If you are looking for Kertos alternatives, you are probably at a specific moment: a customer is asking for an ISO 27001 certificate, legal wants the GDPR documentation, or a NIS2 registration deadline is approaching, and nobody on the team can absorb that work on top of their own. So this guide does not compare feature lists. It compares the four vendor models you are actually choosing between, the seven criteria that separate them, and the costs that appear in no proposal.
Every vendor statement here comes from that vendor's own website, as of August 12, 2026. Where something is not published there, the text says so.
Key takeaways
- Companies searching for Kertos alternatives are in practice comparing four categories: US automation platforms, European platforms with an in-house expert team, traditional consultancies, and do-it-yourself in spreadsheets.
- Framework counts are not a quality signal. Vanta advertises "35+", Drata "30+", and Scrut "60+" on their own sites. Most companies pursuing ISO 27001 alongside GDPR and a SOC 2 report work with three to five.
- Data location claims differ sharply in precision: Vanta states an EU data center in Frankfurt, Scrut names the Frankfurt region in its DPA for AI processing, and Drata states no EU region on its site.
- NIS2 is not one deadline. Germany has had it in force since December 6, 2025, while France has not transposed it at all; on July 8, 2026 the European Commission referred France, Ireland, Spain, and the Netherlands to the Court of Justice over the delay.
- Kertos states on its own ISO 27001 framework page that it automates around 60 percent of compliance workflows, cuts time to audit by 80 percent, and costs 50 percent less than the traditional route, with a 100 percent audit success rate.
When a Kertos alternative genuinely makes sense
Three situations call for a different vendor, and they belong at the start of a comparison rather than the end.
The first is the US public sector. If your commercial target is called FedRAMP, CMMC, or NIST 800-171, you need a platform that carries those programs in its catalog and whose auditor network is established there. Vanta and Drata both list FedRAMP and CMMC 2.0 on their framework pages.
The second is deliberately going without guidance. If you already employ an experienced security lead who has built an information security management system twice, you need a tool, not a team. At a service-heavy vendor you would be paying for capacity you never draw on.
The third is group governance. If a group-wide GRC system is already running, wired into risk reporting, internal audit, and vendor management, a second system rarely solves the problem.
There are also sector constraints that eliminate candidates before any comparison starts. If you host personal health data in France, HDS certification is a legal requirement rather than a preference; in Germany, public sector and regulated buyers frequently ask for a BSI C5 attestation. Ask those questions in the first call, because they shorten the list faster than any comparison table.
In every other case the decision is not driven by the vendor list, but by who actually implements the 93 controls in Annex A of ISO 27001. How those controls are structured, and how to select the ones that apply to you, is covered in our ISO 27001 certification guide.
One point that gets missed regularly: no software vendor certifies you. The certificate is issued by an accredited certification body, such as TÜV Süd, DEKRA, DQS, LRQA, or Bureau Veritas, which are in turn overseen by national accreditation bodies like DAkkS, UKAS, or COFRAC. The platform prepares, the auditor decides. Vendors who blur that line in their marketing deserve a closer look.
Four vendor categories you are actually choosing between
The market looks crowded. It resolves into four models with very different cost profiles.
A common misconception belongs here: a bigger catalog does not mean broader coverage. It means more choice. A company that needs ISO 27001, GDPR, and a SOC 2 report works with three frameworks. Whether the vendor carries 30 or 60 more changes nothing about your workload. What matters is how cleanly the three you need are mapped to each other.
Seven criteria that separate compliance platforms
These seven points separate vendors in practice. Everything else is equipment.
1. The frameworks you will actually need in the next 24 months
Write down what your customers and regulators concretely demand. For a European SaaS company that is typically ISO 27001, GDPR, and a SOC 2 report for US customers. Add automotive customers and a TISAX assessment joins the list. Fall under NIS2 and the risk management measures in Article 21 apply on top.
On the data protection side, check whether the vendor covers only documentation or also day-to-day operation: records of processing, data subject requests, deletion concepts, and processor contracts. The GDPR compliance overview sets out those building blocks.
