Tailored Plans, Guaranteed Outcome

One size doesn't fit all! Tailored pricing for lasting and cost-effective compliance, adapted to your company's size and development stage.

Essential

The compliance engine combined with agentic AI automation and customer success support. Designed for in-house experts, DPOs, and CISOs.

  • Compliance automation platform
  • ISMS, AIMS, RoPA, DPIAs, and TOMs
  • Implementation guidance and onboarding through customer success
  • Continuous Customer Success support

  • For multiple frameworks (GDPR, NIS2, ISO, SOC2…)
  • Full agentic workflows, automation, and KAIA (AI Co-Pilot)
  • Trust Center
  • 100+ Integrations
  • UAM, SSO, and 2FA
  • MCP Read Access for Integrations with LLMs

Pro

The compliance engine, AI automation, and fair-use access to our certified experts. The virtual CISO experience with an appointed DPO for Data Privacy frameworks.

  • Everything in ESSENTIAL
  • Support of one of our certified experts during implementation
  • Ongoing certified expert support on demand
  • Yearly audit and compliance status report and check-ins
  • Incident report and response
  • Appointed external DPO (Data Privacy frameworks)

  • Multi-entity Management
  • Automated Slack Alerts & Reports
  • AI-Driven Security Questionnaire Automation
  • Business Continuity Management (InfoSec frameworks)
  • For multiple frameworks (GDPR, NIS2, ISO, SOC2…)
  • Full agentic workflows, automation, and KAIA (AI Co-Pilot)
  • Trust Center
  • 100+ Integrations
  • UAM, SSO, and 2FA
  • MCP Read Access for Integrations with LLMs

Premium

The full-service package to get your compliance journey started. The engine, AI, and an external CISO and/or DPO managing all your compliance topics.

  • Everything in PRO
  • Appointed external CISO (InfoSec frameworks)
  • Ongoing CISO or DPO support with pre-scheduled check-ins and strategy meetings
  • Quarterly audit and compliance status report and check-ins
  • Maximum priority with shortest response time for CISO/DPO support requests

  • Multi-entity Management
  • Automated Slack Alerts & Reports
  • AI-Driven Security Questionnaire Automation
  • Business Continuity Management (InfoSec frameworks)
  • For multiple frameworks (GDPR, NIS2, ISO, SOC2…)
  • Full agentic workflows, automation, and KAIA (AI Co-Pilot)
  • Trust Center
  • 100+ Integrations
  • UAM, SSO, and 2FA
  • MCP Read Access for Integrations with LLMs
< Request an Offer >

