Asset & risk management depth
ISMS.online
There is a 'Dynamic Risk Register & Treatment' and a claim of automated risk assessments, so treatment tracking exists — above the flat-list floor. But the evidence shows no asset inventory, no risk methodology, no protection-needs inheritance, and no incident workflows with statutory clocks; NIS2 appears only as a domain label, and the quoted 24-hour breach target is ISMS.online's own privacy-policy promise about their handling, not a product feature.
verinice
A genuine risk backbone: BSI IT-Grundschutz methodology end to end with structure analysis, protection-needs definition, automatic protection-need inheritance across asset relations, threats and risks as first-class objects, and NIS2 incident workflows carrying the statutory 24-hour and 72-hour clocks. I found no public information on risk acceptance with named ownership or executive-level risk reporting, so I stop short of the top bench.