Which NIS2 software is best for companies in Germany?

Nine platforms support a TISAX® assessment: Kopexa, DataGuard, Kertos, secjur, Secfix, fuentis, verinice, Drata, and Vanta. Most suppliers need TISAX® alongside ISO 27001 and SOC 2 rather than alone; an automation platform with a shared control set fits, such as Kertos, DataGuard, secjur, or Secfix. If your scope includes prototype protection, only Kopexa documents it per label. For documentation alone, a German GRC tool is enough.

Kertos publishes this page and is one of the vendors compared. Every statement about another vendor comes only from that vendor's own public website, checked on 5 September 2026.

Key takeaways

  • TISAX® is not a certification. It is an assessment that ends in a label, shared with your customers through the ENX portal, and it is valid for three years.
  • The VDA ISA has three criteria catalogues: information security, prototype protection, and data protection. Only the first is based on ISO 27001, according to ENX.
  • On 1 January 2027 the basis changes to VDA ISA2027. Assessments ordered today are still run against ISA 6.0.3, published on 25 April 2024.
  • Of nine vendors checked, only Kopexa documents prototype protection as a product feature. Eight publish nothing on it, Kertos included.

Which vendors support a TISAX assessment?

The table lists every vendor that states TISAX® support on its own website. It is sorted by vendor group, most TISAX-specific first, alphabetically within each group.

Vendor Group Headquarters Prototype protection as a product feature Assessment levels on the product page Price on own website Experts included
Kopexa Automotive specialist Kiel, Germany yes, documented per label and level AL1, AL2, AL3 EUR 249 and EUR 599 per month per space optional partner onboarding
DataGuard Automation with experts Munich, Germany not published Level 1 to 3 on request yes, part of the offering
Kertos Automation with experts Munich, Germany not published not published not published yes, certified experts plus external CISO and DPO mandates
secjur Automation with experts Hamburg, Germany not published AL2 and AL3 on request yes, on request
Secfix Automation with experts Munich, Germany not published not published published for the GDPR offering only yes, in-house TISAX team
fuentis German ISMS and GRC tool Potsdam, Germany not published not published EUR 0, EUR 379, and EUR 979 per month yes, consulting and CISO-as-a-Service
verinice German ISMS and GRC tool Göttingen, Germany not published not published on request support, maintenance, and hosting
Drata International platform San Francisco, USA not published not on the product page on request not published
Vanta International platform San Francisco, USA not published AL1, AL2, AL3 on request through partner network

Based only on the vendors' own public websites, checked on 5 September 2026. "Not published" means the vendor states nothing about it on its own website; it does not mean the capability is missing. Statements that appear only in a blog post and not on a product or framework page are not counted here as a product feature.

How did we compare them?

For each vendor we read only its own website: product page, framework list, pricing page, and legal notice. Review sites, market studies, and other vendors' comparison pages were deliberately excluded, because they often reproduce details late or in shortened form.

The criteria follow what actually decides a TISAX® project: coverage of prototype protection as well as information security, whether the assessment levels are named, whether pricing can be checked, and whether people come with the software. For the facts about TISAX® itself the source is the ENX Association, not a vendor.

One note on language, because it indicates how reliable a source is: several vendor pages refer to a "TISAX certification", which does not exist. A vendor that does not keep assessment and label straight on its own product page has usually not mapped the criteria catalogues carefully either.

What can software do for a TISAX assessment, and what can it not do?

Software handles the evidence work: it collects evidence from your systems automatically, keeps it current, maps it to the requirements of the VDA ISA, and documents effectiveness across a period. That is the part that is most expensive by hand, because evidence has to be current and not merely present.

Software does not perform the assessment. An audit provider approved by the ENX Association does that. No vendor on this page can issue you a label, and none should claim otherwise.

What does an existing ISO 27001 certificate do for TISAX?

This is the commercially most important question on the page, and it is usually answered too optimistically.