2. Where your data sits, and what that means legally
Hosting location is a selection criterion, but not the one it is often taken for. Hosting in Frankfurt does not make a processing operation GDPR compliant, and processing in the US is not automatically unlawful. What governs it is Articles 44 and following of the GDPR, the legal regime the vendor is subject to, and the question of who inside the group and at which sub-processors has access. The full text of Chapter V is on EUR-Lex.
Vanta puts it this way in its own help pages: its US servers are GDPR compliant from a legal perspective, and its DPA, which implements the standard contractual clauses, provides the basis for the transfer. That analysis is defensible. It simply moves the assessment one level up. If you adopt it, you need a documented transfer impact assessment, and somebody has to write it.
Three questions worth asking every vendor during selection. Which country holds the production database, and which holds the backups? Which sub-processors are on the current register, and how are you notified of changes? What access does vendor support have to your data, and is that access logged?
Why vendor choice is therefore a compliance decision rather than a procurement one is covered in our article on EU data sovereignty.
3. Who collects the evidence
The effort in a management system does not come from writing policies. It comes from repeatedly proving they are followed. So test the integrations against your real stack: identity provider, cloud accounts, device management, ticketing, HR system. Kertos states more than 100 integrations for its platform and around 60 percent automation of workflows. The remaining 40 percent are decisions a human has to make, such as risk acceptance or scope definition.
4. Who owns the audit outcome
This is the sharpest dividing line in the market. Pure software vendors give you a system and an auditor from a partner directory; responsibility for the outcome stays with you. Vendors with an in-house team take on part of it. Scrut describes this on its own homepage as "Dedicated InfoSec Managers to help draft policies, interpret frameworks, and prep for audits." Vanta and Drata rely at this point on partner programs made up of consultancies, auditors, and managed service providers.
How to spot dubious vendors and worthless certificates is covered, with concrete warning signs, in our article on ISO 27001 vendor red flags.
How different the two models feel day to day, one Kertos customer describes on G2 like this:
A practical test during selection: ask for a call with a reference customer of your size, before you sign. Vendors who arrange that quickly usually have satisfied customers within reach.
5. The language of the platform, the policies, and the people
Check these three layers separately, because they come apart across vendors. Drata states that its app supports English, Spanish, French, and German, while noting that policies, controls, and risks are not currently available for translation. Vanta names German, French, and Spanish policy templates and training, while also writing in its help pages that the central platform itself is not translated. Scrut publishes no statement about German or French language support.
For an audit in front of a German or French certification body this is not cosmetic. The auditor reads your policies.
The third layer, the language of the people you talk to, is the one most often skipped in selection and the fastest to matter in the project:
6. How controls are mapped across frameworks
Once you need more than one framework, mapping quality drives the workload. A clean mapping means a control you collect once counts simultaneously for ISO 27001, for GDPR, and for the SOC 2 report. A poor one means you upload the same evidence three times. Which of the 93 Annex A controls carry the most weight in that mapping is set out in our guide to the ISO 27001 controls.
How a single control set can be stretched across those three frameworks is shown in ISO 27001, GDPR, and SOC 2 on one control set.
7. The pricing model, and the items that are not in it
The mistake most teams make when comparing: they line up license prices. The license is rarely the largest item. The largest item is internal time, and it appears in no proposal. So ask every vendor how many person-days your team should plan for in year one, and where that number comes from.
Check the pricing basis too. Some vendors price by headcount, some by number of frameworks, some by connected systems. For a company growing from 40 to 120 people, those three models produce very different three-year totals. Ask for the pricing tiers that match your growth plan, not just the entry price.
Vanta, Drata, and Scrut: what the vendors state themselves
The table below reproduces only what the three vendors publish on their own websites, as of August 12, 2026. It deliberately contains no assessment and no claim about what a vendor cannot do.
