is supposed to keep the system alive. KaitoSec runs management reviews, internal audits, improvement actions and surveillance preparation in the same system the certificate was built in, so the next audit starts from a maintained state.