# KaitoSec > KaitoSec is a resilience platform that runs four management systems in one place: information security (ISMS), business continuity (BCMS), data protection (DSMS), and AI governance (AISMS). One data model maps every relevant framework, so evidence and controls are entered once and reused across standards. KaitoSec is built and hosted in Germany on ISO 27001-certified infrastructure, with data kept in the EU. The platform covers risk management, control mapping, policy management, audit preparation, and reporting across the four systems. Every page exists in German and English. The core market is Germany, Austria and Switzerland (DACH), so the links below point at the German pages; each page links its English translation through the language switch and hreflang alternates, and translated URL segments can differ, such as `/de/frameworks/dsgvo` and `/en/frameworks/gdpr`. Blog articles are listed in German where a German version exists and in English otherwise. ## Platform - [GRC Software and ISMS Tool: ISO 27001, BSI, NIS2](https://kaitosec.app/de): GRC software for ISMS, risk management and compliance. ISO 27001, BSI IT-Grundschutz, NIS2 and DORA—up to 6x faster. Made in Germany. - [Integrations for Entra ID, AWS, i-doit and Jira](https://kaitosec.app/de/integrations): Read-only connections from Entra ID through AWS, i-doit and PRTG to SharePoint and Jira. KaitoSec turns system state into audit-ready evidence. - [The four-system resilience platform](https://kaitosec.app/de/platform): ISMS, BCMS, DSMS and AIMS on one data model: KaitoSec connects risks, controls, assets and evidence so your team works without duplicate upkeep. - [AI for GRC & ISMS: Agentic Compliance Automation](https://kaitosec.app/de/platform/ai-assistant): AI for GRC and ISMS: draft policies, assess risks, collect evidence and prepare audits, all with traceability, GDPR compliance and human approval. - [Asset management: owners and dependencies](https://kaitosec.app/de/platform/asset-management): Capture systems, processes, data, vendors and AI components with an owner, criticality and dependencies. Reuse the same context for ISMS, BIA, RoPA and AIMS. - [Business Continuity](https://kaitosec.app/de/platform/business-continuity): Connect critical processes, recovery objectives, plans and exercises to risks and dependencies. During disruption, the applicable plan and owner are clear. - [Compliance mapping across standards](https://kaitosec.app/de/platform/compliance-mapping): Connect one implemented control to every requirement it genuinely supports. Keep coverage, differences, owners and evidence traceable across standards. - [Policy management: version, approval, proof](https://kaitosec.app/de/platform/policy-management): Connect policies to requirements, approval, applicable version, acknowledgement and review. Prove what applied, who approved it and which control it implements. - [Reporting & Dashboards](https://kaitosec.app/de/platform/reporting): Report risk decisions, exercises, vendor reviews, policy acknowledgements and open actions from one current state for management and audit. - [Risk management: treatment, owners, evidence](https://kaitosec.app/de/platform/risk-management): Connect risks to affected assets, treatment, owners and evidence. Steer open decisions and residual risk from one current working view. - [Threat Intelligence](https://kaitosec.app/de/platform/threat-intelligence): Connect CAPEC, CWE, MITRE ATT&CK, OWASP and BSI to assets, risk scenarios, controls and exercises. Assessment time goes into relevance, not transcription. - [Trust center for customer security reviews](https://kaitosec.app/de/platform/trust-center): Provide approved certifications, security practices, subprocessors and evidence to customers and prospects under controlled access. - [Vendor management: contracts and reviews](https://kaitosec.app/de/platform/vendor-management): Manage vendors, sub-processors, contracts, security assessments and operational dependencies in one context. Open reviews and follow-up work remain accountable. - [Pricing: plans for ISMS, BCMS, DSMS and AIMS](https://kaitosec.app/de/pricing): From a free ISO 27001 start to ISMS, BCMS, DSMS and AIMS on one data model: KaitoSec shows all plans and what they include. ## Frameworks - [Frameworks: one data model, every obligation](https://kaitosec.app/de/frameworks): ISO 27001, BSI IT-Grundschutz, NIS2, DORA, GDPR, ISO 42001 and more in one platform. Implement a control once, evidence it across every framework. - [BSI IT-Grundschutz Software: Certification Tool](https://kaitosec.app/de/frameworks/bsi-grundschutz): BSI IT-Grundschutz software for structural analysis, modelling, the Grundschutz Check and risk analysis under BSI 200-1 to 200-3. Compendium included. - [DORA Compliance for Financial Services](https://kaitosec.app/de/frameworks/dora): Run ICT risks, incidents, resilience testing and third-party evidence for DORA from one accountable working state. - [EU AI Act Compliance Platform](https://kaitosec.app/de/frameworks/eu-ai-act): Inventory AI systems, justify risk classifications and maintain traceable governance evidence for the EU AI Act. - [GDPR Compliance Management](https://kaitosec.app/de/frameworks/dsgvo): Run RoPA, DPIAs, data-subject requests, legal bases and evidence with clear owners in one data protection management system. - [ISO 22301 Business Continuity Management](https://kaitosec.app/de/frameworks/iso-22301): ISO 22301 BCMS as one of four management systems. BIA, recovery strategies, BC plans, exercises and management review next to ISMS, DSMS and AIMS. - [ISO 27001 Software: ISMS Tool for