All features and services in detail

✓ IncludedAdd-On Optional add-on– Not included in the plan
PLATFORM & TOOLING
All frameworks
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Compliance Automation and Trust Management PlatformCore access to the Kertos platform, the central workspace where all of your compliance work, evidence and workflows live. You manage one or several frameworks in a single place, instead of in spreadsheets and email.✓✓✓
Vendor and Supplier ManagementA central register of third-party vendors and suppliers with risk assessments, due diligence questionnaires and stored documentation. You track and prove that your supply chain meets security and data protection requirements.✓✓✓
In-Platform Asset ManagementAn inventory of your information assets, covering systems, devices, applications and data, held directly in the platform. Assets link to risks and controls, which is a prerequisite for most security certifications.✓✓✓
Policy ManagementCreate, review, approve, version and distribute internal policies from one place. Policies stay current, and employee acknowledgement is tracked and available as audit evidence.✓✓✓
Pre-Built Control LibraryA ready-made catalog of controls already mapped to common frameworks. You start from a working baseline, instead of building controls from scratch.✓✓✓
Policy and Documentation TemplatesA library of pre-written policy and document templates that you adapt to your organization. Cuts drafting time and gives you an audit-ready starting point.✓✓✓
Task and Evidence ManagementAssign compliance tasks to owners and collect the evidence that proves each control is in place. Keeps implementation organized, on schedule and auditable.✓✓✓
Upload and Link Existing PoliciesBring existing documents into the platform and link them to the relevant controls and frameworks. The work you have already done keeps counting.✓✓✓
Audit Trail and Evidence LogA time-stamped record of actions and evidence changes. Shows auditors that your controls are operating, and who did what and when.✓✓✓
Progress Score DashboardA visual dashboard showing how close your organization is to being audit-ready for each framework. Gives teams and leadership an at-a-glance status.✓✓✓
Incident and Security Management WorkflowA structured workflow to log, triage and resolve security incidents. Gives you the documented incident handling process auditors expect to see.✓✓✓
Multi-Framework Cross-MappingReuse a single control or piece of evidence across multiple frameworks, instead of duplicating the work. Key value when you pursue several certifications at once.✓✓✓
Multi-Entity ManagementManage compliance for multiple legal entities, subsidiaries or business units from one account. Built for groups and larger organizations.Add-On✓✓
Bi-Directional Task SynchronizationTwo-way synchronization of tasks between Kertos and external tools such as Jira or your ticketing system. Compliance work stays aligned with the tools your teams already use.✓✓✓
User Access and Role Management (UAM/URM)Control who can see and do what in the platform through roles and permissions. Enforces least privilege access and supports segregation of duties requirements.✓✓✓
Employee Data Sync (HR Software Integration)Automatically sync employee lists from your HR system. Training assignments, access reviews and onboarding or offboarding evidence stay accurate without manual updates.✓✓✓
Single Sign-On (SSO)Log in through your own identity provider. Improves security and convenience, and is often a required security control in its own right.✓✓✓
Two-Factor Authentication (2FA)Adds a second authentication factor for platform login. A standard security control that protects the compliance data held in Kertos itself.✓✓✓
Trust CenterA public page where you share your security and compliance posture and documents with prospects. Reduces repetitive security questionnaire work during sales cycles.✓✓✓
Collaboration Spaces and CommentingIn-context comments and shared spaces so internal teams and auditors can work together without leaving the platform.✓✓✓
In-App Awareness Training ModulesSecurity awareness training delivered to your employees inside the platform, with completion tracked automatically as evidence.✓✓✓
Control Automation Through Integrations (Cloud, Git and more)Connect cloud, code and other tools to collect evidence and monitor controls automatically. Significantly reduces manual, repetitive evidence gathering.✓✓✓
Breach Management Workflow (PII)A guided workflow for handling personal data breaches, including assessment and notification steps. Supports your GDPR breach notification obligations.✓✓✓
Shadow IT DiscoveryDetects unsanctioned apps and services in use across your organization, so you can bring unknown tools under governance and reduce risk.✓✓✓
REST API AccessProgrammatic access to platform data and functions through a REST API, so you can integrate Kertos into your own systems and automations.Add-OnAdd-OnAdd-On
MCP Read AccessRead access through the Model Context Protocol (MCP), so AI assistants and tools can query the compliance data held in Kertos.✓✓✓
MCP Write AccessWrite access through the Model Context Protocol, so connected AI tools can create and update records in Kertos.Add-OnAdd-OnAdd-On
Automated Slack Alerts and ReportsPush compliance alerts, reminders and reports into Slack automatically, so your teams stay informed where they already work.Add-On✓✓
Auditor View (Read-Only Access for Auditors)A read-only role for external auditors to review evidence directly in the platform. Streamlines audits and avoids exporting and emailing files.✓✓✓
Custom FrameworksBuild and manage bespoke or industry-specific frameworks that are not part of the standard library.Add-OnAdd-OnAdd-On
