| PLATFORM & TOOLING |
| All frameworks |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Compliance Automation and Trust Management Platform | Core access to the Kertos platform, the central workspace where all of your compliance work, evidence and workflows live. You manage one or several frameworks in a single place, instead of in spreadsheets and email. | ✓ | ✓ | ✓ |
| Vendor and Supplier Management | A central register of third-party vendors and suppliers with risk assessments, due diligence questionnaires and stored documentation. You track and prove that your supply chain meets security and data protection requirements. | ✓ | ✓ | ✓ |
| In-Platform Asset Management | An inventory of your information assets, covering systems, devices, applications and data, held directly in the platform. Assets link to risks and controls, which is a prerequisite for most security certifications. | ✓ | ✓ | ✓ |
| Policy Management | Create, review, approve, version and distribute internal policies from one place. Policies stay current, and employee acknowledgement is tracked and available as audit evidence. | ✓ | ✓ | ✓ |
| Pre-Built Control Library | A ready-made catalog of controls already mapped to common frameworks. You start from a working baseline, instead of building controls from scratch. | ✓ | ✓ | ✓ |
| Policy and Documentation Templates | A library of pre-written policy and document templates that you adapt to your organization. Cuts drafting time and gives you an audit-ready starting point. | ✓ | ✓ | ✓ |
| Task and Evidence Management | Assign compliance tasks to owners and collect the evidence that proves each control is in place. Keeps implementation organized, on schedule and auditable. | ✓ | ✓ | ✓ |
| Upload and Link Existing Policies | Bring existing documents into the platform and link them to the relevant controls and frameworks. The work you have already done keeps counting. | ✓ | ✓ | ✓ |
| Audit Trail and Evidence Log | A time-stamped record of actions and evidence changes. Shows auditors that your controls are operating, and who did what and when. | ✓ | ✓ | ✓ |
| Progress Score Dashboard | A visual dashboard showing how close your organization is to being audit-ready for each framework. Gives teams and leadership an at-a-glance status. | ✓ | ✓ | ✓ |
| Incident and Security Management Workflow | A structured workflow to log, triage and resolve security incidents. Gives you the documented incident handling process auditors expect to see. | ✓ | ✓ | ✓ |
| Multi-Framework Cross-Mapping | Reuse a single control or piece of evidence across multiple frameworks, instead of duplicating the work. Key value when you pursue several certifications at once. | ✓ | ✓ | ✓ |
| Multi-Entity Management | Manage compliance for multiple legal entities, subsidiaries or business units from one account. Built for groups and larger organizations. | Add-On | ✓ | ✓ |
| Bi-Directional Task Synchronization | Two-way synchronization of tasks between Kertos and external tools such as Jira or your ticketing system. Compliance work stays aligned with the tools your teams already use. | ✓ | ✓ | ✓ |
| User Access and Role Management (UAM/URM) | Control who can see and do what in the platform through roles and permissions. Enforces least privilege access and supports segregation of duties requirements. | ✓ | ✓ | ✓ |
| Employee Data Sync (HR Software Integration) | Automatically sync employee lists from your HR system. Training assignments, access reviews and onboarding or offboarding evidence stay accurate without manual updates. | ✓ | ✓ | ✓ |
| Single Sign-On (SSO) | Log in through your own identity provider. Improves security and convenience, and is often a required security control in its own right. | ✓ | ✓ | ✓ |
| Two-Factor Authentication (2FA) | Adds a second authentication factor for platform login. A standard security control that protects the compliance data held in Kertos itself. | ✓ | ✓ | ✓ |
| Trust Center | A public page where you share your security and compliance posture and documents with prospects. Reduces repetitive security questionnaire work during sales cycles. | ✓ | ✓ | ✓ |
| Collaboration Spaces and Commenting | In-context comments and shared spaces so internal teams and auditors can work together without leaving the platform. | ✓ | ✓ | ✓ |
| In-App Awareness Training Modules | Security awareness training delivered to your employees inside the platform, with completion tracked automatically as evidence. | ✓ | ✓ | ✓ |
| Control Automation Through Integrations (Cloud, Git and more) | Connect cloud, code and other tools to collect evidence and monitor controls automatically. Significantly reduces manual, repetitive evidence gathering. | ✓ | ✓ | ✓ |