Certification](https://kaitosec.app/de/frameworks/iso-27001): ISO 27001 software to build, operate and audit an ISMS. Manage Annex A controls, SoA, risk analysis and evidence in one tool—certification-ready in weeks. - [ISO 42001 AI Management System](https://kaitosec.app/de/frameworks/iso-42001): Implement ISO 42001, the international standard for AI management systems. Govern the AI lifecycle responsibly and align with the EU AI Act from day one. - [KRITIS-Dachgesetz on one resilience platform](https://kaitosec.app/de/frameworks/kritis-dg): Physical security, business continuity and cyber measures under the KRITIS-Dachgesetz (CER Directive transposition) on one data model with your ISMS and BCMS. - [NIS2 Software: Implementation & Evidence](https://kaitosec.app/de/frameworks/nis2): NIS2 software for NIS2UmsuCG: check applicability, map Section 30 measures, manage supply-chain risk and document reporting obligations. - [NIST CSF 2.0 mapped to your ISMS](https://kaitosec.app/de/frameworks/nist-csf): NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) implemented once, mapped to ISO 27001, BSI IT-Grundschutz and NIS2 on one model. - [SOC 2 for SaaS on one evidence trail](https://kaitosec.app/de/frameworks/soc-2): Run Trust Services Criteria, control owners and period-specific SOC 2 evidence from the same working state as ISO 27001. - [TISAX Compliance for the Automotive Supply Chain](https://kaitosec.app/de/frameworks/tisax): Run VDA ISA requirements, owners, controls and evidence for the TISAX assessment in one traceable working state. ## Solutions - [BSI IT-Grundschutz for municipalities](https://kaitosec.app/de/kommunen): WIBA questionnaire, the municipal IT-Grundschutz profile and Grundschutz++ in one tool. Priced below direct-award thresholds, on-premise included. - [Solutions by role and company size](https://kaitosec.app/de/solutions): Nine starting points for ISMS, risk management, company contexts and accountable roles. Each names the work KaitoSec takes off your desk. - [Platform for ISO and CISO Roles](https://kaitosec.app/de/solutions/isb-ciso): ISMS, BCMS, DSMS and AIMS in one workspace for security officers and CISOs in the German mid-market. Controls, risks, incidents and audits in one place. - [ISMS software for ISO 27001 and IT-Grundschutz](https://kaitosec.app/de/solutions/isms): ISMS software for ISO 27001, IT-Grundschutz and TISAX. Manage policies, risks, controls and evidence in one system for security and compliance teams. - [Resilience Platform for Executive Leadership](https://kaitosec.app/de/solutions/manager): Make risk posture, open decisions and crisis readiness understandable to leadership, oversight and audit from one shared state. - [ISMS for SMEs: GRC software for the mid-market](https://kaitosec.app/de/solutions/mittelstand): ISMS and compliance for SMEs without a dedicated security team. Run ISO 27001, TISAX and NIS2 in one tool, without Excel or consultant dependency. - [Platform for Process Owners](https://kaitosec.app/de/solutions/prozess-owner): Process, application, vendor and risk in one view. KaitoSec makes process ownership auditable and reuses process data as the base for ISMS and BCMS. - [QMS Bridge to ISMS and BCMS](https://kaitosec.app/de/solutions/qms): One process landscape carries ISO 9001, ISO 27001 and ISO 22301 at once. KaitoSec links QMS processes to controls, risks and vendors. - [Risk management software for IT and compliance](https://kaitosec.app/de/solutions/risikomanagement): Risk management software for information security, suppliers and continuity. Run ISO 27005 and BSI 200-3 assessments in one GRC system. - [KaitoSec for SaaS | Continuity as product](https://kaitosec.app/de/solutions/saas): SOC 2, ISO 27001, GDPR, and a BCMS in one data model. Trust Center, vendor management, and questionnaire workflows compile from running operations. - [KaitoSec for startups | Resilience before enterprise review](https://kaitosec.app/de/solutions/startups): Run BCMS, ISMS, DSMS, and AIMS from day one. SOC 2, ISO 27001, and GDPR readiness become by-products of operating well, not a parallel project. ## Services - [ISMS and NIS2 consulting](https://kaitosec.app/de/consulting): Gap analysis, ISMS implementation, certification support: consulting that documents itself in your workspace. The results remain workable after the engagement. - [For consultancies: projects on the platform](https://kaitosec.app/de/for-consultants): The KaitoSec platform as your delivery tool: you run the engagement, your client keeps operating the result. - [Migration from legacy tools](https://kaitosec.app/de/migration): Migration from verinice, HiScout, eramba, Vanta and other tools: we move assets, risks, controls and documents into KaitoSec, structured and traceable. - [Onboarding in one day](https://kaitosec.app/de/onboarding): A guided path from defined scope to a working state that security, owners and management can continue in daily operations. - [Partner programs for resellers and consultancies](https://kaitosec.app/de/partners): Reseller, integration and consulting programs: you build on KaitoSec and deliver ISMS, BCMS, DSMS and AIMS as one resilience system. - [ISMS, BCMS and NIS2 services](https://kaitosec.app/de/services): Consulting, onboarding, migration and training: four building blocks that bring your ISMS into operation and keep it there. - [Training for ISMS, business continuity and NIS2](https://kaitosec.app/de/training): Role-based training for KaitoSec, ISMS practice, risk management and awareness with documentable attendance and clear application in the workspace. ## Guides and knowledge - [Compliance glossary for