Which risk management software fits your compliance requirements?

Key takeaways

  • GRC software, compliance software and risk management software describe overlapping product groups. What decides your choice is which kind of risk you are managing: enterprise risk across the whole business, or information security and privacy risk that you have to evidence to an assessor.
  • Kertos keeps the risk register, assets and controls in one system and produces the audit evidence from them.
  • Four tool groups compete for the job: specialised ISMS platforms, compliance automation platforms, open-source tools and general GRC or enterprise risk systems. They differ less in the risk register itself than in what happens after the assessment.
  • Several regulations demand risk management at once: NIS2 through Article 21(2) of the Directive, ISO 27001 through clauses 6.1.2 and 6.1.3, the GDPR through Articles 32 and 35, and the EU AI Act through Article 9. One register serves all four; separate registers produce contradictory states.
  • Under NIS2, risk management is the substance of the legal duty rather than one chapter among many, and Article 20 places approval, oversight and liability on the management body itself.

Which risk management software fits depends on the kind of risk you manage and the regulations you have to evidence. For companies whose risks arise from information security and data protection, four tool groups are in scope. The difference between providers is rarely the risk register itself, because every one of them offers a register with likelihood and impact. It lies in whether the register is connected to your controls, your assets and your evidence, whether the Statement of Applicability comes out of it, and whether anyone performs the assessment with you. This page sorts out the terms and the tool categories, sets out the selection criteria, and compares what providers offer using their own published descriptions. Last updated 11 September 2026.

What is the difference between GRC, compliance and risk management software?

The three terms are used almost interchangeably in the market but describe different scopes. That is why companies regularly trial a system built for an entirely different class of risk.

TermWhat it usually meansTypical buyer
GRC softwareGovernance, risk and compliance in one system, historically from the large-enterprise world, covering every category of corporate riskLarge enterprises with internal audit and a dedicated risk function
Compliance softwareMeeting and evidencing specific regulations, with controls, policies and evidence at the centreCompanies with certification or reporting obligations
Risk management softwareThe risk register itself: identification, assessment, treatment and reviewBoth groups, usually as a component of the wider solution

The distinction halves your search. If your risks come from information security and data protection and an auditor will eventually ask for evidence, you do not need an enterprise GRC suite; you need a platform where risk, control and evidence hang together. If instead you want financial, process and quality risks in a single register, the reverse is true.

Which regulations require risk management?

Almost every regulation European companies have to evidence contains a risk management requirement. They are worded differently but ask for the same thing in substance: a traceable assessment, assigned measures and proof that both are maintained.

Regulation or standardReferenceWhat it requires
NIS2Article 21(2), Directive (EU) 2022/2555Ten cybersecurity risk-management measures, including risk analysis policies and policies to assess their effectiveness
ISO 27001Clauses 6.1.2 and 6.1.3Risk assessment, risk treatment, a Statement of Applicability and sign-off of residual risks
GDPRArticles 32 and 35Measures appropriate to the risk; a data protection impact assessment where processing is likely to result in high risk
EU AI ActArticle 9A risk management system across the lifecycle of high-risk AI systems
TISAXVDA ISADocumented risk management as part of the assessment
SOC 2Trust Services CriteriaA documented risk assessment underpinning the controls
C5BSI C5Risk management as a criterion within the attestation

That is where the real selection question comes from. A single maintained risk register can serve all of these, because the requirements overlap in substance. Separate registers per regulation create duplicate maintenance and contradictory states, and that is exactly what surfaces in an audit. So the question is not whether a tool keeps a register, but whether it can map several regulations onto the same set of risks.

What does ISO 27001 require in detail?

The standard does not prescribe a tool, it prescribes outcomes. Placing clauses 6.1.2, 6.1.3, 8.2 and 8.3 of the international standard for information security management systems side by side gives a requirements list you can measure any tool against.

RequirementClauseWhat the tool has to do
Define risk acceptance and assessment criteria6.1.2 a)Hold the scale and the acceptance threshold as configuration, not hard-coded
Identify risks and name risk owners6.1.2 c)A named person per risk, not just a department
Analyse and evaluate risks6.1.2 d), e)Inherent and residual risk held separately, with the reasoning visible
Determine controls and compare against Annex A6.1.3 b), c)Risk-to-control linkage, and the comparison itself has to be documented
Produce a Statement of Applicability6.1.3 d)Generated from the data, including justifications for exclusions
Risk treatment plan and residual risk sign-off6.1.3 e), f)Sign-off by the risk owners, recorded in an auditable way
Repeat the assessment at planned intervals8.2Cadence, reminders and history per risk
Evidence that the plan was implemented8.3Evidence attached to the risk or the control, not filed separately

Two of these separate providers reliably. The first is the Statement of Applicability: either it is generated from the assessed risks and their mapped controls, or it stays a hand-maintained document and eventually drifts out of step. The second is residual risk sign-off. The standard requires it explicitly from the risk owners; a tool with no sign-off step leaves a gap that an auditor will find.