Two observations. First, all four vendors cover ISO 27001, GDPR, SOC 2, and NIS2. The difference is not the catalog, it is the service model and the data processing. Second, the data location statements vary in precision. If that point matters to your customers or your regulator, get it confirmed contractually rather than relying on a marketing page.
What that difference feels like for a European team, one customer put on G2:
NIS2 is not one deadline, and that changes the vendor question
This criterion deserves its own section, because it produces sales promises that rest on nothing.
NIS2 is a directive, so it only becomes enforceable through national transposition, and member states are at very different stages. Germany transposed it with the amended BSIG, in force since December 6, 2025. France has not transposed it at all: the relevant bill was adopted by the Sénat in first reading on March 12, 2025, went to the Assemblée nationale as bill number 1112, and has had no plenary vote since its special committee reported on September 10, 2025. On July 8, 2026 the European Commission referred France, Ireland, Spain, and the Netherlands to the Court of Justice over the delay, asking for a lump sum and daily penalty payments.
The practical consequence for a vendor comparison: nobody can sell you compliance with a national NIS2 regime that does not yet exist in your country. What a vendor can credibly offer is a control baseline that maps onto the Article 21 risk management measures, which is largely what an ISO 27001 management system already delivers. Our NIS2 directive guide sets out those obligations as the directive frames them.
If your company falls in scope, the personal duties of the management body are the part that tends to be underestimated, and they arrive with transposition rather than after a grace period. The NIS2 obligations for managing directors summarizes them.
What the traditional route costs, and where the saving comes from
The most honest benchmark is not the license price but the path you would otherwise have taken. For a first ISO 27001 certification through a traditional consultancy, that path looks like this. The figures below come from the German-speaking market and serve as an order of magnitude.
Internal time is not included. That is exactly where the difference between vendors opens up, and exactly where it is hardest to evidence. Kertos states on its own ISO 27001 framework page that it cuts time to audit by 80 percent and costs 50 percent less than the traditional route. For comparison, a first certification usually takes 3 to 12 months in the market.
Audit fees are, incidentally, the one item no vendor can automate away. They depend on the number of people in scope, not on project speed. The audit time table in ISO/IEC 27006 provides for 8.5 audit days for an initial certification covering 26 to 45 people, and 2.8 days for the surveillance audit; the certification body may in practice deviate by up to 30 percent.
A worked example: a 45-person SaaS company before its first certification
Take a 45-person SaaS company that needs ISO 27001 because two enterprise deals depend on it, and that has to comply with the GDPR regardless.
All 45 people are in scope. The audit time table therefore gives 8.5 days for the initial certification, plus 2.8 days for each surveillance audit in years 1 and 2. The certificate is valid for three years, after which recertification is due. Down the traditional consulting route, the company lands at EUR 23,000 to 49,000 in year one, excluding its own working time.
The internal effort depends on who works through the 93 Annex A controls. If the company frees up one person at 50 percent, it loses half a full-time equivalent for the duration of the project. That line appears in none of the proposals it collects.
How that duration can be shortened, and which shortcuts do not exist, is covered in getting ISO 27001 certified quickly.
Switching vendors: five steps that matter
If your evaluation of Kertos alternatives ends in an actual move, the switch rarely fails because of the software and often because of the evidence chain. A company that moves mid-certification-cycle has to show the auditor at the surveillance audit that controls kept running throughout the migration. That is doable, but it is work, and it belongs in the decision.
A third common misconception surfaces exactly here: many teams treat certification as a project with an end date. It is a state. The certificate is valid for three years, with surveillance audits in years 1 and 2 and recertification in year 3. A vendor who sells you the path to the first certificate and then goes quiet solves a third of your problem.
- Check the cycle. Do not put the switch in the eight weeks before a surveillance audit. The best moment is right after a passed audit.
- Export the evidence before you give notice. Policies, risk register, asset inventory, training records, audit reports, and corrective action plans. Get it in writing which format the outgoing vendor exports in, and how long they retain your data after the contract ends.