ISMS, BCMS, DSMS, AIMS](https://kaitosec.app/de/glossary): Every term with a definition, its place in the standard and related entries. For information security, business continuity, data protection and AI governance. - [Guides for ISO 27001, NIS2 and BSI IT-Grundschutz](https://kaitosec.app/de/guides): Three step-by-step guides on ISO 27001 certification, NIS2 scope and duties, and getting started with BSI IT-Grundschutz. - [Getting started with BSI IT-Grundschutz](https://kaitosec.app/de/guides/bsi-grundschutz-starter): A beginner's guide to BSI IT-Grundschutz: learn the methodology, understand Bausteine and modules, and start building your ISMS with this German standard. - [ISO 27001 checklist for smaller companies](https://kaitosec.app/de/guides/iso-27001-checklist): A practical ISO 27001 checklist for small and medium businesses. Covers Annex A controls, gap analysis, and step-by-step certification guidance. - [IT-Grundschutz tools compared](https://kaitosec.app/de/guides/it-grundschutz-tools-vergleich): GSTOOL is discontinued. What follows: verinice, HiScout, eramba and KaitoSec compared by methodology, open source, cost and operations. - [NIS2 guide to scope, duties and deadlines](https://kaitosec.app/de/guides/nis2-compliance-guide): Everything you need to know about the EU NIS2 Directive: who is affected, what is required, key deadlines, and how to prepare your organization. - [Practical resilience and compliance knowledge](https://kaitosec.app/de/knowledge): Practical guidance, checks, and templates for NIS2, ISO 27001, BSI IT-Grundschutz, privacy, business continuity, and third-party risk. - [Business continuity | From BIA to exercised plan](https://kaitosec.app/de/knowledge/bcms): Source-based guides, a local BCMS starter check and free templates for BIA, RTO/RPO, emergency planning and exercises. - [BCMS explained: what it actually steers](https://kaitosec.app/de/knowledge/bcms/articles/bcms-einfach-erklaert): A BCMS is neither an emergency binder nor pure IT recovery. It steers which services must be continued, and under which conditions. - [Planning BCMS exercises: tabletop to proof](https://kaitosec.app/de/knowledge/bcms/articles/bcms-uebungen-planen): Exercises must be allowed to disprove assumptions. For that they need clear objectives, a credible scenario and a clean evaluation. - [Business continuity strategies compared](https://kaitosec.app/de/knowledge/bcms/articles/business-continuity-strategien): A strategy connects recovery requirements with realistic solutions for staff, site, IT and supplier outages. - [Business impact analysis: from process to a robust priority](https://kaitosec.app/de/knowledge/bcms/articles/business-impact-analyse-bia): A BIA does not assess the probability of an outage. It shows how damage grows over time and when services are needed again. - [Crisis team and alerting: deciding fast](https://kaitosec.app/de/knowledge/bcms/articles/krisenstab-alarmierung): A dedicated response organisation only works if thresholds, roles, information channels and decision rights are clarified before the event. - [Suppliers in the BCMS: managing dependencies](https://kaitosec.app/de/knowledge/bcms/articles/lieferanten-bcm): An SLA alone does not prove emergency capability. Critical service providers need tiered BCM requirements, evidence and joint tests. - [Emergency manual, BCP and recovery plan](https://kaitosec.app/de/knowledge/bcms/articles/notfallplaene-richtig-trennen): A manual coordinates the response. Continuity plans secure the service. Recovery plans restore resources in a controlled way. - [RTO, RPO and MTPD: the difference explained](https://kaitosec.app/de/knowledge/bcms/articles/rto-rpo-mtpd-unterschied): RTO describes the target time until recovery, RPO the tolerated data loss and MTPD the outer limit of the outage. - [How resilient is your business continuity management?](https://kaitosec.app/de/knowledge/bcms/check): 20 questions check mandate, BIA, strategies, plans and exercises. The answers stay exclusively in this browser. - [The BCMS implementation path](https://kaitosec.app/de/knowledge/bcms/path): Business continuity: 7 chapters put decisions, responsibilities and evidence in a defensible order. - [Business continuity: start from a defensible draft.](https://kaitosec.app/de/knowledge/bcms/templates): Business continuity: 6 templates for workshops, registers, audits and reviews. No forms, straight to the file. - [BSI IT-Grundschutz – applying the method in practice](https://kaitosec.app/de/knowledge/bsi-grundschutz): Free working aids, checks and source-based guides for IT-Grundschutz under BSI Standards 200-1 to 200-4. - [Basic, Standard or Core Protection: which approach fits?](https://kaitosec.app/de/knowledge/bsi-grundschutz/articles/basis-standard-kern-absicherung): The three paths pursue different goals. The right choice depends on reach, time pressure and the desired evidence level. - [BSI IT-Grundschutz explained simply](https://kaitosec.app/de/knowledge/bsi-grundschutz/articles/bsi-it-grundschutz-einfach-erklaert): The standards explain the approach; the Compendium provides requirements for typical target objects. Only the modelling connects the two. - [Risk analysis under BSI Standard 200-3](https://kaitosec.app/de/knowledge/bsi-grundschutz/articles/bsi-standard-200-3-risikoanalyse): Additional risks are analysed where high protection needs, atypical operating conditions or insufficiently addressed threats exist. - [BSI Standard 200-4: connecting BCM with information security](https://kaitosec.app/de/knowledge/bsi-grundschutz/articles/bsi-standard-200-4-bcm): BIA, continuity strategies, emergency plans and exercises need shared dependencies