Asset & risk management depth
ISMS.online
A "Dynamic Risk Register & Treatment" and "automated risk assessments" clear the flat-list bar, but the evidence evidences no asset inventory, no risk methodology, no protection-needs inheritance and no incident workflows with statutory clocks — the only 24h figure is the vendor's own breach promise about itself. That is a register with treatment tracking and nothing behind it a certifier can trace.
verinice
The Grundschutz backbone is real: structure analysis with automatic inheritance of protection needs, object types for target objects, requirements, measures, threats and risks, and NIS2 incident deadlines of 24 hours, 72 hours and one month with the German implementation law's deviations incorporated. I found no public information on risk acceptance with named ownership or an export to the reporting authority, which keeps it out of the top band.