- Check the mapping. Have the new vendor show how your existing controls map onto the 93 Annex A controls and, where relevant, onto the Article 21 NIS2 risk management measures.
- Connect the integrations first. Identity provider and cloud accounts are the source of most automatically collected evidence. Until they are connected, the new system looks empty, and that unsettles the team.
- Tell your certification body. A tool change is not notifiable, but your auditor plans the engagement based on what they saw last year. A short heads-up saves questions during the audit.
Budget four to eight weeks of parallel running for a clean migration. Skipping that phase produces exactly the gap that gets written up as a nonconformity at the surveillance audit.
That a switch works when it is planned, one customer who came from the other direction describes like this:
Where Kertos fits, and where it does not
Kertos is a European compliance platform that combines automation with an in-house team of certified experts. The platform covers risk and asset management, data discovery, data subject requests, and audit preparation, connects to more than 100 systems, and supports ISO 27001, ISO 27701, ISO 42001, GDPR, SOC 2, TISAX, NIS2, and the EU AI Act. Hosting is in Germany.
The offering comes in three tiers that do not differ in features but in how much work stays with you. In the entry tier your team works with the platform; in the higher tiers Kertos experts take on a growing share of the implementation. That is the real comparison point against pure software vendors, and it is also why a license-price comparison misleads.
Kertos is not the right choice if you need FedRAMP or CMMC, if you already run a group-wide GRC system, or if you specifically want a self-service tool without guidance. In those cases we say so in the first call.
On the review platform G2, Kertos holds 4.8 out of 5. What customers highlight most often is the combination of platform and support, and the verdict on OMR Reviews runs along the same lines:
How those projects actually ran is set out in our success stories. If you want to model the comparison for your own company, book a demo: we go through your frameworks, your stack, and your timeline, and we will tell you if a different category fits you better.
Further comparisons by framework
Depending on which proof is due first, the selection criteria differ considerably. For tool selection around ISO 27001 specifically, there is a separate buyer's guide to ISO 27001 compliance tools.
If a SOC 2 report is what US customers are asking for, our article on the benefits of the SOC 2 report sets out what that proof delivers and what it does not.
For cloud providers selling into the German market, the BSI C5 attestation is often the more relevant proof, because public sector and regulated buyers ask for it. In the automotive supply chain, the TISAX assessment decides who wins the contract, on a separate label system that an ISO 27001 certificate does not replace.
If you build or deploy AI systems, the EU AI Act adds a further layer, with high-risk obligations deferred to December 2027 and August 2028.
Frequently asked questions
What are the best Kertos alternatives?
It depends on what you are replacing. For US programs like FedRAMP or CMMC, Vanta and Drata carry larger catalogs; for a pure self-service tool without guidance, the US platforms are also the obvious pick. If you want European hosting and local-language support through the audit, the field narrows considerably.
How much does compliance software cost?
License prices are mostly not published and depend on company size, number of frameworks, and the share of service included. The more reliable comparison figure is total effort: in the German-speaking market, the traditional consulting route to ISO 27001 runs EUR 23,000 to 49,000 in year one for a company under 50 people, excluding internal working time.
Is Vanta or Kertos better?
The answer depends on your requirements. Vanta advertises 35+ frameworks, an EU data center in Frankfurt, and a partner network for implementation. Kertos runs a smaller framework catalog, hosting in Germany, and an in-house team of certified experts who take on the implementation. If you have implementation capacity in house, the first model wins; if you do not, the second.
Does NIS2 apply in my country yet?
That depends on the member state. Germany has had NIS2 in force since December 6, 2025 through the amended BSIG. France has not transposed it, and the European Commission referred France, Ireland, Spain, and the Netherlands to the Court of Justice on July 8, 2026 over the delay. Check your own national status before accepting any vendor's compliance promise.
Can I switch compliance software without losing my certification?
Yes. The certificate belongs to your company, not to your software vendor. Do not schedule the switch in the weeks immediately before a surveillance audit, and make sure evidence from the old system is exported and mapped in the new one before you switch anything off.