with the information domain. - [Carrying out the IT-Grundschutz-Check](https://kaitosec.app/de/knowledge/bsi-grundschutz/articles/it-grundschutz-check-durchfuehren): Implementation status, justification, evidence and the open measure belong together. Otherwise the check remains a self-assessment. - [IT-Grundschutz modelling: mapping modules](https://kaitosec.app/de/knowledge/bsi-grundschutz/articles/it-grundschutz-modellierung): The modelling decides which requirements apply to which target objects. Mistakes here multiply across the entire IT-Grundschutz-Check. - [Structural analysis: the information domain](https://kaitosec.app/de/knowledge/bsi-grundschutz/articles/it-grundschutz-strukturanalyse): Business processes first, technology second. That keeps visible which information and systems actually matter for the service. - [Protection needs assessment: justify it](https://kaitosec.app/de/knowledge/bsi-grundschutz/articles/schutzbedarfsfeststellung-bsi): Protection needs arise from potential damage to processes and information. Inheritance and cumulation then carry them over to the technology. - [IT-Grundschutz starter check](https://kaitosec.app/de/knowledge/bsi-grundschutz/check): 20 evidence-backed questions from the security process through to maintenance. The evaluation stays local in your browser. - [Implementation path under BSI Standard 200-2](https://kaitosec.app/de/knowledge/bsi-grundschutz/path): BSI IT-Grundschutz: 7 chapters put decisions, responsibilities and evidence in a defensible order. - [BSI IT-Grundschutz: start from a defensible draft.](https://kaitosec.app/de/knowledge/bsi-grundschutz/templates): BSI IT-Grundschutz: 6 templates for workshops, registers, audits and reviews. No forms, straight to the file. - [Data protection | Organising the GDPR in practice](https://kaitosec.app/de/knowledge/datenschutz): Source-based data protection guides, a starter check and free templates for the record of processing, DPIAs, processors, deletion and incidents. - [Processing on behalf: vetting providers](https://kaitosec.app/de/knowledge/datenschutz/articles/auftragsverarbeitung-dienstleister-pruefen): A data processing agreement is the frame. Robustness comes from selection checks, concrete instructions, evidence of measures and ongoing oversight. - [Data subject rights and deletion in practice](https://kaitosec.app/de/knowledge/datenschutz/articles/betroffenenrechte-loeschkonzept): Deadlines can only be met when identification, search, decision, execution and evidence are prepared across systems and the people responsible. - [Building a data protection management system](https://kaitosec.app/de/knowledge/datenschutz/articles/datenschutzmanagementsystem-dsms): A privacy management system connects responsibilities, processing activities, risks, controls and evidence. Only then can data protection be operated. - [Personal data breach: the first 72 hours](https://kaitosec.app/de/knowledge/datenschutz/articles/datenschutzverletzung-72-stunden): Not every security incident is notifiable. But every suspicion needs a fast, documented assessment of data, consequences and countermeasures. - [Conducting a DPIA: structure and decisions](https://kaitosec.app/de/knowledge/datenschutz/articles/dsfa-datenschutz-folgenabschaetzung): A data protection impact assessment does not start with a long report, but with a solid threshold assessment and a clear processing scenario. - [Legal basis, purpose limitation, minimisation](https://kaitosec.app/de/knowledge/datenschutz/articles/rechtsgrundlage-zweckbindung-datenminimierung): A legal basis does not legitimise an arbitrary scope of data. Purpose, necessity and transparency must be documented as one connected decision. - [TOMs and privacy by design from the risk](https://kaitosec.app/de/knowledge/datenschutz/articles/tom-privacy-by-design): Technical and organisational measures must fit the processing context and remain effective across the entire lifecycle. - [Creating the RoPA as a steering instrument](https://kaitosec.app/de/knowledge/datenschutz/articles/vvt-verzeichnis-verarbeitungstaetigkeiten): A good record reflects real processing and links legal basis, data flows, recipients, deletion, risks and the people responsible. - [How robust is your data protection management?](https://kaitosec.app/de/knowledge/datenschutz/check): 20 questions cover governance, processing activities, data protection risks, data subject rights, service providers and incidents. Your answers stay local. - [The data protection implementation path](https://kaitosec.app/de/knowledge/datenschutz/path): Data protection: 7 chapters put decisions, responsibilities and evidence in a defensible order. - [Data protection: start from a defensible draft.](https://kaitosec.app/de/knowledge/datenschutz/templates): Data protection: 6 templates for workshops, registers, audits and reviews. No forms, straight to the file. - [ISO 27001 – putting ISO/IEC 27001 into practice](https://kaitosec.app/de/knowledge/iso-27001): Free templates, checks and source-based guides for a defensible ISMS under ISO/IEC 27001:2022. - [Planning an internal ISO 27001 audit](https://kaitosec.app/de/knowledge/iso-27001/articles/internes-audit-iso-27001): A good audit follows requirements into decisions, samples and actual operational evidence. - [Defining the ISMS scope for the audit](https://kaitosec.app/de/knowledge/iso-27001/articles/isms-scope-richtig-festlegen): A scope is not a marketing phrase. It has to delimit services, organisational units, sites, technology and interfaces consistently. - [ISO 27001:2022: what an ISMS actually has to