Which risk management software fits your compliance requirements?
Key takeaways
- GRC software, compliance software and risk management software describe overlapping product groups. What decides your choice is which kind of risk you are managing: enterprise risk across the whole business, or information security and privacy risk that you have to evidence to an assessor.
- Kertos keeps the risk register, assets and controls in one system and produces the audit evidence from them.
- Four tool groups compete for the job: specialised ISMS platforms, compliance automation platforms, open-source tools and general GRC or enterprise risk systems. They differ less in the risk register itself than in what happens after the assessment.
- Several regulations demand risk management at once: NIS2 through Article 21(2) of the Directive, ISO 27001 through clauses 6.1.2 and 6.1.3, the GDPR through Articles 32 and 35, and the EU AI Act through Article 9. One register serves all four; separate registers produce contradictory states.
- Under NIS2, risk management is the substance of the legal duty rather than one chapter among many, and Article 20 places approval, oversight and liability on the management body itself.
Which risk management software fits depends on the kind of risk you manage and the regulations you have to evidence. For companies whose risks arise from information security and data protection, four tool groups are in scope. The difference between providers is rarely the risk register itself, because every one of them offers a register with likelihood and impact. It lies in whether the register is connected to your controls, your assets and your evidence, whether the Statement of Applicability comes out of it, and whether anyone performs the assessment with you. This page sorts out the terms and the tool categories, sets out the selection criteria, and compares what providers offer using their own published descriptions. Last updated 11 September 2026.
What is the difference between GRC, compliance and risk management software?
The three terms are used almost interchangeably in the market but describe different scopes. That is why companies regularly trial a system built for an entirely different class of risk.
| Term | What it usually means | Typical buyer |
|---|---|---|
| GRC software | Governance, risk and compliance in one system, historically from the large-enterprise world, covering every category of corporate risk | Large enterprises with internal audit and a dedicated risk function |
| Compliance software | Meeting and evidencing specific regulations, with controls, policies and evidence at the centre | Companies with certification or reporting obligations |
| Risk management software | The risk register itself: identification, assessment, treatment and review | Both groups, usually as a component of the wider solution |
The distinction halves your search. If your risks come from information security and data protection and an auditor will eventually ask for evidence, you do not need an enterprise GRC suite; you need a platform where risk, control and evidence hang together. If instead you want financial, process and quality risks in a single register, the reverse is true.
Which regulations require risk management?
Almost every regulation European companies have to evidence contains a risk management requirement. They are worded differently but ask for the same thing in substance: a traceable assessment, assigned measures and proof that both are maintained.
| Regulation or standard | Reference | What it requires |
|---|---|---|
| NIS2 | Article 21(2), Directive (EU) 2022/2555 | Ten cybersecurity risk-management measures, including risk analysis policies and policies to assess their effectiveness |
| ISO 27001 | Clauses 6.1.2 and 6.1.3 | Risk assessment, risk treatment, a Statement of Applicability and sign-off of residual risks |
| GDPR | Articles 32 and 35 | Measures appropriate to the risk; a data protection impact assessment where processing is likely to result in high risk |
| EU AI Act | Article 9 | A risk management system across the lifecycle of high-risk AI systems |
| TISAX | VDA ISA | Documented risk management as part of the assessment |
| SOC 2 | Trust Services Criteria | A documented risk assessment underpinning the controls |
| C5 | BSI C5 | Risk management as a criterion within the attestation |
That is where the real selection question comes from. A single maintained risk register can serve all of these, because the requirements overlap in substance. Separate registers per regulation create duplicate maintenance and contradictory states, and that is exactly what surfaces in an audit. So the question is not whether a tool keeps a register, but whether it can map several regulations onto the same set of risks.
What does ISO 27001 require in detail?
The standard does not prescribe a tool, it prescribes outcomes. Placing clauses 6.1.2, 6.1.3, 8.2 and 8.3 of the international standard for information security management systems side by side gives a requirements list you can measure any tool against.
| Requirement | Clause | What the tool has to do |
|---|---|---|
| Define risk acceptance and assessment criteria | 6.1.2 a) | Hold the scale and the acceptance threshold as configuration, not hard-coded |
| Identify risks and name risk owners | 6.1.2 c) | A named person per risk, not just a department |
| Analyse and evaluate risks | 6.1.2 d), e) | Inherent and residual risk held separately, with the reasoning visible |
| Determine controls and compare against Annex A | 6.1.3 b), c) | Risk-to-control linkage, and the comparison itself has to be documented |
| Produce a Statement of Applicability | 6.1.3 d) | Generated from the data, including justifications for exclusions |
| Risk treatment plan and residual risk sign-off | 6.1.3 e), f) | Sign-off by the risk owners, recorded in an auditable way |
| Repeat the assessment at planned intervals | 8.2 | Cadence, reminders and history per risk |
| Evidence that the plan was implemented | 8.3 | Evidence attached to the risk or the control, not filed separately |
Two of these separate providers reliably. The first is the Statement of Applicability: either it is generated from the assessed risks and their mapped controls, or it stays a hand-maintained document and eventually drifts out of step. The second is residual risk sign-off. The standard requires it explicitly from the risk owners; a tool with no sign-off step leaves a gap that an auditor will find.
