Which ISMS Software Should You Choose?
Key takeaways
- The term "ISMS software" covers two separate markets: GRC and IT-Grundschutz tools built for public sector bodies, large corporate groups, and operators of critical infrastructure, and compliance automation built for organizations working toward ISO 27001 certification. Choose the wrong group and every product comparison that follows is the wrong comparison.
- Three questions settle the shortlist: does the solution have to run on-premises, is BSI IT-Grundschutz your leading standard, and is there someone in-house who owns the ISMS professionally?
- A first ISO 27001 certification costs EUR 23,000 to 49,000 in year one for organizations under 50 employees, and EUR 37,000 to 80,000 for 50 to 200 employees. The software license is rarely the largest item in that total.
- Published vendor prices are not comparable, because almost none of them state whether preparation, implementation, and certification body fees are included. As a rule they are not.
Place your own case first, then the vendors. If you need BSI IT-Grundschutz, an on-premises deployment, or a structure built for public authorities, municipalities, and subsidiaries inside a group, your shortlist belongs in the GRC group. If you need ISO 27001 certification, automated evidence, and integrations into your own systems, it belongs in the automation group. Both trade under the same search term, solve different problems, and cannot sensibly be scored against each other.
What are the two kinds of ISMS software?
| Characteristic | GRC and IT-Grundschutz tools | Compliance automation |
|---|---|---|
| Core job | Structured documentation of an ISMS that already exists | Building, evidencing, and maintaining the ISMS through to the audit |
| Leading standard | BSI IT-Grundschutz, ISO 27001 | ISO 27001, extended with NIS2, TISAX, SOC 2 |
| Deployment | On-premises or cloud, sometimes open source | SaaS |
| Typical customers | Public authorities, municipalities, corporate groups, critical infrastructure | Start-ups, scale-ups, mid-sized SaaS companies |
| Assumption about the buyer | An information security function is already in place | Usable without prior ISMS experience |
Which vendor belongs to which group?
| Vendor | Headquarters | Group | Standards named on their own site (selection) | Strength as they describe it |
|---|---|---|---|---|
| ISMS.online | Brighton, United Kingdom | Automation | ISO 27001, ISO 9001, ISO 27701, ISO 42001, ISO 22301, NIS2, SOC 2, GDPR | Very broad standard coverage and prebuilt content, "up to 81% of the work is already done for you" |
| Kertos | Munich, Germany | Automation | ISO 27001, ISO 27701, ISO 42001, GDPR, NIS2, EU AI Act, SOC 2, TISAX, C5 | Agentic platform KAIA plus certified experts, including external CISO and DPO mandates |
| Orbiq | Munich, Germany | Automation | ISO 27001, NIS2, focus on EU data residency | Discloses in its own comparison that it ranks itself first, and states the weighting it used |
| otris isms | Dortmund, Germany | GRC | ISO 27001, BSI IT-Grundschutz, NIS2, TISAX, GDPR | Built for corporate groups, public enterprises, municipalities, and authorities |
| Secfix | Berlin and Munich, Germany | Automation | ISO 27001, SOC 2, TISAX, GDPR, NIS2, ISO 9001, ISO 27701, ISO 42001 | European cloud infrastructure, documented customer projects certified in four weeks |
| Vanta | United States | Automation | SOC 2, ISO 27001, ISO 42001, GDPR, NIS2, HIPAA, EU AI Act | Largest verified integration surface, "automatically pull data from 400+ tools" |
| verinice | SerNet GmbH, Germany | GRC | BSI IT-Grundschutz, ISO 2700x, VDA ISA and TISAX, GDPR, NIS2, business continuity | "The only sovereign ISMS tool", fully open source, on-premises optional |
Every claim above comes from the vendor's own public website, checked on August 18, 2026. The table is sorted alphabetically and does not rank market position. For closer head-to-head comparisons see compliance management software compared and NIS2 software compared.
How do users rate these vendors on G2?