deliver](https://kaitosec.app/de/knowledge/iso-27001/articles/iso-27001-2022-einfach-erklaert): The standard does not demand a museum of documents. It demands a steerable system for information risks, responsibilities and improvement. - [ISO 27001 risk assessment without false precision](https://kaitosec.app/de/knowledge/iso-27001/articles/iso-27001-risikoanalyse): A usable method connects business impact, scenarios and decisions. A colourful score alone is not yet risk management. - [Implementing ISO 27001: a realistic order for the start](https://kaitosec.app/de/knowledge/iso-27001/articles/iso-27001-umsetzung-roadmap): Scope, governance and risk method first. After that, controls, evidence and audits can be built without parallel worlds. - [Structuring the 93 controls of ISO 27002 sensibly](https://kaitosec.app/de/knowledge/iso-27001/articles/iso-27002-93-controls): Organisational, people, physical and technological: the four themes help with responsibility and evidence management. - [Management review under ISO 27001](https://kaitosec.app/de/knowledge/iso-27001/articles/managementbewertung-iso-27001): The management review is not a status presentation. It is meant to decide on changes, performance, resources and improvements. - [Statement of Applicability: how to run it](https://kaitosec.app/de/knowledge/iso-27001/articles/statement-of-applicability-soa): The SoA connects risks, selected controls, justifications and implementation status. It is more than a ticked-off Annex A list. - [ISO 27001 readiness check](https://kaitosec.app/de/knowledge/iso-27001/check): 20 verifiable questions on scope, risk, governance and improvement. The evaluation stays local in your browser. - [Implementation path along clauses 4 to 10](https://kaitosec.app/de/knowledge/iso-27001/path): ISO 27001: 7 chapters put decisions, responsibilities and evidence in a defensible order. - [ISO 27001: start from a defensible draft.](https://kaitosec.app/de/knowledge/iso-27001/templates): ISO 27001: 6 templates for workshops, registers, audits and reviews. No forms, straight to the file. - [Third-party risk | Managing cyber and vendor risk](https://kaitosec.app/de/knowledge/tprm): Source-based guides, a local TPRM starter check and free templates for vendor tiering, due diligence, evidence, monitoring and exit. - [Continuous monitoring of vendors](https://kaitosec.app/de/knowledge/tprm/articles/continuous-monitoring-lieferanten): Continuous monitoring combines contractual information, performance data, security events, evidence and internal changes. - [Making fourth parties and concentration risks visible](https://kaitosec.app/de/knowledge/tprm/articles/fourth-party-konzentrationsrisiko): Many seemingly independent providers depend on the same cloud, identity, network or software services. - [Vendor due diligence: asking questions, assessing evidence](https://kaitosec.app/de/knowledge/tprm/articles/lieferanten-due-diligence): A completed questionnaire is a claim. Only matching evidence, scope and recency turn it into a reliable assessment. - [Vendor exit and offboarding under control](https://kaitosec.app/de/knowledge/tprm/articles/lieferanten-exit-offboarding): An exit does not begin with the termination notice. Critical relationships need return, migration and transition scenarios defined early. - [Vendor inventory and criticality](https://kaitosec.app/de/knowledge/tprm/articles/lieferanteninventar-kritikalitaet): One provider can deliver several services with completely different risk. The specific relationship is therefore classified, not just the company. - [Vendor incidents: reporting paths first](https://kaitosec.app/de/knowledge/tprm/articles/lieferantenvorfall-meldewege): If a provider only starts looking for the right contact after hours have passed, the contractual reporting obligation is operationally worthless. - [Agreeing concrete security requirements with vendors](https://kaitosec.app/de/knowledge/tprm/articles/sicherheitsanforderungen-lieferantenvertrag): Control objectives only become manageable when scope, deadline, evidence, reporting path and the consequences of a deviation fit the specific service. - [Third-party risk management: what a TPRM actually governs](https://kaitosec.app/de/knowledge/tprm/articles/third-party-risk-management-einfach-erklaert): TPRM connects procurement, information security, privacy, BCM and business ownership across the entire vendor lifecycle. - [How resilient is your third-party risk management?](https://kaitosec.app/de/knowledge/tprm/check): 20 questions cover governance, inventory, criticality, due diligence, contracts, monitoring, incidents, subcontractors and exit. Everything stays local. - [The TPRM implementation path](https://kaitosec.app/de/knowledge/tprm/path): Third-party risk: 7 chapters put decisions, responsibilities and evidence in a defensible order. - [Third-party risk: start from a defensible draft.](https://kaitosec.app/de/knowledge/tprm/templates): Third-party risk: 6 templates for workshops, registers, audits and reviews. No forms, straight to the file. - [NIS2 scope, measures and duties](https://kaitosec.app/de/nis2): The German NIS2 act has been in force since 6 December 2025. Articles, 49 templates and a checker to work out whether you are in scope and what follows. - [NIS2 for energy utilities: IT, OT and evidence](https://kaitosec.app/de/nis2/energieversorger): Energy utilities implement NIS2 with ISO 27001 or BSI IT-Grundschutz: IT and OT in one model, an integrated BCMS, KRITIS evidence from live operations. - [NIS2 obligations and reporting explained](https://kaitosec.app/de/nis2/knowledge): Ten articles on scope under Section 28 BSIG, the ten measures under Section 