Asset & risk management depth
ISMS.online
The evidence shows a 'Dynamic Risk Register & Treatment' and an 'automated risk assessments' marketing line, but nothing on asset inventory, a documented risk methodology, protection-needs inheritance, or incident workflows with statutory clocks — the only '24 hours' quote is the vendor's own breach-notification promise about itself, not a customer-facing feature.
verinice
This is a documented-methodology product: automatic protection-needs inheritance in the structure analysis, ISO/IEC 27005 among the covered standards, NIS2 incident handling carrying the 24-hour, 72-hour and one-month statutory clocks, and a BCM domain for continuity. We found no public information on risk acceptance with named ownership or executive-level risk reporting, so the chain stops short of what a certifier reads upward.