Information security frameworks only
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Automated ISMS PlatformAutomates the Information Security Management System (ISMS) required by ISO 27001 and similar frameworks. Centralizes controls, risks and evidence for security certifications.✓✓✓
Business Continuity Management (BCM)Tools to document, maintain and test your business continuity and disaster recovery plans. Meets the resilience requirements found in security frameworks.Add-On✓✓
Information Security Asset ManagementAsset inventory focused on the information security scope, linking assets to their security controls and risks.✓✓✓
Risk ManagementIdentify, assess, treat and monitor risks in a structured risk register. Core to ISO 27001 style frameworks.✓✓✓
Information Security Training ModulesSecurity-specific training content for your employees, with completion tracked as evidence for certification.✓✓✓
Data protection frameworks only
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Automated RoPAAutomatically generates and maintains the Record of Processing Activities required by GDPR Article 30. Saves significant manual documentation effort.✓✓✓
DPIAsGuided Data Protection Impact Assessments for high-risk processing activities. Helps you meet GDPR Article 35 obligations.✓✓✓
Automated DSRsA workflow to receive and fulfill data subject requests such as access and deletion within legal deadlines.Add-OnAdd-OnAdd-On
Data Privacy Training ModulesPrivacy and GDPR awareness training for your employees, with completion tracked as evidence.✓✓✓
Automated TOMsDocuments the technical and organizational measures required by GDPR Article 32 and keeps them current. Frequently requested by customers and auditors.✓✓✓
Security Breach Management WorkflowsStructured handling and documentation of data protection breaches to meet notification duties and keep an audit trail.✓✓✓
AI governance frameworks only
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Automated AIMS PlatformAutomates an AI Management System in line with ISO 42001 to govern your AI use and its risks. Supports emerging AI compliance obligations.✓✓✓
AI Assets InventoryA register of the AI systems and models you use. The foundation for AI governance and EU AI Act readiness.✓✓✓
AI Risk AssessmentAssess and classify the risks of your AI systems by risk level. Supports responsible AI practices and regulatory requirements.✓✓✓
AI Training ModulesEmployee training on AI governance and responsible AI use, with completion tracked as evidence.✓✓✓
KAIA, THE AI COMPLIANCE CO-PILOT
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Vendors and Systems Auto-FillKAIA populates vendor and system records automatically, which reduces manual data entry during setup.✓✓✓
Real-Time Insights and RecommendationsAI-generated guidance and next best actions based on your current compliance state.✓✓✓
Setup and In-App Product GuidanceIn-product AI assistance that walks your team through configuration and how to use platform features.✓✓✓
AI-Driven Pre-Audit AssistanceAI help to check your readiness and prepare documentation before an audit.✓✓✓
Real-Time Compliance MonitoringContinuous AI monitoring of controls and evidence that flags gaps as soon as they arise.✓✓✓
MCP IntegrationConnects KAIA to external AI tools and assistants through the Model Context Protocol (MCP).✓✓✓
Policy Co-Pilot (Policy Generator)Generates and tailors policy documents with AI, drawing on your own context and framework requirements.✓✓✓
Questionnaire Automation (AI)AI drafts answers to security and vendor questionnaires using your existing compliance data.Add-On✓✓
Universal Contextual SearchNatural language search across all compliance data in the platform, so your team finds anything quickly.✓✓✓
Agentic Evidence CheckerAn AI agent that reviews collected evidence for completeness and validity and flags issues before an audit.✓✓✓
Assisted Register and Inventory CreationAI helps you build registers and inventories for assets, vendors and systems faster and more completely.✓✓✓
Assisted Risk Management WorkflowsAI assistance in identifying, assessing and treating risks within your risk register.✓✓✓
Assisted RoPA CreationAI helps you create and maintain the Record of Processing Activities required under GDPR.✓✓✓
IMPLEMENTATION PACKAGE
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Dedicated Implementation SupportA dedicated team from Kertos to support the implementation of your chosen framework.–✓✓
Project KickoffA structured kickoff session to scope the project, set timelines and align stakeholders at the start.✓✓✓
Personal OnboardingGuided onboarding tailored to your organization to get your team productive quickly.✓✓✓
Pre-Audit Completeness Check-InA review before the external audit to confirm everything is in place and reduce the risk of findings.–✓✓
Internal AuditA Kertos-supported internal audit, a required step before certification for many frameworks.Add-OnAdd-OnAdd-On
Post-Audit Review and Mitigation StrategyAfter the audit, a review of findings and a plan to remediate them.–✓✓
ONGOING CUSTOMER SUPPORT AND SUCCESS
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Customer SupportAccess to the Kertos support team for platform questions and issues.✓✓✓
Customer Success ManagerA named Customer Success Manager who helps you get value from the platform and stay on track over time.✓✓✓
Implementation Status Report and Check-InA status report and review meeting on your implementation progress.–YearlyQuarterly
ONGOING CERTIFIED EXPERT SUPPORT
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Expert CollaborationOngoing access to collaborate with Kertos's certified compliance experts on a fair-use basis, for questions that go beyond the platform itself.–✓✓