30, the reporting cascade and management liability under Section 38. - [Section 28 BSIG: NIS2 sectors and thresholds](https://kaitosec.app/de/nis2/knowledge/betroffenheitspruefung-paragraf-28-bsig-sektoren-schwellenwerte): Which organisations fall under Section 28 BSIG? The 18 NIS2 sectors, size thresholds with AND operator and the consolidation rule for groups. - [BSI Registration under NIS2: Step-by-Step in the BSI Portal](https://kaitosec.app/de/nis2/knowledge/bsi-registrierung-schritt-fuer-schritt): How to register your entity in the BSI portal: MUK sign-in, ELSTER certificate, mandatory fields under Section 33 BSIG and the two-week update deadline. - [The 10 Minimum Measures Under Section 30 BSIG](https://kaitosec.app/de/nis2/knowledge/die-10-mindestmassnahmen-nach-paragraph-30-bsig): All 10 minimum measures under Section 30 BSIG explained: risk analysis, incident management, BCM, supply chain, MFA and the fine risks under Section 65. - [NIS2 Supplier Inventory: Step-by-Step Guide](https://kaitosec.app/de/nis2/knowledge/lieferanteninventar-nis2-schritt-fuer-schritt): Three search routines for complete scope, a classification session with justification lines and an approval format for your NIS2 supplier inventory. - [NIS2 Reporting Cascade: 24h, 72h and Final Report](https://kaitosec.app/de/nis2/knowledge/meldepflichten-nis2-24h-72h-abschlussbericht): What the early warning, full notification and final report under Section 32 BSIG must contain – content requirements for all three reporting stages. - [Check NIS2 Applicability: 5 Steps Under the New BSIG](https://kaitosec.app/de/nis2/knowledge/nis2-betroffenheit-5-schritte): In five steps, determine whether your organisation falls under NIS2: sector, size, exceptions, entity type and the registration deadline under Section 33 BSIG. - [Conducting a NIS2 Gap Assessment: Template and Plan](https://kaitosec.app/de/nis2/knowledge/nis2-gap-assessment-durchfuehren): Step-by-step guide for a NIS2 gap assessment: audit catalogue from § 30 BSIG, assess the current state, prioritise gaps and get the action plan approved. - [NIS2 Security Policies: Minimal Policy Stack](https://kaitosec.app/de/nis2/knowledge/nis2-sicherheitsrichtlinien-policy-stack): How to create an IS-Policy and seven core sub-policies under Section 30 BSIG that hold up in a BSI audit – avoiding the common pitfalls. - [NIS2 and ISO 27001: Overlaps, Gaps, and BSI Evidence](https://kaitosec.app/de/nis2/knowledge/nis2-und-iso-27001): Where ISO 27001:2022 covers NIS2, where the four critical gaps lie, and whether ISO certification counts as BSI evidence. With a full control mapping. - [Section 38 BSIG: Personal Liability of Management under NIS2](https://kaitosec.app/de/nis2/knowledge/paragraf-38-bsig-haftung-geschaeftsleitung): What does Section 38 BSIG mean for managing directors? Internal liability, recourse claims, D&O insurance and the documentation that protects you. - [49 NIS2 templates to download](https://kaitosec.app/de/nis2/templates): Word and Excel starting points for policies, registers, incident forms and supplier reviews, sorted by NIS2 chapter and ready to adapt. ## Compare - [ISMS and GRC tools compared](https://kaitosec.app/de/compare): Thirteen comparisons with the ISMS and GRC tools on a DACH shortlist. Each one names where the other product is the better answer and when it was checked. - [Akarion Alternative | AI Governance & On-Premise](https://kaitosec.app/de/compare/akarion-alternative): Looking for an Akarion alternative? KaitoSec adds ISO 42001, SOC 2 and on-premise deployment to the same ISMS, continuity and data protection scope. - [Drata Alternative | Beyond SOC 2 and ISO 27001](https://kaitosec.app/de/compare/drata-alternative): Looking for a Drata alternative? KaitoSec adds BSI IT-Grundschutz, NIS2 and four management systems on one data model to SOC 2 and ISO 27001 evidence. - [eramba Alternative | Managed Service or Self-Hosted](https://kaitosec.app/de/compare/eramba-alternative): Looking for an eramba alternative? KaitoSec adds BSI IT-Grundschutz and German advisory, which the open-source community edition does not carry. - [HiScout Alternative | Enterprise GRC or Lean Team](https://kaitosec.app/de/compare/hiscout-alternative): Looking for a HiScout alternative? KaitoSec carries the same Grundschutz substance for a lean security team instead of a dedicated ISMS department. - [ISMS.online Alternative | UK Breadth or DACH Depth](https://kaitosec.app/de/compare/isms-online-alternative): Looking for an ISMS.online alternative? KaitoSec carries BSI IT-Grundschutz, TISAX and German supervisory practice instead of eleven generic standards. - [Kertos Alternative | Continuity in the Same System](https://kaitosec.app/de/compare/kertos-alternative): Looking for a Kertos alternative with business continuity? KaitoSec runs BCMS, ISMS, DSMS and AIMS on one data model, not ISO 27001 and GDPR alone. - [Proliance Alternative | Four Systems, One Model](https://kaitosec.app/de/compare/proliance-alternative): Looking for a Proliance alternative? KaitoSec runs ISMS, data protection, continuity and AI governance as four systems on one model, not as consulting. - [QSEC Alternative | Migrating a Classic GRC Suite](https://kaitosec.app/de/compare/qsec-alternative): Looking for a QSEC alternative? Compare the Nexis GRC suite with KaitoSec on frameworks, AI support and pricing before migrating ISMS, BCM and data protection. - [Secfix Alternative | Grundschutz and Continuity](https://kaitosec.app/de/compare/secfix-alternative): Looking for a Secfix alternative? KaitoSec adds BSI IT-Grundschutz, a BCMS and on-premise deployment to ISO 27001, SOC 2, TISAX and