- If the proofs are missing before the audit: Administrators and IT managers who oversee the ISMS often pull data from Excel lists and folders together. You’ll learn how compliance software can partially automate all actions, responsibilities, and evidence so that you don’t have to search for them again before every audit.
- If ISO 27001 and NIS2 apply simultaneously: Many measures require both regulations. You see how you can document each measure only once and prove it for both.
- If Microsoft 365 and Windows are to provide the data: Many proofs are created anyway there, such as MFA, device protection, and access. You will learn what you should ask vendors about interfaces, updates, and outages before purchasing.
- Before you decide on a tool: A practical test in three steps shows whether a solution fits your processes. In addition, we evaluate the public data from six providers.
Quick overview:
In many medium-sized companies with 50 to 500 employees, information security depends on someone who is actually responsible for the IT operations:
At the Admin, who is also the Information Security Officer.
Or the IT management, which is also holding the ISO-27001 certificate in place.
Seit NIS2 gilt, wird es für viele Betriebe enger, etwa in Energie, Gesundheit, Logistik, Maschinenbau oder bei digitalen Diensten: Laut BSI „NIS-2 in Zahlen“ haben sich bereits 20.141 Unternehmen und Organisationen registriert, 1.272 Erstmeldungen sind eingegangen.
If you are in this role, you must now present evidence of actions and findings.
Compliance automation can help you reduce routine work – it does not replace decisions or security knowledge.

Bild von Markus Winkler auf Pexels
The most important figures
- NIS-2 registrations: 20,141 registered companies and organizations, of which 13,252 are important and 6,837 are particularly important (BSI, as of September 30, 2026).
- Reports: 1,272 first reports after NIS-2 (BSI, same status).
- Professionals: 79,000 unfilled positions in IT overall, not just in security (Bitkom, September 3, 2026).
- Grundschutz++: The BSI will present the methodology at the it-sa on October 27, 2026; as of January 1, 2027, certification applications for ISO 27001 will be possible based on this basis.
Who has the problem – and why it’s pressing now
For more than 20 years, we have been explaining Windows and Microsoft services in Windows Tweaks. For this article, we wanted to find out where compliance work really gets bogged down in everyday life, and we evaluated the public statements of six providers ourselves.
The topic rarely ends up in its own department. Often it’s the admin with additional responsibilities: they were appointed as the information security officer in addition to their IT duties. Or the IT management, who is also tasked with maintaining the certificate.
In addition, there are the questions from the others: the management wants to know whether the audit exists. Data protection and compliance require the same evidence, only in a different form.
The problem is rarely the requirement itself, but the care.
Typical signs:
- The risk list is located in an Excel file.
- The evidence is divided into three folders.
- Shortly before the surveillance audit begins the search.
- The same measure is included twice in the documentation for ISO 27001 and NIS2.
Often the basic foundation is lacking. According to Eurostat (survey 2024, Germany), only 63 percent of companies with 50 to 249 employees had written rules regarding ICT security. 57 percent regularly carried out risk assessments.
The technical foundations for Microsoft 365 and Windows are covered in a separate ISO 27001 checklist; this concerns the choice of tools.
A realistic example:
A supplier with 120 employees obtained its ISO 27001 certificate in 2025. The system administrator also manages the information security management system (ISMS). When the main customer demands NIS2 certifications and monitoring audits are underway at the same time, there is no overview:
Which measure meets which requirement, and when was the last proof examined?
Instead of immediately choosing a platform, he first describes the three processes that cost him the most time.
What does compliance automation mean?
Compliance automation means linking requirements, security controls, responsibilities, and evidence in a software system. An ISMS software then displays, for example, which control a document serves, who is responsible, and when it was last reviewed. Unlike a document repository, it accompanies the ongoing process.
What software does and what it doesn’t
It can centrally manage policies and evidence, assign requirements from multiple regulations to the same controls, and link risks with actions.
However, an automatically captured status is not yet a judgment on safety. Scope, risk assessment, the selection of appropriate measures, and the acceptance of residual risks remain tasks for the company. Therefore, a solution that records changes, makes responsibilities visible, and requires a professional release of evidence is useful.
If Microsoft 365 and Windows provide the proofs
In many companies, important evidence is already created in Microsoft 365 and on Windows devices: whether all accounts are protected by MFA (Entra ID), whether laptops are encrypted and up to date (Intune, BitLocker), and who accessed data when (audit log in Microsoft Purview). An ISMS software can retrieve such evidence via interfaces or export it as a file. Therefore, during the test, ask specifically:
- Which services can be connected, and how often are the data updated?
- What happens if a connection fails or permissions change?
- Can evidence also be uploaded via export, where there is no interface?
ISO 27001: Controls, risks and the explanation for applicability
ISO/IEC 27001:2022 describes an Information Security Management System (ISMS). Annex A includes 93 Controls (security measures) in four subject areas; they serve as a reference for the selection of measures.
The central part is the Statement of Applicability: In it, you state which controls are relevant, how they are handled, and why others are omitted.
NIS2: Structure obligations, not hand them over
Bei NIS2 unterstützt Software vor allem die Organisation der Risikomanagementmaßnahmen, von Verantwortlichkeiten und Belegen. In Deutschland gilt das NIS2UmsuCG seit dem 6. Dezember 2025. NIS2 ist keine Zertifizierung. Ein ISO-27001-ISMS liefert eine gute Grundlage, ersetzt aber weder Registrierung noch Meldeprozess bei erheblichen Sicherheitsvorfällen oder die Verantwortung der Leitung.