What does NIS2 require of risk management?
Under NIS2, risk management is not one chapter among many, it is the substance of the obligation. Article 21 of Directive (EU) 2022/2555 is titled "cybersecurity risk-management measures", and unlike a certification, compliance is not optional. Article 21(2) lists ten measures. Two of them drive tool selection: point (a) requires policies on risk analysis and information system security, which is what a risk register delivers, and point (f) requires policies and procedures to assess the effectiveness of those measures. That effectiveness assessment is a separate duty alongside the measure itself. Operating a control is not enough; you have to be able to show that you checked whether it works, when you did so and what came out of it.
Article 20 adds the layer above. Management bodies have to approve the risk-management measures, oversee their implementation and can be held liable for failures, and they have to undergo training themselves. In practice that means a report has to exist that a board can actually read and sign.
One caveat that matters outside Germany: transposition is not uniform. Germany transposed NIS2 through the BSIG as amended, in force since 6 December 2025 with no transitional period, where section 30(2) mirrors Article 21(2) measure for measure and section 38 carries the management duties. France had not completed transposition as of September 2026, so French entities face the Directive's obligations on a different timetable. Check the status in every country you operate in before assuming a single deadline. How to approach the wider programme is covered in our guide to preparing for NIS2.
What types of risk management software are there?
The market splits into four groups, and the groups address different buyers. Choosing the wrong group means buying either a tool built for a different class of risk or a system whose rollout takes longer than the certification itself.
| Category | Suits | Strength | Limitation |
|---|---|---|---|
| Specialised ISMS platforms | Companies running an ISMS and nothing else | Depth on policies, risks and standard coverage | Data protection and further regulations often not covered |
| Compliance automation platforms | Companies running several regulations in parallel | Evidence collected automatically from the source systems | Less depth on non-technical enterprise risk |
| Open-source tools | Teams with their own IT capacity, often with a BSI IT-Grundschutz context | No licence cost, full control of the data in your own environment | Operation, updates and support sit with you |
| General GRC and enterprise risk systems | Large enterprises with process, quality and financial risk | Breadth across every risk category in the business | Usually too heavy to configure and roll out for an ISMS |
For mid-sized technology companies the choice almost always falls between the first two. The question underneath it is simple: does this stop at ISO 27001, or are the GDPR, NIS2, TISAX, SOC 2 or the EU AI Act coming too? If it stops at one standard, an ISMS platform is enough. If more are coming, a platform that satisfies a control once and reuses the evidence across regulations pays for itself. We compare the ISMS systems themselves in our overview of ISMS software.
What should you look for when choosing?
- Does the Statement of Applicability come out of the system? If you still maintain it in a spreadsheet, the tool has not taken on the most expensive part of the work.
- Are risks linked to assets and controls? A register without those links is a list, and a list goes stale between audits.
- Is there an effectiveness review with a date and a result? That is Article 21(2)(f) of NIS2 and clause 9 of ISO 27001 in one requirement.
- Where does the data sit, and who operates it? A risk register is a written description of your weaknesses. It is the most sensitive set of records in the entire ISMS.
- Who performs the assessment? Software records and calculates; rating likelihood and impact remains a judgement. The question is whether you hold that expertise in-house or buy it in.
- Does the register survive the audit? Assessors ask for point-in-time views, for change history and for risk owner sign-off.
How do the providers differ in functionality?
Kertos publishes this page. Everything below about other providers comes from that provider's own risk product page and nowhere else, checked on 11 September 2026. Where a provider's page does not state something, the cell says so rather than saying "no".
| Provider | Risk register | Scoring | Control linkage | Pre-built risk library | Certified experts included |
|---|---|---|---|---|---|
| Kertos | Yes, with automated capture and assessment | Inherent and residual risk | Yes, risks linked directly to the corresponding controls | Not stated on the product page | Yes |
| Vanta | Yes, "track all of your risks in a single place" | Inherent and residual risk, with an owner per risk | Yes, continuous monitoring of the associated controls and tests | Not stated on the product page | Not stated on the product page |
| Drata | Yes, "centralized risk register" | Custom risks and custom scoring formulas | Yes, linking relevant controls to the risk | Not stated on the product page | Not stated on the product page |
| Scrut | Yes, with custom fields and bulk import | Four selectable calculation methods | Yes, by framework or individually | Yes, pre-built risk library | Not stated on the product page |
| Secureframe | Yes, with point-in-time snapshots | AI-assisted, inherent and residual risk | Yes, controls linkable to known risks | Yes, including NIST risk scenarios | Not stated on the product page |
| Sprinto | Yes, "a live, connected risk register" | Continuous rescoring as status changes | Yes, automatic mapping to controls and systems | Not stated on the product page | Not stated on the product page |
Where the others are stronger, and this belongs in any honest overview: Vanta offers point-in-time snapshots of the register built explicitly for sharing with auditors. Drata allows custom scoring formulas, which is worth a great deal if you already have an established methodology. Scrut names four selectable calculation methods and, by its own account, over 70 supported frameworks. Secureframe ships a risk library with NIST scenarios that shortens the start. Sprinto rescores risks continuously as soon as a check fails.