What does NIS2 require of risk management?

Under NIS2, risk management is not one chapter among many, it is the substance of the obligation. Article 21 of Directive (EU) 2022/2555 is titled "cybersecurity risk-management measures", and unlike a certification, compliance is not optional. Article 21(2) lists ten measures. Two of them drive tool selection: point (a) requires policies on risk analysis and information system security, which is what a risk register delivers, and point (f) requires policies and procedures to assess the effectiveness of those measures. That effectiveness assessment is a separate duty alongside the measure itself. Operating a control is not enough; you have to be able to show that you checked whether it works, when you did so and what came out of it.

Article 20 adds the layer above. Management bodies have to approve the risk-management measures, oversee their implementation and can be held liable for failures, and they have to undergo training themselves. In practice that means a report has to exist that a board can actually read and sign.

One caveat that matters outside Germany: transposition is not uniform. Germany transposed NIS2 through the BSIG as amended, in force since 6 December 2025 with no transitional period, where section 30(2) mirrors Article 21(2) measure for measure and section 38 carries the management duties. France had not completed transposition as of September 2026, so French entities face the Directive's obligations on a different timetable. Check the status in every country you operate in before assuming a single deadline. How to approach the wider programme is covered in our guide to preparing for NIS2.

What types of risk management software are there?

The market splits into four groups, and the groups address different buyers. Choosing the wrong group means buying either a tool built for a different class of risk or a system whose rollout takes longer than the certification itself.

CategorySuitsStrengthLimitation
Specialised ISMS platformsCompanies running an ISMS and nothing elseDepth on policies, risks and standard coverageData protection and further regulations often not covered
Compliance automation platformsCompanies running several regulations in parallelEvidence collected automatically from the source systemsLess depth on non-technical enterprise risk
Open-source toolsTeams with their own IT capacity, often with a BSI IT-Grundschutz contextNo licence cost, full control of the data in your own environmentOperation, updates and support sit with you
General GRC and enterprise risk systemsLarge enterprises with process, quality and financial riskBreadth across every risk category in the businessUsually too heavy to configure and roll out for an ISMS

For mid-sized technology companies the choice almost always falls between the first two. The question underneath it is simple: does this stop at ISO 27001, or are the GDPR, NIS2, TISAX, SOC 2 or the EU AI Act coming too? If it stops at one standard, an ISMS platform is enough. If more are coming, a platform that satisfies a control once and reuses the evidence across regulations pays for itself. We compare the ISMS systems themselves in our overview of ISMS software.

What should you look for when choosing?

  • Does the Statement of Applicability come out of the system? If you still maintain it in a spreadsheet, the tool has not taken on the most expensive part of the work.
  • Are risks linked to assets and controls? A register without those links is a list, and a list goes stale between audits.
  • Is there an effectiveness review with a date and a result? That is Article 21(2)(f) of NIS2 and clause 9 of ISO 27001 in one requirement.
  • Where does the data sit, and who operates it? A risk register is a written description of your weaknesses. It is the most sensitive set of records in the entire ISMS.
  • Who performs the assessment? Software records and calculates; rating likelihood and impact remains a judgement. The question is whether you hold that expertise in-house or buy it in.
  • Does the register survive the audit? Assessors ask for point-in-time views, for change history and for risk owner sign-off.

How do the providers differ in functionality?

Kertos publishes this page. Everything below about other providers comes from that provider's own risk product page and nowhere else, checked on 11 September 2026. Where a provider's page does not state something, the cell says so rather than saying "no".

ProviderRisk registerScoringControl linkagePre-built risk libraryCertified experts included
KertosYes, with automated capture and assessmentInherent and residual riskYes, risks linked directly to the corresponding controlsNot stated on the product pageYes
VantaYes, "track all of your risks in a single place"Inherent and residual risk, with an owner per riskYes, continuous monitoring of the associated controls and testsNot stated on the product pageNot stated on the product page
DrataYes, "centralized risk register"Custom risks and custom scoring formulasYes, linking relevant controls to the riskNot stated on the product pageNot stated on the product page
ScrutYes, with custom fields and bulk importFour selectable calculation methodsYes, by framework or individuallyYes, pre-built risk libraryNot stated on the product page
SecureframeYes, with point-in-time snapshotsAI-assisted, inherent and residual riskYes, controls linkable to known risksYes, including NIST risk scenariosNot stated on the product page
SprintoYes, "a live, connected risk register"Continuous rescoring as status changesYes, automatic mapping to controls and systemsNot stated on the product pageNot stated on the product page

Where the others are stronger, and this belongs in any honest overview: Vanta offers point-in-time snapshots of the register built explicitly for sharing with auditors. Drata allows custom scoring formulas, which is worth a great deal if you already have an established methodology. Scrut names four selectable calculation methods and, by its own account, over 70 supported frameworks. Secureframe ships a risk library with NIST scenarios that shortens the start. Sprinto rescores risks continuously as soon as a check fails.