Community Webinars and EventsAccess to Kertos community webinars and events for ongoing learning and networking.–✓✓
Compliance ReportA report summarizing your compliance posture and progress, prepared by your certified experts.–YearlyQuarterly
Incident Support and ResponseHelp from Kertos's certified experts when a security or compliance incident occurs.–✓✓
EXTERNAL CISO SERVICES (INFOSEC)
Feature / ServiceDescriptionESSENTIALPROPREMIUM
ISMS ManagementSteering and supporting daily ISMS operation. Responsibility and risk decisions stay with you.––✓
Risk Assessment and Security RecommendationsExpert assessment together with your risk owners, with up to two event-driven updates per year.––✓
Preparation and Facilitation of Management Review ProcessesPreparation, facilitation, summary and follow-up. Sign-off stays with you.––✓
Documentation ReviewReview inside the document control cycle. Drafting and release stay with you.––✓
Evidence ReviewReview of evidence and measure status in the Kertos platform, with escalation of overdue items.––✓
Pre-Audit GuidancePreparation and follow-up for internal and external audits, with attendance available as an option.––✓
Incident Response ManagementAssessment and advice. Technical response and forensics stay out of scope.––✓
Reporting and Escalation to ManagementRegular and event-driven reporting on risks, incidents and deviations.––✓
Regular Check-InsA monthly working session with your internal information security coordinator.––✓
Awareness and Training ManagementThe external CISO advises which groups need which training, reviews completion status in the Kertos platform, and agrees reminders and follow-ups with management.––✓
EXTERNAL DPO SERVICES (GDPR ONLY)
Feature / ServiceDescriptionESSENTIALPROPREMIUM
Official Appointment of the DPO (Art. 37)Kertos is formally appointed as your external Data Protection Officer under GDPR Article 37. Satisfies the legal obligation for organizations required to designate a DPO.–✓✓
Privacy ReportsA report on your data protection posture, prepared by your external DPO.–YearlyQuarterly
Quarterly Operation and Strategy Check-InsQuarterly meetings to review privacy operations and strategy with your external DPO.–Add-On✓
Direct Communication with Customer's ClientsWhere needed, your external DPO communicates directly with your own clients or data subjects on privacy matters.–Add-OnAdd-On
Data Processing Agreement Check (Art. 28)Review of data processing agreements with your processors, as required under GDPR Article 28.–✓✓
Supervisory Authority LiaisonYour external DPO liaises with the relevant data protection supervisory authority on your behalf.–✓✓
General Privacy Guidance and Advisory (Art. 39)Ongoing privacy advice and guidance, one of the core DPO tasks under GDPR Article 39.–✓✓
Advice on Training and Awareness (Art. 39)DPO advice on staff data protection training and awareness programs, as part of the Article 39 duties.–✓✓
Advice on Conducting DPIAs (Art. 39, Art. 35)DPO guidance on when and how to carry out Data Protection Impact Assessments.–✓✓
Main Contact Point for the Supervisory Authority (Art. 39, Art. 36)Your DPO acts as the main point of contact for the supervisory authority, including on prior consultation matters.–✓✓
Advice on Handling Data Subject Rights (Art. 12-22)DPO guidance on responding to data subject rights requests such as access, rectification and erasure.–✓✓
Advice on the Record of Processing Activities (Art. 30)DPO advice on creating and maintaining the Record of Processing Activities.–✓✓
Data Breach Support (Art. 33, Art. 34)DPO support in assessing and notifying personal data breaches to authorities and affected individuals.–✓✓
Advice on Security of Processing (TOMs) (Art. 32)DPO advice on appropriate technical and organizational security measures for your processing.–✓✓
PARTNER SERVICES
ServiceDescriptionAvailability
PentestingPenetration testing of your systems and applications to find exploitable vulnerabilities. Often required or recommended for certification, delivered through partners.Add-On
Phishing Simulation and Web Browsing SecuritySimulated phishing campaigns and safe browsing protection to test and improve employee security awareness.Add-On
Dark Web MonitoringMonitors the dark web for leaked credentials or data relating to your organization, so you can react early.Add-On
Secret DetectionScans your code and repositories for exposed secrets such as API keys and passwords.Add-On
Attack Surface ManagementContinuously discovers and monitors your internet-facing assets to reduce exposure.Add-On
External Certification AuditThe independent audit performed by an external certification body that leads to your actual certificate. Kertos coordinates this through partners.Add-On
Compliance Data Migration (Other GRC Platforms)Migrates your existing compliance data from another GRC tool into Kertos, which eases the switch. Delivered through a partner.Add-On
Personalized In-House Training CoursesCustom, tailored training courses delivered to your own staff.Add-On
API ScanningSecurity scanning of your APIs to detect vulnerabilities.Add-On
Vulnerability ManagementOngoing identification, prioritization and remediation tracking of security vulnerabilities.Add-On
Shadow AI DiscoveryDetects unsanctioned AI tools in use across your organization so they can be brought under governance.Add-On
Endpoint ProtectionSecurity software that protects laptops and other devices, known as endpoint detection and response. Delivered through a partner.Add-On
Exposure ManagementA broader program to continuously identify and reduce security exposures across your environment.Add-On
TESTIMONIALS