One finding applies to all five equally and matters most to European buyers: none of the five product pages names a European data location, and none names expert support as part of the scope. All five describe a register you keep yourself. That is not a criticism of the software, it is a statement about the delivery model. If you are going to run the assessment yourself and hold the methodology in-house, that is the cheaper route. If not, you are buying an empty register.
What the difference looks like in practice is what one customer names as the best thing about Kertos in a G2 review: "The Personal support when going through the certification process". Asked what problem it solves, the same review answers: "It helps you structure the certification process and not get lost". (Verified User in Computer Software, Small-Business, G2, 3 September 2026, 4.5 out of 5.)
Who is Kertos the right risk management software for?
Kertos captures and assesses risks automatically, links them directly to the corresponding controls, and brings assets, risks and evidence together in one system. The platform covers ISO 27001, ISO 27701, ISO 42001, the GDPR, NIS2, the EU AI Act, SOC 2, TISAX and C5 together, so a control is satisfied once and the evidence is reused across regulations. Over 100 integrations keep the underlying asset and system inventory current. Certified Kertos experts do the specialist work alongside your team, including external CISO and data protection officer mandates. The feature detail sits on the page for automated risk management.
That fits mid-sized technology companies carrying more than one standard at a time who do not want to build an ISMS function of their own. AskUI reached ISO 27001 certification in 8 to 10 weeks without external consultants. The audit pass rate is 100 percent, manual compliance effort falls by around 80 percent, and costs run up to 60 percent below traditional consulting.
One customer describes the way of working like this: "Kertos helps us carry out the ISO 27001 certification in an organised and structured way. It defines clear tasks and offers AI-supported suggestions tailored to our company structure." (Martin S., Agentic AI Engineer, Small-Business, G2, 4 September 2026, 5 out of 5, translated from German.)
When is Kertos not the right choice?
Four cases argue against Kertos.
- You manage enterprise risk beyond information security. If you want financial, process and quality risk in the same system, you belong in the fourth category above rather than on a compliance platform.
- Your endpoints run mostly on Linux. "Linux devices are not supported for the device scanner", one customer notes as his only criticism (Verified User in Computer Software, Small-Business, G2, 3 September 2026). With a Linux-heavy engineering team, manual work remains at that point.
- You also want to cover quality management. "It would be helpful to have a framework for implementing ISO 9001", writes one managing director in his review (Alexander W., Geschäftsführer, Small-Business, G2, 4 September 2026). ISO 9001 is not in the covered framework set; anyone wanting quality and information security management in one system ends up with the GRC systems from the first table on this page.
- You expect clarity on day one without guidance. A customer in the health sector puts it this way: "At first the platform is a bit overwhelming and the benefits do not come through; in places the odd feature is still missing." (Verified User in Health, Wellness and Fitness, Small-Business, G2, 22 August 2026, 4.5 out of 5, translated from German.) Setup is designed around working with the Kertos team. If you want pure self-service, a lighter tool serves you better.
One honest note on the AI support as well: it produces suggestions and answers questions, but it does not replace the judgement involved in rating likelihood and impact. That decision stays with people, and in the audit it is people who will question it.
Frequently asked questions
Is a spreadsheet enough as a risk register for ISO 27001?
Formally yes, in practice rarely. The standard prescribes documented information, not a tool. A spreadsheet usually fails in three places: the link between risk, control and evidence, the change history an audit asks for, and risk owner sign-off under clause 6.1.3 f). For a company with few assets and a single standard, a spreadsheet can carry the first cycle.
What is the difference between inherent and residual risk?
Inherent risk is the rating before the controls take effect, residual risk the rating afterwards. ISO 27001 requires both views: clause 6.1.2 for the assessment and 6.1.3 for treatment including acceptance of what remains. A tool holding only one value per risk cannot demonstrate a control's effect arithmetically.
Who has to sign off a risk?
The risk owners. Clause 6.1.3 f) of ISO 27001 requires their approval of the risk treatment plan and their acceptance of the residual risks. Under NIS2 the layer above joins in: Article 20 requires management bodies to approve the risk-management measures and oversee their implementation.
Do you need separate risk management software for NIS2?
No, a second system is unnecessary and usually harmful. The ten measures in Article 21(2) of NIS2 overlap substantially with an ISMS run to ISO 27001. One maintained risk register carries the standard's risk assessment and the basis for the measures. Separate systems create duplicate maintenance and contradictory states.
What does risk management software cost?
Most providers in this market publish no price and route you to a conversation, Kertos included. What you can plan reliably are the surrounding items: internal effort for the initial assessment and its upkeep, the certification body's audit fees and, where needed, external specialist support. Our overview of ISO 27001 certification costs breaks down the audit side.
Does the provider's location matter?
A risk register describes a company's weaknesses in plain language, which makes it the most sensitive set of records in the ISMS. For companies that want those records held in the EU, the provider's location and where the data is operated become selection criteria in their own right. Which European providers work as an alternative to the large US platforms is covered in our overview of EU alternatives to Vanta and Drata.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