One finding applies to all five equally and matters most to European buyers: none of the five product pages names a European data location, and none names expert support as part of the scope. All five describe a register you keep yourself. That is not a criticism of the software, it is a statement about the delivery model. If you are going to run the assessment yourself and hold the methodology in-house, that is the cheaper route. If not, you are buying an empty register.

What the difference looks like in practice is what one customer names as the best thing about Kertos in a G2 review: "The Personal support when going through the certification process". Asked what problem it solves, the same review answers: "It helps you structure the certification process and not get lost". (Verified User in Computer Software, Small-Business, G2, 3 September 2026, 4.5 out of 5.)

Who is Kertos the right risk management software for?

Kertos captures and assesses risks automatically, links them directly to the corresponding controls, and brings assets, risks and evidence together in one system. The platform covers ISO 27001, ISO 27701, ISO 42001, the GDPR, NIS2, the EU AI Act, SOC 2, TISAX and C5 together, so a control is satisfied once and the evidence is reused across regulations. Over 100 integrations keep the underlying asset and system inventory current. Certified Kertos experts do the specialist work alongside your team, including external CISO and data protection officer mandates. The feature detail sits on the page for automated risk management.

That fits mid-sized technology companies carrying more than one standard at a time who do not want to build an ISMS function of their own. AskUI reached ISO 27001 certification in 8 to 10 weeks without external consultants. The audit pass rate is 100 percent, manual compliance effort falls by around 80 percent, and costs run up to 60 percent below traditional consulting.

One customer describes the way of working like this: "Kertos helps us carry out the ISO 27001 certification in an organised and structured way. It defines clear tasks and offers AI-supported suggestions tailored to our company structure." (Martin S., Agentic AI Engineer, Small-Business, G2, 4 September 2026, 5 out of 5, translated from German.)

When is Kertos not the right choice?

Four cases argue against Kertos.

  • You manage enterprise risk beyond information security. If you want financial, process and quality risk in the same system, you belong in the fourth category above rather than on a compliance platform.
  • Your endpoints run mostly on Linux. "Linux devices are not supported for the device scanner", one customer notes as his only criticism (Verified User in Computer Software, Small-Business, G2, 3 September 2026). With a Linux-heavy engineering team, manual work remains at that point.
  • You also want to cover quality management. "It would be helpful to have a framework for implementing ISO 9001", writes one managing director in his review (Alexander W., Geschäftsführer, Small-Business, G2, 4 September 2026). ISO 9001 is not in the covered framework set; anyone wanting quality and information security management in one system ends up with the GRC systems from the first table on this page.
  • You expect clarity on day one without guidance. A customer in the health sector puts it this way: "At first the platform is a bit overwhelming and the benefits do not come through; in places the odd feature is still missing." (Verified User in Health, Wellness and Fitness, Small-Business, G2, 22 August 2026, 4.5 out of 5, translated from German.) Setup is designed around working with the Kertos team. If you want pure self-service, a lighter tool serves you better.

One honest note on the AI support as well: it produces suggestions and answers questions, but it does not replace the judgement involved in rating likelihood and impact. That decision stays with people, and in the audit it is people who will question it.

Frequently asked questions

Is a spreadsheet enough as a risk register for ISO 27001?

Formally yes, in practice rarely. The standard prescribes documented information, not a tool. A spreadsheet usually fails in three places: the link between risk, control and evidence, the change history an audit asks for, and risk owner sign-off under clause 6.1.3 f). For a company with few assets and a single standard, a spreadsheet can carry the first cycle.

What is the difference between inherent and residual risk?

Inherent risk is the rating before the controls take effect, residual risk the rating afterwards. ISO 27001 requires both views: clause 6.1.2 for the assessment and 6.1.3 for treatment including acceptance of what remains. A tool holding only one value per risk cannot demonstrate a control's effect arithmetically.

Who has to sign off a risk?

The risk owners. Clause 6.1.3 f) of ISO 27001 requires their approval of the risk treatment plan and their acceptance of the residual risks. Under NIS2 the layer above joins in: Article 20 requires management bodies to approve the risk-management measures and oversee their implementation.

Do you need separate risk management software for NIS2?

No, a second system is unnecessary and usually harmful. The ten measures in Article 21(2) of NIS2 overlap substantially with an ISMS run to ISO 27001. One maintained risk register carries the standard's risk assessment and the basis for the measures. Separate systems create duplicate maintenance and contradictory states.

What does risk management software cost?

Most providers in this market publish no price and route you to a conversation, Kertos included. What you can plan reliably are the surrounding items: internal effort for the initial assessment and its upkeep, the certification body's audit fees and, where needed, external specialist support. Our overview of ISO 27001 certification costs breaks down the audit side.

Does the provider's location matter?

A risk register describes a company's weaknesses in plain language, which makes it the most sensitive set of records in the ISMS. For companies that want those records held in the EU, the provider's location and where the data is operated become selection criteria in their own right. Which European providers work as an alternative to the large US platforms is covered in our overview of EU alternatives to Vanta and Drata.

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check