Asset & risk management depth
HiScout GRC Suite
The risk methodology is real and documented — risk analysis to BSI-Standard 200-3 and 100-3 with measure suggestions drawn from the cross-reference tables, and Grundschutz and BCM risk results flowing together in one tool down to IT implementation. I found no public information on incident handling with statutory reporting clocks or explicit protection-needs inheritance across asset relations, which is what separates a documented methodology from a backbone a certifier works inside.
verinice
The Grundschutz backbone is real: structure analysis with automatic inheritance of protection needs, object types for target objects, requirements, measures, threats and risks, and NIS2 incident deadlines of 24 hours, 72 hours and one month with the German implementation law's deviations incorporated. I found no public information on risk acceptance with named ownership or an export to the reporting authority, which keeps it out of the top band.