Good compliance support is the difference between software that tells you what is missing and a person who tells you what to do about it. Most compliance platforms stop at the first. Kertos combines its platform with a dedicated, certified point of contact who translates the frameworks for your specific product. In this series you get to know our specialists and pick up practical tips for your day-to-day work.
Each episode puts one expert at the centre, answering real questions about the frameworks they work in every day: practical answers on ISO 27001, SOC 2, NIS2 and the EU AI Act, from the experts who bring our customers through audits.
What is "Ask a Compliance Expert"?
Ask a Compliance Expert is a video and article series from Kertos where our specialists explain how compliance frameworks work in practice. Each episode takes one expert and a set of questions and turns it into something you can watch, read and act on.
Honesty over polish. Compliance is a dry subject, and most content about it is either sales material or dense legal text. We wanted a third option: real specialists who speak plainly about where teams fail and how to avoid it. You can find the frameworks we cover in the Kertos frameworks overview.
Why compliance software needs expert support
Software alone cannot interpret a standard. That is the short answer, and the reason expert support sits at the centre of how we work. A platform can collect evidence, track controls and flag gaps. It cannot decide how a vaguely worded requirement applies to your specific setup.
Standards are deliberately broad so they apply to every kind of company. The price of that breadth is ambiguity. A clause about “appropriate technical measures” means little until someone maps it to the tools you already use. Bodies like ENISA publish guidance on this, but general guidance still has to be translated into your controls, by a person who has done it before.
That translation is the real work. Our specialists turn what ISO, SOC 2, NIS2 or the EU AI Act requires into concrete steps, tailored to your resources. They then help you defend those decisions in the audit. Passing an audit well is an art in itself:
- The software keeps you audit-ready.
- The expert gets you through the audit.
Skip that support and the failure mode is predictable: teams misread a requirement, implement the wrong thing, and only notice during the audit itself, when there is barely time to fix it. Recovering a failed or strained audit often costs months of rework and damages the relationship with the auditor.
There is a business reason too. Done right, compliance is not about avoiding fines, it is about winning business. Customers increasingly do not buy from vendors who cannot prove their security. This pattern shows up across many of our success stories.
How expert support works at Kertos
Every Kertos customer gets a dedicated point of contact, not an anonymous support queue. You know who your specialist is, and they know your setup. Here is how it works in practice:
- During onboarding you are matched with a specialist who knows your frameworks and your industry.
- You get regular working sessions to work through requirements in order, instead of a document dump.
- Between sessions your point of contact is one message away, for every question the software cannot answer.
- When an audit is coming up, they help you prepare evidence and defend your decisions.
The models flex to your needs. Some customers want pure delivery, others want guidance. What stays constant is the one-to-one relationship.
The support scales with your goals. Many companies start with one framework and add a second later, because a customer asks for it. Because your Kertos contact already knows your controls, reusing evidence across frameworks like ISO 27001 and SOC 2 becomes far easier than starting over each time. Our ISO 27001 support is built around exactly this continuity.
The series
The video series starts with our first expert, Kutluhan Abut, whose expertise we have split into short videos. The article versions will follow, and future episodes will feature more Kertos specialists.
These four videos feature Kutluhan Abut, a compliance expert at Kertos with a background in law and data protection.
What the series covers
The series spans the frameworks Kertos customers deal with most, from information security certifications through European regulation to AI governance.
Standards change quickly, AI regulation especially. The official text of the EU AI Act is in the EU's legal database, and the AI management standard ISO 42001 is described on the official ISO site. Part of our specialists' job is to track these changes so your team does not have to read every regulation line by line.
FAQs
Do I get a dedicated compliance point of contact with Kertos?
Yes. Every customer gets a dedicated specialist who knows your frameworks and your setup, rather than a rotating support pool. That continuity is central to how expert support works here.
Is Kertos software or consulting?
Both, by design. The Kertos platform automates evidence collection, control tracking and documentation. The specialist interprets the requirements, tailors them to your product, and helps you defend your decisions in the audit.
Which frameworks does Kertos cover?
ISO 27001, SOC 2, GDPR, NIS2, DORA, TISAX, the EU AI Act and ISO 42001.
How do I submit a question for a future episode?
Send it through your Kertos point of contact or through the website. The best episodes come from questions real teams are wrestling with.
Watch, or start a conversation
Ask a Compliance Expert exists because the hardest parts of compliance are the judgment calls. And judgment comes from people.
If you want that kind of support for your own compliance program, not just a software platform but a person who knows the frameworks, book a no-obligation Kertos demo and meet the team. New episodes appear on this page.






