Skip to content

Compare

KaitoSec vs Secjur

Secjur automates a broad ISMS and data-protection catalogue for German-speaking mid-market companies. Two things are missing from that catalogue: a full BSI IT-Grundschutz mapping and a business continuity system, and the platform runs cloud only. KaitoSec carries all three.

Secjur is a German compliance automation platform, founded in 2018 in Hamburg. Its Digital Compliance Office targets mid-market companies and corporate subsidiaries across the DACH region, with end-to-end coverage for ISO 27001, TISAX, NIS2, DORA and SOC 2, and partial coverage for BSI IT-Grundschutz and BSI C5.

FeatureKaitoSecSecjur
BSI IT-GrundschutzYesPartial
ISO 27001YesYes
TISAXYesYes
NIS2 under the German implementation lawYesYes
GDPR with German supervisory practiceYesYes
SOC 2YesYes
ISO 22301YesNo
ISO 42001YesNo
On-premise deploymentYesNo
Four management systems on one data modelYesPartial
Published list pricesYesNo
Integrations for German mid-market IT (i-doit, Docusnap, Matrix42, macmon)YesNo

Last reviewed in September 2026 against Secjur's public product information at secjur.com. Product scopes change, so ask both vendors about the rows that decide your case.

When KaitoSec can be a good fit

01

Continuity is missing from the catalogue

Secjur's own platform page names end-to-end coverage for ISO 27001, TISAX, NIS2, DORA and SOC 2 — ISO 22301 does not appear anywhere on that list. NIS2 asks for business continuity in Article 21 in the same breath as incident handling. KaitoSec runs a full BCMS under ISO 22301 in the same data model as the ISMS: BIA, recovery strategies, BC plans and exercises whose findings become risks and actions.

02

Grundschutz beyond the partial mapping

Secjur states its own coverage of BSI IT-Grundschutz as partial, alongside end-to-end coverage for ISO 27001. For federal and state authorities, KRITIS operators and their suppliers, Grundschutz is often the binding requirement, not an extra next to ISO 27001. KaitoSec carries Basis-, Standard- and Kern-Absicherung as a full framework, mapped to the same controls as ISO 27001 and NIS2.

03

Deployment where the data may not leave

Secjur's Digital Compliance Office runs as SaaS hosted in Germany; no on-premise option appears in its public product information. For organisations under a policy that keeps security data in their own infrastructure — many authorities, KRITIS operators, defence suppliers — that ends the evaluation regardless of framework depth. KaitoSec offers on-premise deployment in the Enterprise plan.

04

AI governance as a management system, not just a legal duty

Secjur's AI product addresses the EU AI Act's legal obligations. It does not carry ISO 42001, the management system standard for AI. KaitoSec runs ISO 42001 as a full AIMS, sharing assets, risks and controls with the ISMS, so an AI system's classification feeds the same risk register the ISMS already maintains.

05

One price you can put in front of finance

Secjur quotes DCO access on request only; its own blog content names a starting point of roughly €8,000 to €10,000 as an orientation figure, not a binding list price, and no tiered public pricing page exists as of September 2026. KaitoSec publishes list prices per user below the Enterprise plan and quotes advisory as a separate line, so procurement can model the total before the first call.

When Secjur can be a good fit

01

A genuinely shared data model for ISMS and data protection

Secjur is not just a bundle of separate products. Its own product pages describe one shared asset register with protection-need and personal-data classification that feeds both the ISO 27001 risk analysis and the GDPR risk view, with control mapping shared across ISO 27001, TISAX, NIS2 and GDPR. Where the requirement stops at those four frameworks, that overlap is real and saves duplicate record-keeping.

02

Coverage across the whole DACH region

Secjur expanded into Switzerland in 2023 and names the revised Swiss data protection act (nDSG) alongside the Austrian NIS2 implementation (NISG) in its own product material, next to the German rules. An organisation with entities in Germany, Austria and Switzerland gets a single vendor that speaks to all three sets of local rules.

03

TÜV- and ISACA-certified advisors bundled with the platform

Secjur bundles gap analysis and certification support with the DCO through consultants it describes as TÜV and ISACA certified, and cites a self-reported 100% success rate on ISO 27001 and TISAX audits. Buyers who want platform and audit preparation from a single line item get that as the default, not an add-on.

FAQ

Does secjur support BSI IT-Grundschutz?

Only partially. Secjur's own platform page states end-to-end coverage for ISO 27001, TISAX, NIS2, DORA and SOC 2, and separately names 'partial coverage' for BSI IT-Grundschutz and BSI C5. Ask secjur directly which Bausteine and Schutzbedarf categories that partial mapping actually reaches. KaitoSec carries Grundschutz as a full framework, with Basis-, Standard- and Kern-Absicherung mapped to the same controls as ISO 27001 and NIS2.

Does secjur run a business continuity management system?

Not as a published framework. Secjur's framework list covers ISO 27001, TISAX, NIS2, DORA, SOC 2, GDPR and the EU AI Act; ISO 22301 does not appear on it. Confirm directly whether BIA, RTO/RPO and recovery plans are in the current offer. KaitoSec runs a full BCMS in the same data model as the ISMS, so a critical process carries both its controls and its recovery plan.

Is secjur available on-premise?

No. Secjur's Digital Compliance Office is hosted in Germany as SaaS; its public product information names no on-premise option. If your policy requires the compliance tool inside your own infrastructure, verify this directly with secjur before shortlisting it. KaitoSec offers on-premise deployment in the Enterprise plan.

What does secjur cost?

Secjur names no public price list; every page points to a quote request. Secjur's own blog content mentions a starting point of roughly €8,000 to €10,000 as an orientation figure for the platform, not a fixed price. On pricing you're comparing an estimate against a list: KaitoSec publishes list prices per user below the Enterprise plan and quotes advisory as a separate line. Put the same scope — frameworks, users, integrations, advisory days — in front of both before you compare totals.

We're a small team. Is secjur the right size for us?

Independent reviews describe secjur as built for mid-market companies and corporate subsidiaries, roughly 50 to 1,500 employees, and note it can feel oversized for teams under about 20 people, who are often pointed toward smaller tools instead. Bring your own headcount, framework list and team structure to a review with either vendor rather than sizing from a segment label.

Should we replace secjur or run both?

That depends on scope. If ISO 27001, TISAX, NIS2, GDPR and SOC 2 are the whole requirement and continuity and Grundschutz stay out of scope, secjur's shared asset and risk register across those frameworks is a real advantage, not a reason to switch on its own. The evaluation changes once BSI IT-Grundschutz needs to go beyond partial coverage, business continuity enters the picture, or on-premise deployment becomes a hard requirement — those are the rows secjur itself does not claim to cover.

Check this against your own scope

A matrix shows what a product covers. Your audit asks about your frameworks, your deployment constraints and your team size. Bring those and we go through the rows that decide your case.