NIS2. - [Secjur Alternative | Continuity and Grundschutz Depth](https://kaitosec.app/de/compare/secjur-alternative): Looking for a Secjur alternative? KaitoSec adds business continuity, BSI IT-Grundschutz depth and on-premise deployment to ISO 27001, TISAX and NIS2. - [Sprinto Alternative | Beyond SOC 2 and ISO 27001](https://kaitosec.app/de/compare/sprinto-alternative): Looking for a Sprinto alternative? KaitoSec adds BSI IT-Grundschutz, NIS2 under German law and four systems on one model to SOC 2 and ISO 27001. - [Vanta Alternative | DACH Requirements First](https://kaitosec.app/de/compare/vanta-alternative): Looking for a Vanta alternative? KaitoSec runs BSI IT-Grundschutz, NIS2 and four management systems on one data model, not just cloud evidence. - [verinice Alternative | ISMS after the veo Switch](https://kaitosec.app/de/compare/verinice-alternative): Looking for a verinice alternative? verinice classic ends in 2027. Compare verinice.veo and KaitoSec before the migration decision is made for you. ## Tools - [Free tools for compliance cost and NIS2 scope](https://kaitosec.app/de/tools): Two free tools: compare cost scenarios and structure a first NIS2 scope check. Both results are orientation, not legal advice. - [NIS2 Compliance Checker](https://kaitosec.app/de/tools/nis2-checker): A first structured orientation on potential NIS2 scope and maturity. It does not replace a binding legal classification. - [Compliance ROI Calculator](https://kaitosec.app/de/tools/roi-calculator): Compare your own assumptions for internal time, external guidance and platform costs in consistent scenarios. ## Blog - [Blog on security, continuity and data protection](https://kaitosec.app/de/blog): Articles on ISMS, BCMS, DSMS and AIMS. What supervisory authorities check, what audits ask for, and how four management systems run on one set of data. - [NIS2-Fristen: Was bis wann nachweisbar vorliegen muss](https://kaitosec.app/de/blog/nis2-fristen-nachweise-2026): NIS2 hat mehrere Fristauslöser: Betroffenheit, Kenntnis eines erheblichen Vorfalls, Datenänderungen und besondere Nachweisregeln für kritische Anlagen. - [Was kostet eine ISMS-Software? Preismodelle im Vergleich](https://kaitosec.app/de/blog/isms-software-kosten): Der Lizenzpreis ist nur einer von sechs Kostenblöcken. Dieser Artikel ordnet den DACH-Markt in drei Preisstufen ein und zeigt, was bei Einführung, internem Aufwand, Schulung und Betrieb dazukommt. - [§ 28 BSIG Absatz für Absatz: Betroffenheit und Folgepflichten](https://kaitosec.app/de/blog/28-bsig-absatz-fuer-absatz): § 28 BSIG bestimmt die Einstufung und wichtige Ausnahmen. So prüfen Sie alle acht Absätze und leiten die tatsächlich geltenden NIS2-Pflichten ab. - [NIS2-Gap-Assessment: Ablauf und Vorlage für zehn Arbeitstage](https://kaitosec.app/de/blog/nis2-gap-assessment-zehn-arbeitstage): In zehn Arbeitstagen zu einer belegbaren NIS2-Lückenanalyse: mit Prüfplan, Bewertungsmaßstab, Nachweisvorlage und Entscheidungen für die Geschäftsleitung. - [GSTOOL-Nachfolge 2026: Grundschutz-Software auswählen und den Wechsel vorbereiten](https://kaitosec.app/de/blog/gstool-nachfolge-2026-grundschutz-software): Welche Anforderungen eine GSTOOL-Nachfolge erfüllen sollte: mit Bewertungsmatrix, Testfällen und einem Plan für die Übernahme Ihrer Sicherheitskonzepte. - [Krisenstab alarmieren: Rollen, Kanäle und Eskalationszeiten](https://kaitosec.app/de/blog/krisenstab-alarmieren-rollen-kanaele-eskalationszeiten): Von der ersten Meldung bis zum entscheidungsfähigen Krisenstab: So definieren Sie Alarmierung, Vertretungen, Rückmeldungen und einen überprüfbaren Ablauf. - [Wiederanlaufplan: was der Auditor sehen will, was der Betrieb braucht](https://kaitosec.app/de/blog/wiederanlaufplan-auditor-betrieb): Ein Wiederanlaufplan muss Entscheidungen belegbar und Schritte ausführbar machen. Mit Planstruktur, Abnahmekriterien und einem Beispiel für den Wiederanlauf. - [IT-Grundschutz-Software ablösen: Migrationspfad, Aufwand und Fallstricke](https://kaitosec.app/de/blog/it-grundschutz-software-abloesen-migration): Ein belastbarer Wechselplan für Grundschutz-Bestände: Datenmodell prüfen, Aufwand am Pilot messen, Nachweise erhalten und den Übergang abnehmen. - [Schutzbedarfsfeststellung ohne Tabellenchaos: Vorgehen für 200 Zielobjekte](https://kaitosec.app/de/blog/schutzbedarfsfeststellung-200-zielobjekte): Schutzbedarf nachvollziehbar bewerten: Kategorien definieren, Zielobjekte gruppieren, Abhängigkeiten prüfen und Entscheidungen mit dem Fachbereich freigeben. - [Wie lange darf es stillstehen? RTO, RPO und MTPD mit dem Fachbereich festlegen](https://kaitosec.app/de/blog/rto-rpo-mtpd-mit-fachbereich-festlegen): So legen Fachbereich und IT tragfähige Wiederanlaufziele für RTO, RPO und MTPD fest und erkennen die Lücke zwischen Bedarf und Fähigkeit. - [Ein Control-Set, zwei Audits: IT-Grundschutz und ISO 27001 nachvollziehbar mappen](https://kaitosec.app/de/blog/bsi-grundschutz-iso-27001-mapping-control-set): Gemeinsame Maßnahmen und Nachweise für Grundschutz und ISO 27001 nutzen: mit Mapping-Vorlage, Versionsregeln und einer Prüfung der tatsächlichen Abdeckung. - [Business Impact Analyse in fünf Workshops strukturieren](https://kaitosec.app/de/blog/business-impact-analyse-fuenf-workshops): Ein begrenzter Einstieg in die BIA: fünf Workshops mit klaren Ergebnissen, vorbereiteten Daten und einem nachvollziehbaren Beschluss über die Prioritäten. - [Erpressungsforderung: Wer entscheidet, welche Kriterien?](https://kaitosec.app/de/blog/erpressungsforderung-wer-entscheidet): Wer über eine Erpressungsforderung nach einem Cyberangriff entscheidet, nach welchen Kriterien, und warum die Zahlung selbst gegen Sanktionsrecht verstoßen kann: Geschäftsführerhaftung, Krisenstab-Rollen und die Art.