Skip to content

Compare

KaitoSec vs verinice

Every verinice classic installation faces a move. SerNet supports the classic client until the end of 2027, so the choice is verinice.veo or a different system. This page compares the second option.

verinice is the German ISMS tool from SerNet, open source under the AGPL and licensed by the BSI for the IT-Grundschutz methodology. The classic Java client is being replaced by verinice.veo, fully web-based and available as verinice.cloud or verinice.onprem, covering ISO 27001, IT-Grundschutz, data protection, NIS2, TISAX and BCM.

FeatureKaitoSecverinice
BSI IT-GrundschutzYesYes
ISO 27001YesYes
GDPRYesYes
NIS2YesYes
TISAXYesYes
ISO 22301YesYes
ISO 42001 (AIMS)YesNo
SOC 2YesNo
Four management systems on one data modelYesPartial
On-premise deploymentYesYes
BSI licence for the IT-Grundschutz methodologyNoYes
Open source, source code publicNoYes

Last reviewed in August 2026 against verinice's public product information at verinice.com. Product scopes change, so ask both vendors about the rows that decide your case.

When KaitoSec can be a good fit

01

The migration is happening either way

SerNet supports verinice classic until the end of 2027. Whichever way you go, the control register, the risk assessments and the evidence have to move. That is the moment to ask whether the target system should carry only the ISMS or the continuity, data protection and AI work as well.

02

Four systems on one data model

verinice.veo covers ISO 27001, IT-Grundschutz, data protection, NIS2, TISAX and BCM as separate domains. KaitoSec runs ISMS, BCMS, DSMS and AIMS on one data model, so a critical asset feeds control selection, recovery planning and the AI system inventory at the same time, and one management review covers all four.

03

Advisory in the same engagement

SerNet sells consulting as well, so this is not about availability but about the seam. In KaitoSec, gap analysis, implementation support and certification support run in the same workspace as the records they touch, and advisory stays optional and separately priced.

04

The PDCA cycle after the certificate

Management reviews, internal audits, improvement actions and surveillance preparation run in KaitoSec in the same system the certificate was built in. Ask both vendors to walk you through year two rather than the implementation project.

05

Depth for the ISB, a way in for everyone else

An ISMS is filled in by people who do not work in it daily: process owners, department heads, whoever runs the management review. KaitoSec offers them Simple Mode and the ISB Expert Mode, with KaitoSec AI drafting from the workspace context via Cmd+J. Both work on the same records, each at the depth their role needs.

When verinice can be a good fit

01

The BSI licence and two decades in public administration

SerNet holds a BSI licence for the IT-Grundschutz methodology and has spent close to twenty years inside German public administration. Where a procurement framework or an IT security guideline names verinice, that is the path of least resistance, and it is a real one.

02

Open source and the offline option

verinice is open source under the AGPL and the code is public on GitHub. The classic client runs entirely offline, which matters in classified or air-gapped environments, and source code transparency satisfies procurement rules that require auditable software. KaitoSec offers neither.

FAQ

Can KaitoSec replace verinice for BSI IT-Grundschutz?

KaitoSec carries Grundschutz Bausteine, requirements and threats and links them to ISO 27001 and NIS2 where the content aligns. Whether a replacement fits depends on your profiles, your existing data, your integrations and the migration path, and those belong in a review before the decision, not after it.

Is KaitoSec suitable for German public authorities?

KaitoSec supports on-premise deployment, German-language interfaces and BSI IT-Grundschutz, and it meets the data sovereignty requirements common in public administration. What it does not have is a BSI licence for the methodology or a twenty-year procurement history; verinice has both. Weigh that against the frameworks you need beyond Grundschutz.

What happens to our existing verinice data if we migrate?

Migration is a named service in the engagement, not a side effect of onboarding: export from verinice in its VNA format — the same format verinice's own v2v tool uses for the move to verinice.veo — then a mapping pass onto the KaitoSec model and the evidence import for the historical audit trail. Scope, gaps and cutover are agreed before anything is imported.

verinice has been around since 2007. Is KaitoSec proven?

Age is one argument, current fit is another. The BSI has published its Grundschutz++ milestone plan: the pilot phase started on 1 April 2026, the release follows at it-sa in October 2026, and certification under ISO 27001 on that basis begins on 1 January 2027. Ask both vendors what their migration plan for it looks like. KaitoSec already holds the Bausteine machine-readable and linked to assets and evidence.

Is verinice.veo enough for us?

For ISO 27001, IT-Grundschutz, data protection, NIS2, TISAX and BCM, verinice.veo covers the German core, and it does so under a BSI licence with an open codebase. The gap opens where ISO 42001, SOC 2 or DORA belong in the picture, or where you want the four systems on one data model rather than side by side. If your scope is the German core and nothing beyond it, take verinice.veo seriously.

Check this against your own scope

A matrix shows what a product covers. Your audit asks about your frameworks, your deployment constraints and your team size. Bring those and we go through the rows that decide your case.