Asset & risk management depth
ISMS.online
A "Dynamic Risk Register & Treatment" clears the flat-list bar, but nothing in the evidence evidences an asset inventory, a documented risk methodology, inherited protection needs, or incident workflows with statutory clocks — the only 24-hour figure on record is the vendor's own privacy-policy promise, not a product feature. The supply-chain module gestures at third-party risk; the ISMS core stops at register-plus-treatment.
verinice
The BSI methodology is implemented as real objects — targets, requirements, measures, threats, risks — with automatic protection-needs inheritance and supporting structural analysis, and the NIS2 domain carries the statutory clocks (report after 24 hours, situation report after 72 hours, final report after one month). Risk management per NIS2 Article 21 is documented as integrated into both the Grundschutz and ISO 27001 domains. We found no public information on risk acceptance with named ownership or executive-level risk reporting.