-34-DSGVO-Frist im Überblick. - [Was kostet eine ISO-27001-Zertifizierung im Mittelstand?](https://kaitosec.app/de/blog/iso-27001-zertifizierung-kosten): Die Auditortage sind akkreditierungsgebunden und nicht verhandelbar, der Tagessatz schon. Marktkorridore fuer Audit, Beratung und internen Aufwand im Ueberblick. - [Cyberangriff auf ein kleines Kraftwerk in Großbritannien: vier Tage Stillstand unterhalb der Meldeschwelle](https://kaitosec.app/de/blog/cyberangriff-kraftwerk-grossbritannien-2026): Eine kleine Stromerzeugungsanlage in Großbritannien stand im Juli 2026 nach einem Cyberangriff vier Tage still, öffentlich wurde es erst vier Wochen später. Was belegt ist, was rekonstruiert ist und welche Meldepflichten in Deutschland seit Dezember 2025 gälten. - [KRITIS-Dachgesetz und NIS2: Was gilt für wen?](https://kaitosec.app/de/blog/kritis-dachgesetz-und-nis2): KRITIS-Dachgesetz und NIS2 gelten parallel: physische Resilienz beim BBK, Cybersicherheit beim BSI. Schwellenwerte, Fristen und Bußgelder im Überblick. - [Cyberangriff auf das Landesnetz Berlin: sieben Tage unbemerkt, fünf Tage Datenabfluss](https://kaitosec.app/de/blog/cyberangriff-landesnetz-berlin-2026): Angreifer waren sieben Tage unbemerkt im Berliner Landesnetz. Was belegt ist, wer den Schaden nach dem Wiederanlauf trägt und was andere daraus prüfen können. - [Grundschutz++ ab 2027: Zertifizierbar, aber wie ausgereift?](https://kaitosec.app/de/blog/grundschutz-plus-plus): Grundschutz++ ist ab 1. Januar 2027 zertifizierbar. Die Methodik bricht mit dem alten BSI-Grundschutz, doch die Risikobewertung bleibt offen. - [Resilience Made Easy: Der Weg vom GRC-Aktenschrank zum Agentic Workspace](https://kaitosec.app/de/blog/resilience-made-easy): Warum wir KaitoSec nicht als GRC-Ablage bauen, sondern als Agentic Workspace für kontinuierliche Resilienz. Und was das für die tägliche ISB-Arbeit bedeutet. - [Brauche ich ein ISMS für NIS2? Pflicht oder Option](https://kaitosec.app/de/blog/brauche-ich-ein-isms-fuer-nis2): NIS2 schreibt kein ISMS und keine ISO 27001 zwingend vor. Was das BSI wirklich fordert, welche Strukturen §30 BSIG verlangt und welche Optionen KMU haben. - [NIS2-Meldepflichten: Wann, was und an wen melden?](https://kaitosec.app/de/blog/nis2-meldepflichten-wann-was-an-wen-melden): Dreistufiges NIS2-Meldeverfahren: Frühwarnung (24h), Erstmeldung (72h), Abschlussbericht (1 Monat). Wer meldet was an wen, und welche Bußgelder drohen bei Verstoß? - [Reicht ISO 27001 für NIS2-Compliance aus?](https://kaitosec.app/de/blog/reicht-iso-27001-fuer-nis2-compliance-aus): Nein, sagt das BSI. ISO 27001 ist ein solides Fundament, aber Scope-Freiheit, Risikoakzeptanz und §32/§38-Pflichten bleiben offen. So schließen Sie die Lücken. - [Bin ich von NIS2 betroffen? So prüfen Sie es](https://kaitosec.app/de/blog/bin-ich-von-nis2-betroffen): Ob Ihr Unternehmen unter NIS2 fällt, hängt von Sektorzugehörigkeit und Unternehmensgröße ab. 18 Sektoren, Größenschwellen und Sonderfälle: Schritt für Schritt erklärt. - [NIS2-Berater oder selbst umsetzen? Ein Kostenvergleich](https://kaitosec.app/de/blog/nis2-berater-oder-selbst-umsetzen-kostenvergleich): Ein NIS2-Beratungsprojekt kostet KMU 50.000–150.000 EUR. Welche Teile der Umsetzung Sie selbst übernehmen können, wo sich ein Berater lohnt und wie der Hybridansatz funktioniert, mit konkreten Zahlen. - [NIS2 in Deutschland: Was müssen Unternehmen 2026 wissen?](https://kaitosec.app/de/blog/nis2-in-deutschland-was-muessen-unternehmen-2026-wissen): Das NIS2UmsuCG ist seit Dezember 2025 in Kraft. Rund 29.500 Unternehmen in Deutschland müssen jetzt Registrierungs-, Melde- und Risikomanagementpflichten erfüllen. Pflichten, Fristen, Bußgelder und Umsetzung, der komplette Überblick. - [NIS2 und ISMS: Was Ihr bestehendes System nicht abdeckt](https://kaitosec.app/de/blog/nis2-isms-integration): ISMS-Tools verwalten Kontrollen und Audits, aber sie liefern keinen NIS2-Umsetzungspfad. Warum ISMS-Anbieter Beratung dazuverkaufen, wo der rote Faden fehlt und wie KaitoSec die Lücke schließt. - [NIS2-Bußgelder: Welche Strafen drohen bei Verstößen?](https://kaitosec.app/de/blog/nis2-bussgelder-strafen-verstoesse): NIS2-Verstöße können Unternehmen bis zu 10 Mio. EUR oder 2 % des weltweiten Jahresumsatzes kosten. Welche Bußgelder bei welchen Verstößen drohen, wie die Geschäftsführerhaftung greift und was zwei Praxisszenarien zeigen. ## Company - [About KaitoSec | The Team Behind the Resilience Platform](https://kaitosec.app/de/about): KaitoSec runs ISMS, BCMS, DSMS, and AIMS in one data model: the workspace for continuous resilience, built and hosted in Germany. - [Contact KaitoSec about adoption and migration](https://kaitosec.app/de/contact): Clarify questions about adoption, migration, operation or professional fit directly with the team that builds KaitoSec. - [Demo: discuss your ISMS, BCMS or DSMS case](https://kaitosec.app/de/demo): 30 minutes on one real workflow from your ISMS, BCMS, DSMS or AIMS: we clarify where time is lost today and whether KaitoSec fits your case. ## Legal - [Site notice and company information](https://kaitosec.app/de/imprint): Site notice, company details, registered office, management and contact information for KaitoSec GmbH. - [Privacy policy and personal data handling](https://kaitosec.app/de/privacy): How KaitoSec collects, uses, stores and protects your personal data, and which rights you can exercise at any time. - [Terms and conditions for the KaitoSec platform](https://kaitosec.app/de/terms): General terms and conditions of KaitoSec GmbH for the ISMS platform and consulting services.