Asset & risk management depth
DataGuard ISMS
The asset register with owners, tagging, bulk import and asset-to-risk linking, plus a risk distribution matrix, pre-built risk and measure libraries and mitigation tracking with assigned tasks, is a working asset-and-risk core. Incident handling appears only as configurable workflows and a security-incidents module, and we found no public information on statutory reporting clocks (NIS2 24h/72h), a documented risk methodology, or inheritance of protection needs across the visualized asset dependencies.
SECJUR Digital Compliance Office (ISMS)
The ISMS product page presents SECJUR's own certifications, not the customer's ISMS: no asset inventory, risk methodology, treatment tracking, protection-needs inheritance, or incident workflows with NIS2 24h/72h clocks appear anywhere in the evidence. The deepest operational capability evidenced is task management and a policy generator — ticket-system level, not a risk backbone; NIS2/DORA exist only as framework content claims.