| Breach Management Workflow (PII) | A guided workflow for handling personal data breaches, including assessment and notification steps. Supports your GDPR breach notification obligations. | ✓ | ✓ | ✓ |
| Shadow IT Discovery | Detects unsanctioned apps and services in use across your organization, so you can bring unknown tools under governance and reduce risk. | ✓ | ✓ | ✓ |
| REST API Access | Programmatic access to platform data and functions through a REST API, so you can integrate Kertos into your own systems and automations. | Add-On | Add-On | Add-On |
| MCP Read Access | Read access through the Model Context Protocol (MCP), so AI assistants and tools can query the compliance data held in Kertos. | ✓ | ✓ | ✓ |
| MCP Write Access | Write access through the Model Context Protocol, so connected AI tools can create and update records in Kertos. | Add-On | Add-On | Add-On |
| Automated Slack Alerts and Reports | Push compliance alerts, reminders and reports into Slack automatically, so your teams stay informed where they already work. | Add-On | ✓ | ✓ |
| Auditor View (Read-Only Access for Auditors) | A read-only role for external auditors to review evidence directly in the platform. Streamlines audits and avoids exporting and emailing files. | ✓ | ✓ | ✓ |
| Custom Frameworks | Build and manage bespoke or industry-specific frameworks that are not part of the standard library. | Add-On | Add-On | Add-On |
| Information security frameworks only |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Automated ISMS Platform | Automates the Information Security Management System (ISMS) required by ISO 27001 and similar frameworks. Centralizes controls, risks and evidence for security certifications. | ✓ | ✓ | ✓ |
| Business Continuity Management (BCM) | Tools to document, maintain and test your business continuity and disaster recovery plans. Meets the resilience requirements found in security frameworks. | Add-On | ✓ | ✓ |
| Information Security Asset Management | Asset inventory focused on the information security scope, linking assets to their security controls and risks. | ✓ | ✓ | ✓ |
| Risk Management | Identify, assess, treat and monitor risks in a structured risk register. Core to ISO 27001 style frameworks. | ✓ | ✓ | ✓ |
| Information Security Training Modules | Security-specific training content for your employees, with completion tracked as evidence for certification. | ✓ | ✓ | ✓ |
| Data protection frameworks only |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Automated RoPA | Automatically generates and maintains the Record of Processing Activities required by GDPR Article 30. Saves significant manual documentation effort. | ✓ | ✓ | ✓ |
| DPIAs | Guided Data Protection Impact Assessments for high-risk processing activities. Helps you meet GDPR Article 35 obligations. | ✓ | ✓ | ✓ |
| Automated DSRs | A workflow to receive and fulfill data subject requests such as access and deletion within legal deadlines. | Add-On | Add-On | Add-On |
| Data Privacy Training Modules | Privacy and GDPR awareness training for your employees, with completion tracked as evidence. | ✓ | ✓ | ✓ |
| Automated TOMs | Documents the technical and organizational measures required by GDPR Article 32 and keeps them current. Frequently requested by customers and auditors. | ✓ | ✓ | ✓ |
| Security Breach Management Workflows | Structured handling and documentation of data protection breaches to meet notification duties and keep an audit trail. | ✓ | ✓ | ✓ |
| AI governance frameworks only |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Automated AIMS Platform | Automates an AI Management System in line with ISO 42001 to govern your AI use and its risks. Supports emerging AI compliance obligations. | ✓ | ✓ | ✓ |
| AI Assets Inventory | A register of the AI systems and models you use. The foundation for AI governance and EU AI Act readiness. | ✓ | ✓ | ✓ |
| AI Risk Assessment | Assess and classify the risks of your AI systems by risk level. Supports responsible AI practices and regulatory requirements. | ✓ | ✓ | ✓ |
| AI Training Modules | Employee training on AI governance and responsible AI use, with completion tracked as evidence. | ✓ | ✓ | ✓ |
| KAIA, THE AI COMPLIANCE CO-PILOT |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Vendors and Systems Auto-Fill | KAIA populates vendor and system records automatically, which reduces manual data entry during setup. | ✓ | ✓ | ✓ |
| Real-Time Insights and Recommendations | AI-generated guidance and next best actions based on your current compliance state. | ✓ | ✓ | ✓ |
| Setup and In-App Product Guidance | In-product AI assistance that walks your team through configuration and how to use platform features. | ✓ | ✓ | ✓ |