Ratings describe reputation, not verified product capability, and the sample sizes here differ by two orders of magnitude. Read the table together with the review count rather than by stars alone.
| Vendor | G2 rating | Reviews |
|---|---|---|
| ISMS.online | 4.5 out of 5 | 292 |
| Kertos | 4.8 out of 5 | 48 |
| Orbiq | no G2 profile | 0 |
| otris isms | no G2 profile | 0 |
| Secfix | 4.8 out of 5 | 108 |
| Vanta | 4.6 out of 5 | 2,707 |
| verinice | no G2 profile | 0 |
As of August 18, 2026, sorted alphabetically. The gap matters more than the ranking: none of the three vendors in the GRC group maintains a G2 profile at all. G2 maps the SaaS market, not the German GRC market, so a buyer who shortlists from review platforms never sees half the landscape. On OMR Reviews, which covers the DACH market, Kertos stands at 4.9 out of 5 from 21 reviews and carries the "Leader GRC Tools Q3/26" badge.
Three customer comments about Kertos from G2:
| Quote | Rating | Date |
|---|---|---|
| "Kertos makes building an Information Security Management System incredibly smooth and intuitive." (Konrad E.) | 4.5 out of 5 | December 1, 2025 |
| "For us, Kertos is not just a compliance tool, but a real sparring partner: the privacy expert works through complex issues with us." (Alexander S.) | 5 out of 5 | July 23, 2026 |
| "Supports our processes and is easy to use. It has been amazing while we've been getting ISO27001 certified." (Maximilian R.) | 5 out of 5 | August 2, 2026 |
What does ISMS software actually cost?
The license price is one cost block among several. The table below normalizes the total cost of a first ISO 27001 certification and shows which items published vendor prices leave out.
| Cost block | Under 50 employees | 50 to 200 employees | Included in vendor prices? |
|---|---|---|---|
| Software license | Published entry prices start at around EUR 20 per month for assistant-only tools. Most vendors publish no price at all. | Yes, this is the quoted price | |
| Gap analysis and preparation | EUR 5,000 to 15,000 | EUR 10,000 to 25,000 | No |
| Implementation | EUR 10,000 to 20,000 | EUR 15,000 to 35,000 | Partly |
| Certification body fees | EUR 8,000 to 14,000 | EUR 12,000 to 20,000 | Never |
| Total, year one | EUR 23,000 to 49,000 | EUR 37,000 to 80,000 | No |
| Surveillance audit, year two onward | EUR 4,000 to 7,000 | EUR 6,000 to 10,000 | No |
Market benchmarks for consultant-supported projects in Germany, as of August 2026. These are not Kertos prices. No vendor reduces certification body fees. What is reducible is preparation and implementation. Full breakdown under ISO 27001 certification costs.
Who runs the ISMS, the software or your team?
This question decides project outcomes more often than feature coverage does. GRC tools assume a qualified person owns the risk analysis, the selection of controls, and audit preparation. Automation platforms reduce that requirement, but they only remove it when the vendor supplies qualified specialists alongside the software. So settle before you buy whether you will fill an internal role, purchase consulting days, or award a mandate. That choice moves the total cost more than any licensing decision.
When is Kertos not the right choice?
Kertos is not the right choice if the software has to run on-premises, because Kertos operates exclusively as SaaS on European infrastructure. Nor is it right if BSI IT-Grundschutz is your leading standard, or if you are a public authority, a municipality, or an operator of critical infrastructure that needs an open source, sovereignly operated solution. In those cases the GRC group is the factually correct answer. Kertos also does not cover PCI DSS or NIST CSF. And if you already have an experienced information security function in-house and want a documentation tool alone, you would be paying Kertos for expert capacity you never call on.
Where does Kertos fit?
Kertos sits in the automation group and combines the agentic platform KAIA with certified experts who take on external CISO and DPO mandates. The model is aimed at organizations without an ISMS function of their own: AskUI reached ISO 27001 certification in 8 to 10 weeks without external consultants. Customers report around 80 percent less manual compliance effort and up to 60 percent lower cost than traditional consulting, alongside a 100 percent audit pass rate and 98 percent customer satisfaction. Kertos is built in Germany and runs on European infrastructure.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


