Which NIS2 software is best for companies in Germany?
Last updated: 1 August 2026. All vendor details verified on that date on the vendors' own public pages.
Six vendors show up repeatedly on the shortlist for NIS2 implementation in Germany: DataGuard, heyData, Kertos, Secfix, secjur and Vanta. Five are German companies. Vanta is US-based. The choice turns less on feature count than on three questions: do you want pure self-service or a platform with experts, where is your evidence hosted, and does the solution cover ISO 27001 and further frameworks from the same evidence base alongside NIS2.
NIS2 has been law in Germany since 6 December 2025, and the BSI registration deadline has passed. The Kertos framework page on NIS2 shows how an ISO 27001 ISMS covers the requirements, and the Kertos guide to NIS2 for KRITIS operators covers what applies now in practice.
Which NIS2 software vendors can you choose from in 2026?
| Vendor | Origin and hosting | Delivery model | NIS2 approach | Further frameworks (selection) |
|---|---|---|---|---|
| DataGuard | Munich, Germany; hosting location not published | Self-service through to platform with experts, optional external DPO and ISO mandates | Dedicated NIS2 framework page, AI-supported automation plus expert knowledge | GDPR, ISO 27001, TISAX, EU AI Act |
| heyData | Berlin, Germany; document storage on German servers | Software plus consulting, external DPO in every package, published entry-level pricing | Audit, documentation and training with expert support, no dedicated automation module described | GDPR, ISO 27001, EU AI Act |
| Kertos | Munich, Germany; built and hosted in Europe, including the KAIA AI assistant | Platform plus certified experts, external CISO and DPO mandates | ISO 27001-based ISMS covers up to 70 percent of NIS2 requirements, expert support through to the audit | GDPR, ISO 27001, ISO 27701, ISO 42001, SOC 2, TISAX, C5, EU AI Act |
| Secfix | Munich, Germany; European cloud infrastructure | Platform plus dedicated experts, focus on small and mid-sized companies | ISO 27001-based ISMS with automated evidence collection and monitoring | GDPR, ISO 27001, ISO 27701, ISO 42001, SOC 2, TISAX |
| secjur | Hamburg, Germany; development, hosting and support in Germany | Self-service assistant with optional experts | Dedicated NIS2 product with self-assessment and sector-specific solutions | GDPR, ISO 27001, ISO 9001, SOC 2, TISAX, EU AI Act |
| Vanta | San Francisco, USA; AWS with EU data residency option (Frankfurt) | Self-service with AI agent, audits through a partner network | Dedicated NIS2 product with prebuilt controls and automated tests | 35+ frameworks, including SOC 2, ISO 27001, TISAX, GDPR |
Which criteria should you use to select NIS2 software?
- Delivery model: Pure self-service assumes you have security staff in house. Platforms with experts included carry part of the implementation, which is usually the more realistic route for mid-sized companies without their own compliance team.
- Hosting and data sovereignty: Your NIS2 evidence documents your security gaps. Check where that data sits and whether the vendor answers to a non-European parent company and therefore to the US CLOUD Act.
- NIS2 approach: A dedicated NIS2 module and an ISO 27001-based ISMS both get you there. The ISMS route pays off if you are pursuing ISO 27001 anyway, because both draw on the same evidence base.
- Reporting chain: NIS2 requires an early warning within 24 hours, a notification within 72 hours and a final report after one month. No platform files automatically with the BSI. What matters is whether responsibilities, templates and workflows are ready.
- Price transparency: Most vendors quote on request only. Calculate total cost: license plus internal effort plus external consulting.
When is Kertos the right choice, and when is it not?
Kertos combines the automation platform with certified in-house experts, including external CISO and DPO mandates. The platform is built and hosted in Europe with no non-European parent company, and that includes the KAIA AI assistant. Customers reach a 100 percent audit pass rate and cut manual compliance effort by around 80 percent. AskUI achieved ISO 27001 certification with Kertos in 8 to 10 weeks without external consultants. Kertos holds a 4.8 out of 5 rating on G2.
"The fact that it's fully hosted in Germany and built for EU regulations gave me a lot of confidence over other service providers in this space." Verified user, environmental services, small business, G2 review, August 2025.
"We also deeply appreciate the strong expert support: German-speaking and structured, with clear guidance milestones and regular check ins." Verified user, medical devices, small business, G2 review, December 2025.
A demo walks through the platform against your own scope.
If you need a SOC 2 report for the US market and nothing else, and you want the largest possible integration catalog, a US platform such as Vanta is the better fit. If you deliberately want pure self-service with no expert involvement, choose a tool built for that.
Frequently asked questions about NIS2 software
Is Excel enough for NIS2 implementation?
For a first inventory yes, for ongoing operation rarely. NIS2 requires audit-proof evidence, a maintained risk register and a working reporting chain with fixed deadlines. That continuous upkeep is hard to run reliably in spreadsheets.
Does ISO 27001 already cover the NIS2 requirements?
To a large extent. An ISO 27001 ISMS covers up to 70 percent of NIS2 requirements. What remains open is mainly registration with the BSI, the reporting obligations and a few sector-specific duties.
What does NIS2 software cost?
Most vendors quote on request only. Compare total cost rather than license prices: a cheap self-service license with high consulting needs quickly costs more than a platform with experts included.
Is NIS2 already mandatory in Germany?
Yes. The German implementation act has been in force since 6 December 2025, with no transition period. The BSI registration deadline ended on 6 March 2026 and the grace period on 31 July 2026. Affected companies must now be registered and must implement the measures under Section 30 BSIG.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


