Asset & risk management depth
ISMS.online
A 'Dynamic Risk Register & Treatment' and a one-line 'automated risk assessments' claim are all the risk backbone evidence there is: no asset inventory, no documented methodology, no protection-needs inheritance, and no incident handling — the only 24-hour target anywhere is ISMS.online's own privacy promise about their breach, not a product feature for mine. Above a flat list, nowhere near a certifier-grade ISMS core.
verinice
This is a real risk backbone: an ISMS built on BSI IT-Grundschutz methodology with automatic protection-needs inheritance across asset relations, object types running from target objects through requirements and measures to threats and risks, and NIS2 incident handling wired to the statutory clocks — report after 24 hours, situation report after 72 hours, final report after one month. Risk management per NIS2 Article 21 is integrated into both the Grundschutz and ISO 27001 domains, and ISO 27005 sits in the covered standards. What I could not find is risk acceptance with a named owner — who accepted which residual risk stays unevidenced.