| AI-Driven Pre-Audit Assistance | AI help to check your readiness and prepare documentation before an audit. | ✓ | ✓ | ✓ |
| Real-Time Compliance Monitoring | Continuous AI monitoring of controls and evidence that flags gaps as soon as they arise. | ✓ | ✓ | ✓ |
| MCP Integration | Connects KAIA to external AI tools and assistants through the Model Context Protocol (MCP). | ✓ | ✓ | ✓ |
| Policy Co-Pilot (Policy Generator) | Generates and tailors policy documents with AI, drawing on your own context and framework requirements. | ✓ | ✓ | ✓ |
| Questionnaire Automation (AI) | AI drafts answers to security and vendor questionnaires using your existing compliance data. | Add-On | ✓ | ✓ |
| Universal Contextual Search | Natural language search across all compliance data in the platform, so your team finds anything quickly. | ✓ | ✓ | ✓ |
| Agentic Evidence Checker | An AI agent that reviews collected evidence for completeness and validity and flags issues before an audit. | ✓ | ✓ | ✓ |
| Assisted Register and Inventory Creation | AI helps you build registers and inventories for assets, vendors and systems faster and more completely. | ✓ | ✓ | ✓ |
| Assisted Risk Management Workflows | AI assistance in identifying, assessing and treating risks within your risk register. | ✓ | ✓ | ✓ |
| Assisted RoPA Creation | AI helps you create and maintain the Record of Processing Activities required under GDPR. | ✓ | ✓ | ✓ |
| IMPLEMENTATION PACKAGE |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Dedicated Implementation Support | A dedicated team from Kertos to support the implementation of your chosen framework. | – | ✓ | ✓ |
| Project Kickoff | A structured kickoff session to scope the project, set timelines and align stakeholders at the start. | ✓ | ✓ | ✓ |
| Personal Onboarding | Guided onboarding tailored to your organization to get your team productive quickly. | ✓ | ✓ | ✓ |
| Pre-Audit Completeness Check-In | A review before the external audit to confirm everything is in place and reduce the risk of findings. | – | ✓ | ✓ |
| Internal Audit | A Kertos-supported internal audit, a required step before certification for many frameworks. | Add-On | Add-On | Add-On |
| Post-Audit Review and Mitigation Strategy | After the audit, a review of findings and a plan to remediate them. | – | ✓ | ✓ |
| ONGOING CUSTOMER SUPPORT AND SUCCESS |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Customer Support | Access to the Kertos support team for platform questions and issues. | ✓ | ✓ | ✓ |
| Customer Success Manager | A named Customer Success Manager who helps you get value from the platform and stay on track over time. | ✓ | ✓ | ✓ |
| Implementation Status Report and Check-In | A status report and review meeting on your implementation progress. | – | Yearly | Quarterly |
| ONGOING CERTIFIED EXPERT SUPPORT |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Expert Collaboration | Ongoing access to collaborate with Kertos's certified compliance experts on a fair-use basis, for questions that go beyond the platform itself. | – | ✓ | ✓ |
| Community Webinars and Events | Access to Kertos community webinars and events for ongoing learning and networking. | – | ✓ | ✓ |
| Compliance Report | A report summarizing your compliance posture and progress, prepared by your certified experts. | – | Yearly | Quarterly |
| Incident Support and Response | Help from Kertos's certified experts when a security or compliance incident occurs. | – | ✓ | ✓ |
| EXTERNAL CISO SERVICES (INFOSEC) |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| ISMS Management | Steering and supporting daily ISMS operation. Responsibility and risk decisions stay with you. | – | – | ✓ |
| Risk Assessment and Security Recommendations | Expert assessment together with your risk owners, with up to two event-driven updates per year. | – | – | ✓ |
| Preparation and Facilitation of Management Review Processes | Preparation, facilitation, summary and follow-up. Sign-off stays with you. | – | – | ✓ |
| Documentation Review | Review inside the document control cycle. Drafting and release stay with you. | – | – | ✓ |
| Evidence Review | Review of evidence and measure status in the Kertos platform, with escalation of overdue items. | – | – | ✓ |
| Pre-Audit Guidance | Preparation and follow-up for internal and external audits, with attendance available as an option. | – | – | ✓ |
| Incident Response Management | Assessment and advice. Technical response and forensics stay out of scope. | – | – | ✓ |
| Reporting and Escalation to Management | Regular and event-driven reporting on risks, incidents and deviations. | – | – | ✓ |