VDA ISA criteria catalogue Relationship to ISO 27001 Source
Information security ENX describes the ISA as "an information security requirements catalogue based on key aspects of the international standard ISO/IEC 27001" ENX Association
Prototype protection Separate catalogue. Annex A of ISO 27001 contains no control for protecting prototype vehicles, prototype parts, or test events ENX Association
Data protection Separate catalogue covering requirements for personal data ENX Association
Crediting an existing ISO 27001 certificate not published ENX publishes no rule on this
Normative reference from 1 January 2027 ISA2027 references ISO/IEC 27001:2022, among others ENX Association, 1 July 2026

Checked on enx.com, 5 September 2026.

One figure circulates in the market, and it comes from a vendor rather than from ENX. Kopexa states on its own website that with an existing ISO 27001 certification "approximately 60-70% of TISAX requirements" are already covered. The ENX Association publishes no such ratio and no control-by-control mapping. Treat it as a vendor claim rather than a rule. If you are starting from scratch, the ISO 27001 certification process is the more sensible entry point, because the information security half of both procedures has the same origin.

Which assessment level applies to your company?

The level drives effort, duration, and price more than any software decision does. It follows the protection needs of the information your customer expects you to handle.

Level Protection needs Form of assessment
AL1 normal Self-assessment; the auditor confirms that it exists
AL2 high Plausibility check of the self-assessment, with evidence review and an interview by web conference
AL3 very high Comprehensive verification on site, including document review, interviews, and observation

Source: TISAX Participant Handbook, ENX Association, checked 5 September 2026.

Customers rarely accept AL1. The most expensive mistake at this stage is an oversized scope: implementing controls beyond what your customer requires costs real effort and earns no additional label.

Can a supplier outside Germany obtain a TISAX label?

Yes, and this is worth stating plainly because TISAX® is often mistaken for a German-only procedure. It originates in the German automotive industry, but nothing about participation is restricted to German companies or to the German language.

The ENX Association publishes the TISAX® documentation in English, including the Participant Handbook and the VDA ISA catalogue itself. Assessments are performed by audit providers approved by ENX rather than by ENX, and the public directory of approved providers can be filtered by country. On 5 September 2026 that directory listed 17 approved audit providers, several of which operate internationally.

What your location does not change is the requirement itself. TISAX® is contractual rather than statutory, so it reaches you through your customer rather than a regulator, and it travels down the supply chain as each tier passes it to its own suppliers.

Which VDA ISA version applies, and what changes on 1 January 2027?

Two versions currently apply side by side, and most vendor pages name only one of them or none at all.

  • VDA ISA 6.0.3, published on 25 April 2024, is the basis for assessments ordered today.
  • VDA ISA2027 was published on 1 July 2026. In ENX's own words, "ISA2027 will therefore apply to all TISAX Assessments ordered from January 1st, 2027 onwards." The three-year validity of labels is unchanged.

In practice: if your assessment falls in the first quarter of 2027, confirm which catalogue it will be run against before you place the order. A vendor that cannot show you the catalogue by version is handing that work back to you.

What does participating in TISAX cost?

Two cost blocks need separating. The ENX Association's registration fees are published; the audit provider's fee is not, because you negotiate it with the provider.

Item Amount Note
Assessment-Based Charge EUR 405 per location one-off, with volume discounts from five locations
Participation-Based Charge EUR 5,000 per year unlimited scopes and locations; waived for members of the ENX Association
Audit provider fee not published set by the approved audit provider, not by ENX

Source: TISAX Participation Price List, ENX Association, document dated 19 August 2020, retrieved 5 September 2026. Check whether a newer price list has since replaced it before you budget.

Does one platform cover TISAX, ISO 27001, and SOC 2 together?

Yes, and for most suppliers that is the actual reason to buy a platform. TISAX® on its own rarely justifies the purchase; the case works once the same piece of evidence serves several procedures.

The mechanism is control mapping: a control is implemented once and evidenced once, and that evidence is mapped to the requirements of several catalogues. Vanta describes this on its own TISAX page as reusing evidence from ISO 27001, NIS 2, and SOC 2. Kertos, DataGuard, secjur, Secfix, fuentis, and Kopexa also run TISAX® alongside further standards.