Warum Grundschutz++ das Thema verändert: Das BSI schreibt auf seiner Grundschutz++-Seite:
Checklists can in the future be automatically generated and adapted to the specific application case based on the requirements of the user catalog Grundschutz++.
BSI, Basic protection++
The BSI has been providing machine-readable format (OSCAL) requirements since September 29, 2025. A practical test question for any software therefore is: Can it import such catalogs and display measures on them?
What you should consider when choosing
Eine lange Funktionsliste sagt wenig über die Arbeitsersparnis. Besser ist ein Praxistest: Ordne einer relevanten Kontrolle einen Verantwortlichen und einen Nachweis zu, ändere dann eine Anforderung und prüfe, was automatisch passiert und wo du manuell nachpflegen musst. Auch die Compliance-Automatisierung im Überblick lässt sich besser beurteilen, wenn du deine ISMS-Prozesse vorher klar beschrieben hast.
- Level of automation: Are proofs only submitted or are actions also assigned, tasks triggered, and changes logged?
- Standard coverage: Can ISO 27001, NIS2 and other regulations be combined into one document?
- Hosting and data location: Where are the guidelines, risk data, and evidence located, and who is allowed to access them?
- Integrations: Which systems provide data, and are the origin, timeliness, and potential failures comprehensible?
- Support: Is there appropriate support available for technical or professional questions?
- Price transparency: Is it clear which users, modules, standards, integrations, or support services are included in the price?
Our analysis: What six providers publicly declare
We have reviewed the official websites of six providers and compiled their information into a structure of a test grid. The order is not a ranking.
According to the provider’s statements, as of October 8, 2026. „Not specified“ means that it was not found on the accessible official websites. „Standards“ refers to ISO 27001 and NIS2, as well as other regulations to the best of our knowledge.
Standards and Hosting
| Providers | Standards | Hosting & Data Location |
| SECJUR | ISO 27001, NIS2; also including TISAX, DORA and SOC 2, among others | „Hosted in Germany“ |
| DataGuard | ISO 27001, NIS2; also TISAX and EU AI Act | not specified |
| OPUS i (kronsoft) | ISO 27001; NIS2 „prepared“ | On-Premise, Cloud or SaaS in a German data center |
| Secfix | ISO 27001, NIS2 | „European cloud infrastructure“ |
| Vanta | ISO 27001, NIS2 | EU data center in Frankfurt (according to the 2023 announcement) |
| verinice (SerNet) | ISO 27001, NIS2 | verinice.cloud (country not specified) or self-run business |
Specialty, testing, and entry
| Providers | Special feature | Testing and getting started |
| SECJUR | Platform plus support from certified professionals | Demo on request |
| DataGuard | Tariff „Pro“ with experts and an external information security officer | Demo available for booking |
| OPUS i (kronsoft) | Training and ongoing support in the rental agreement | Free standalone version |
| Secfix | internal ISO-27001 experts | Demo, free initial consultation |
| Vanta | Access to „expert partners“ | Free demo |
| verinice (SerNet) | SerNet Support, a partner network for consulting | free evaluation (30 or 60 days) |
A column titled „Automation level“ is intentionally missing: The extent to which a software solution actually triggers tasks and assigns evidence can only be determined through in-house testing.
Methodology: We read the official pages of the providers regarding products, standards, and hosting. Only what is stated in the text of an official provider page counts as „mentioned.“ Drata is missing because the website was blocked for automated requests; that says nothing about the product. We did not review contracts, certificates, functionality depth, or individual offers.
What stands out:
- Hosting in Germany or the EU: Four of the six providers explicitly mention a German or European location (SECJUR, OPUS i, Secfix, Vanta).
- Professional support is widespread: All six providers mention advice, experts, training, or a partner network. Ask in the test what extent this support includes for getting started.
- Verinice in transition: According to the manufacturer, sales of the classic open-source version end on December 31, 2026; new customers are referred to by verinice as cloud or on-premise.
Anyone who wants to edit multiple regulations in one platform and, if necessary, call in experts, will find this combination at SECJUR. However, a software is not a certification body. The same practical test applies to every provider: Can a requirement for a measure be assigned, the corresponding proof be kept up to date, and the process be presented in a comprehensible manner later?
FAQ: Compliance automation, ISMS software and ISO 27001 explained in a nutshell
What is compliance automation?
Software manages requirements, security measures, risks, and evidence centrally and links them together. This allows recurring tasks to be structured or partially automated.
Can software completely automate ISO 27001 compliance?
No. It speeds up documentation and verification, but does not decide on scope, measures, or residual risks.
Which tools help with ISO 27001 and NIS2?
Compliance platforms or ISMS tools that cover the required requirements and make it possible to assign proofs in a traceable manner are suitable. The key is to ensure a fit with your system landscape.
What should you pay attention to when choosing?
Test the level of automation, standard coverage, hosting, integrations, support, and price transparency using a real workflow.
What is a Statement of Applicability?
The applicability statement documents which Annex-A controls are taken into account and how selection or exclusion is justified.
Does ISO 27001 help with NIS2?
Yes, a well-maintained ISMS supports risk management and evidence management. You still need to implement additional obligations under NIS2 on your own.
Conclusion
Compliance automation is worthwhile where requirements, measures, and evidence must remain up-to-date on a permanent basis. First, document processes, responsibilities, and gaps in evidence, and then test it with a real case to see if a solution reduces maintenance costs. The technical basis for Microsoft 365 and Windows is described in our ISO-27001 checklist. Responsibility for effective information security remains with the company even with software.
On Windows Tweaks you will find time-saving tech guides for PC, software & Microsoft. For a stress-free digital everyday life. Already We have been tweaking Windows since 1998 and just don't stop!