| Regular Check-Ins | A monthly working session with your internal information security coordinator. | – | – | ✓ |
| Awareness and Training Management | The external CISO advises which groups need which training, reviews completion status in the Kertos platform, and agrees reminders and follow-ups with management. | – | – | ✓ |
| EXTERNAL DPO SERVICES (GDPR ONLY) |
| Feature / Service | Description | ESSENTIAL | PRO | PREMIUM |
| Official Appointment of the DPO (Art. 37) | Kertos is formally appointed as your external Data Protection Officer under GDPR Article 37. Satisfies the legal obligation for organizations required to designate a DPO. | – | ✓ | ✓ |
| Privacy Reports | A report on your data protection posture, prepared by your external DPO. | – | Yearly | Quarterly |
| Quarterly Operation and Strategy Check-Ins | Quarterly meetings to review privacy operations and strategy with your external DPO. | – | Add-On | ✓ |
| Direct Communication with Customer's Clients | Where needed, your external DPO communicates directly with your own clients or data subjects on privacy matters. | – | Add-On | Add-On |
| Data Processing Agreement Check (Art. 28) | Review of data processing agreements with your processors, as required under GDPR Article 28. | – | ✓ | ✓ |
| Supervisory Authority Liaison | Your external DPO liaises with the relevant data protection supervisory authority on your behalf. | – | ✓ | ✓ |
| General Privacy Guidance and Advisory (Art. 39) | Ongoing privacy advice and guidance, one of the core DPO tasks under GDPR Article 39. | – | ✓ | ✓ |
| Advice on Training and Awareness (Art. 39) | DPO advice on staff data protection training and awareness programs, as part of the Article 39 duties. | – | ✓ | ✓ |
| Advice on Conducting DPIAs (Art. 39, Art. 35) | DPO guidance on when and how to carry out Data Protection Impact Assessments. | – | ✓ | ✓ |
| Main Contact Point for the Supervisory Authority (Art. 39, Art. 36) | Your DPO acts as the main point of contact for the supervisory authority, including on prior consultation matters. | – | ✓ | ✓ |
| Advice on Handling Data Subject Rights (Art. 12-22) | DPO guidance on responding to data subject rights requests such as access, rectification and erasure. | – | ✓ | ✓ |
| Advice on the Record of Processing Activities (Art. 30) | DPO advice on creating and maintaining the Record of Processing Activities. | – | ✓ | ✓ |
| Data Breach Support (Art. 33, Art. 34) | DPO support in assessing and notifying personal data breaches to authorities and affected individuals. | – | ✓ | ✓ |
| Advice on Security of Processing (TOMs) (Art. 32) | DPO advice on appropriate technical and organizational security measures for your processing. | – | ✓ | ✓ |
| PARTNER SERVICES |
| Service | Description | Availability |
| Pentesting | Penetration testing of your systems and applications to find exploitable vulnerabilities. Often required or recommended for certification, delivered through partners. | Add-On |
| Phishing Simulation and Web Browsing Security | Simulated phishing campaigns and safe browsing protection to test and improve employee security awareness. | Add-On |
| Dark Web Monitoring | Monitors the dark web for leaked credentials or data relating to your organization, so you can react early. | Add-On |
| Secret Detection | Scans your code and repositories for exposed secrets such as API keys and passwords. | Add-On |
| Attack Surface Management | Continuously discovers and monitors your internet-facing assets to reduce exposure. | Add-On |
| External Certification Audit | The independent audit performed by an external certification body that leads to your actual certificate. Kertos coordinates this through partners. | Add-On |
| Compliance Data Migration (Other GRC Platforms) | Migrates your existing compliance data from another GRC tool into Kertos, which eases the switch. Delivered through a partner. | Add-On |
| Personalized In-House Training Courses | Custom, tailored training courses delivered to your own staff. | Add-On |
| API Scanning | Security scanning of your APIs to detect vulnerabilities. | Add-On |
| Vulnerability Management | Ongoing identification, prioritization and remediation tracking of security vulnerabilities. | Add-On |
| Shadow AI Discovery | Detects unsanctioned AI tools in use across your organization so they can be brought under governance. | Add-On |
| Endpoint Protection | Security software that protects laptops and other devices, known as endpoint detection and response. Delivered through a partner. | Add-On |
| Exposure Management | A broader program to continuously identify and reduce security exposures across your environment. | Add-On |