The limit is prototype protection and the data protection catalogue. Neither has anything in ISO 27001 that could be reused. If you are assuming a multi-framework tool brings those along, ask about them specifically. For choosing an ISMS tool with no automotive dimension, our ISMS software comparison is the better page, and for the American attestation report, the page on SOC 2 preparation software.

The vendors in detail

Kopexa: best for suppliers whose scope includes prototype protection

  • What it is: A GRC platform from Kopexa GmbH in Kiel, aimed at the automotive industry.
  • Best for: Suppliers with an AL3 scope who need to document prototype protection in a structured way.
  • Standards covered, per its own website: TISAX, ISO 27001, NIS2, GDPR, ISO 9001, SOC 2, BSI Grundschutz, and others.
  • Where it is strongest: The only vendor in this comparison that documents prototype protection per label and per assessment level. Prices are published at EUR 249 and EUR 599 per month per space, and the terminology is correct: the site states plainly that TISAX is not a certification but a label.
  • Where it falls short: Consulting runs optionally through partners rather than in-house experts. If you handle TISAX® as one of many standards with no automotive dimension, you are buying specialization you will not use.

DataGuard: best for companies outsourcing privacy and information security together

  • What it is: A platform from DataCo GmbH in Munich combining software with expert guidance.
  • Best for: Companies that want TISAX® and GDPR handled under one mandate.
  • Standards covered, per its own website: GDPR, ISO 27001, TISAX, NIS2, and the EU AI Act.
  • Where it is strongest: A detailed and maintained knowledge base with separate entries for each assessment level. DataGuard named the terminology distinction earlier than the market did, stating on its own page that TISAX® does not issue certificates but provides labels.
  • Where it falls short: Prototype protection is defined but not offered as a product feature. SOC 2 does not appear on the homepage. Prices are not published.

Kertos: best for companies running TISAX alongside other EU standards on one control set

  • What it is: A compliance platform from Kertos GmbH in Munich, run as SaaS on European infrastructure, with certified experts included.
  • Best for: Companies running TISAX® alongside ISO 27001, SOC 2, NIS2, and GDPR that do not want to fill the specialist role internally.
  • Standards covered: ISO 27001, ISO 27701, ISO 42001, GDPR, NIS2, EU AI Act, SOC 2, TISAX, and C5.
  • Where it is strongest: One shared control set across all of those standards, more than 100 integrations for automated evidence collection, and external CISO and DPO mandates included as a service rather than sold as separate consulting. Kertos publishes a 100% first-attempt audit pass rate. A reviewer in the software industry titled their G2 review "Kertos an integrated Compliance tool with Seamless Mapping and Monitoring" (G2, 27 October 2025, 4.5 out of 5).
  • Where it falls short: Kertos does not document prototype protection as a product feature on its own website, and publishes neither assessment levels nor prices. For a scope built around AL3 prototype protection that is a genuine disadvantage against Kopexa.

secjur: best for companies wanting broad German standard coverage

  • What it is: A platform from secjur GmbH in Hamburg with optional expert support.
  • Best for: Companies running many parallel standards with an AL2 or AL3 scope.
  • Standards covered, per its own website: ISO 27001, ISO 9001, TISAX, SOC 2, NIS2, GDPR, the EU AI Act, and others.
  • Where it is strongest: The product page names AL2 and AL3 explicitly and publishes quantified efficiency figures for the TISAX® project. secjur is highly visible in German-language content, which raises how often it appears in comparisons.
  • Where it falls short: Prototype protection appears only in a blog post, not as a product feature. The terminology moves between label and certification. Prices are not published.

fuentis and verinice: best for public bodies, large enterprises, and critical infrastructure operators