What Our Customers Say

Compliance you can trust: Whether B2C, B2B, startup, or scaleup, Kertos is the ideal solution for companies aiming for rapid growth.

Herwig Gangl
Herwig Gangl
Co-Founder

"Implementing data protection and compliance in a structured way with Kertos"

From the very start, we felt that we were working with a partner who takes a realistic view of the effort and the process involved. The result, for us, is now a central platform that lets us manage our compliance topics in a structured way, across teams.

Thomas Gan
Thomas Gan
Co-Founder, MuffinTech

“Fast, straightforward, and seamlessly automated!”

It's incredible how effortlessly the Kertos team guided us through the complex ISO 27001 process. Fast, straightforward, and seamlessly automated! Compliance is no longer on our minds because Kertos takes care of everything.

Janina Möllmann
Janina Möllmann
CEO, GAIA Technologies

“ISO 27001 certification within a few weeks”

With Kertos, we were able to achieve our ISO27001 certification within a few weeks. It was immediately obvious that this was a powerful compliance automation solution developed in and for the European market!

Matthias Knoche
Matthias Knoche
COO, McMakler

“European compliance automation built for mid-market teams”

As a mid-market company, we don't have a large compliance team, and Kertos means we don't need to build one. It automated our GDPR workflows so thoroughly that work which used to take days now takes minutes, and in many cases doesn't need a compliance manager to touch it at all. Onboarding took an afternoon, including connecting our own homegrown software via API. And unlike the mass compliance providers, we get a European partner who understands our requirements firsthand.

Julian Lübke
Julian Lübke
Co-Founder & CEO, deeploi

“Real compliance powerhouse”

Kertos quickly and precisely guided us through the GDPR and ISO27001 certification compliance jungle. The Kertos platform was easy to implement and is a real compliance powerhouse due to the high level of automation.

Ferdinand Schmidt-Thomé
Ferdinand Schmidt-Thomé
Co-Founder, Aware

“Flexible and scalable solution for GDPR compliance”

As a health-tech company that deals with sensitive customer data, we have found a flexible and scalable solution to comply with the GDPR in Kertos. It strengthens the trust of our customers, sets new standards through automation, and the support team is consistently responsive and reliable when it comes to urgent concerns — Kertos is therefore the all-in-one solution that really pays off for us.

FAQ

Frequently Asked Questions

Information about Kertos's Compliance Platform

How does Kertos help comply with the EU AI Act?

With Kertos, you can specifically address EU AI Act requirements, identify risks, and automate compliance documentation. Our platform helps you reliably comply with the legal framework for AI systems.

Can I manage multiple frameworks at the same time?

Yes, Kertos is specifically designed to support multi-framework compliance. You can manage standards such as ISO 27001, SOC2, and GDPR in parallel and ensure that your company is compliant at all levels.

What is Kertos and how does the platform support my compliance?

Kertos is Europe's most innovative compliance platform. We automate standards like ISO 27001, GDPR, SOC2, or TISAX®, from initial analysis to audit. Our solution enables you to design compliance processes efficiently and sustainably, while you fully concentrate on your core business. Kertos integrates all relevant data sources of your company via API interfaces, including websites, single sign-on solutions (SSO), office applications and central databases.

Which industries benefit from Kertos?

Our platform supports companies in various industries:

  • Startups: Building trust through the early implementation of security standards.
  • Scaleups: Security and compliance for growth-oriented companies.
  • SaaS: Protection of sensitive customer data and cloud compliance.
  • FinTech: Meeting high regulatory requirements.
  • HealthTech: Security and data protection for health data.
  • InsurTech: Compliance with the strictest standards for sensitive customer data.
Which frameworks does Kertos support?

With Kertos, you can manage a variety of compliance standards in one central location, including:

  • ISO 27001
  • TISAX®
  • SOC 2
  • DORA (Digital Operational Resilience Act)
  • GDPR
  • ISO 27701
  • ISO 42001
  • EU AI Act
  • NIS2

Our multi-framework support helps you make your organization holistically compliant.

How does Kertos simplify the compliance process?

Kertos automates time-consuming tasks such as data protection documentation, incident management, and the development of an ISMS. With our no-code integrations and REST API, you can seamlessly connect your systems and get a complete overview of your compliance processes in real-time.

What is Kertos AI (KAI) and how does it help me?

Kertos AI (KAI) is your intelligent compliance partner, available 24/7. KAI handles tasks such as risk assessments, policy management, and supplier evaluations, automates documentation creation, and provides answers to complex compliance questions.

‍

Can I integrate Kertos with my existing systems?

Yes! Kertos offers simple no-code integrations with standard interfaces, as well as a REST API that seamlessly integrates with your existing systems. This allows you to connect internal and external systems, including databases, SaaS tools, and third-party services, for maximum transparency.

Is the platform suitable for my company?

Kertos is flexible and scalable, enabling companies of any size – from startups to established market leaders – to benefit from the automation and simplification of compliance processes.

Do you have any more questions?

Our team is happy to assist you with any questions you may have about our platform, various frameworks, and compliance.

Inquire now

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check