  • What it is: Two German ISMS and GRC tools. fuentis comes from fuentis AG in Potsdam, verinice from SerNet GmbH in Göttingen.
  • Best for: Organizations running BSI IT-Grundschutz, or required for sovereignty reasons to host the tool themselves.
  • Standards covered, per their own websites: fuentis names ISO 27001, BSI IT-Grundschutz, NIS2, TISAX, SOC 2, and others; verinice names BSI IT-Grundschutz, ISO 27001, data protection, NIS2, and VDA ISA / TISAX.
  • Where it is strongest: fuentis offers SaaS, private cloud, and on-premises, publishes prices from EUR 0 for twelve months, and runs CISO-as-a-Service. verinice is licensed under AGPL, available as open source on GitHub, and can be operated entirely in-house. Both use the TISAX® terminology correctly; fuentis goes further and states explicitly that assessments are carried out by ENX-recognized audit providers rather than by certification bodies.
  • Where it falls short: Neither names a VDA ISA version or the assessment levels on its pages. Neither documents prototype protection as a feature. verinice does not cover SOC 2.

Vanta and Drata: best for companies with US business alongside a TISAX scope

  • What it is: Two US automation platforms, both headquartered in San Francisco.
  • Best for: Companies that need SOC 2 for North American customers in parallel.
  • Standards covered, per their own websites: both list TISAX, ISO 27001, SOC 2, and NIS2; Drata publishes more than 30 standards on a single page.
  • Where it is strongest: Vanta's TISAX page is the only one among the international vendors to name all three assessment levels with definitions, and it describes reusing evidence from ISO 27001, NIS 2, and SOC 2 explicitly. Drata has the broadest published standards catalogue in this comparison.
  • Where it falls short: No prototype protection as a feature, and no VDA ISA version named. Neither publishes prices. Both operate outside the EU, which can matter for suppliers with sovereignty requirements.

When is Kertos not the right choice?

If your scope is built primarily around prototype protection, especially at AL3, a vendor that documents that catalogue explicitly is the better fit; in this comparison that is Kopexa.

Kertos is also the wrong choice if the software has to run on premises, because Kertos runs exclusively as SaaS. If BSI IT-Grundschutz is your leading standard, or if a public body, municipality, or critical infrastructure operator needs an open-source solution under its own control, fuentis and verinice are the right candidates. And if you already have an experienced information security function in house and want only a documentation tool, you will be paying Kertos for expert work you never call on.

What certifications does Kertos hold itself?

Kertos is certified to ISO/IEC 27001:2022 and to ISO/IEC 42001. The certificate is available in the trust center at trust.kertos.io, alongside all 93 Annex A controls of ISO 27001:2022 with individual status, the applicable policies, and the list of subprocessors with their countries.

To be clear, because these two statements are frequently conflated: Kertos does not hold a TISAX® label itself. TISAX® is a procedure for companies in the automotive supply chain and is assessed per location. It is one of the standards the Kertos platform supports for customers, not one of the labels Kertos holds for itself.

Frequently asked questions

Is TISAX a certification?

No. TISAX® is an assessment that ends in a label, and the ENX Association deliberately avoids the word certification for it. The result is not published openly; it is shared through the ENX portal with the specific customers who asked for it. A label is valid for three years.

Who performs a TISAX assessment?

An audit provider approved by the ENX Association. ENX maintains the criteria framework, approves the audit providers, and monitors the quality of implementation; it does not assess. On 5 September 2026 the public ENX directory listed 17 approved audit providers. No software vendor can issue a label.

Do you need software for a TISAX assessment?

No. A single assessment can be passed with spreadsheets and a document folder. The effort arrives afterwards: labels expire after three years, the scope grows with new customers, and evidence goes stale as your systems change. From the second procedure or the second standard onwards, a platform usually pays for itself.

Does a TISAX label also cover ISO 27001?

No, these are two separate procedures with separate assessors and separate outcomes. The information security catalogue of the VDA ISA is based on key aspects of ISO/IEC 27001 according to ENX, so the substantive preparation overlaps. A label does not replace a certificate, and a certificate does not replace a label.

Next step

To see how your TISAX® scope can run alongside ISO 27001 and SOC 2 on one control set, book a slot through the Kertos demo.

Last updated 5 September 2026. TISAX® is a registered trademark of ENX Association.

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check