Information Security
i-doit INDITOR ISMS
EU-Made Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by i-doit GmbH · www.i-doit.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
i-doit INDITOR ISMS is the ISMS module of i-doit GmbH's GRC Suite, sold in separate ISO, BSI and NIS-2 editions with a 30-day free trial. The scores run highest on information security management and on integrations and automation, both clustering at 6–7: protection-needs analyses at process level with automatic inheritance, threat assessment, and measure tracking with owners, deadlines and email notification, on a CMDB fed by LDAP/Active Directory, JDisc and OCS discovery and Nagios and Checkmk monitoring. Framework coverage spans 5–7 — German-regime depth (BSI IT-Grundschutz 200-standards, the NIS-2 implementation act, TISAX/VDA-ISA, BAIT/VAIT, B3S) set against per-edition packaging and no public information on cross-framework mapping or DORA. Audit readiness and controls and statement of applicability score 5–6 each, with no public information on audit-scoped evidence packs, auditor access roles or point-in-time reconstruction. The weakest marks are sovereignty at 3–4 and pricing transparency at 3–5: the cloud/SaaS variant appears only as an FAQ question without an answer in the captured text, and from-prices leave catalogs, optional modules and add-ons — the API included — without public prices.
Speaks for it
- Protection-needs analyses at process level with automatic inheritance into the infrastructure, threat assessment, and measure tracking with owners, deadlines and automatic email notification
- German-regime depth across BSI IT-Grundschutz 200-standards, the NIS-2 implementation act, TISAX/VDA-ISA, BAIT/VAIT, B3S, VdS 10000 and Kritis
- Feeds from the live estate through LDAP/Active Directory, JDisc and OCS discovery, Nagios and Checkmk monitoring, and importers for ServiceNow, Matrix42, ACMP, GLPI and VMware
- Revision-safe, versioned document management with centrally planned audits, documented results and automatic audit reports
- Published annual entry prices for all three editions (ISO ab 588 €/ Jahr, BSI ab 1.908 €/ Jahr, NIS-2 ab 1.908€/ Jahr) plus a 30-day free trial
Held against it
- Every edition price is a from-price, catalogs and extended modules are marked optional without public prices, and we found no public information on add-on prices — the API add-on included — so the real total is not computable from these pages
- The cloud/SaaS variant appears only as an FAQ question whose answer is not in the captured text, and we found no public information on hosting location, a data processing agreement or a subprocessor list
- The ISMS ships as separate ISO, BSI and NIS-2 editions, and we found no public information on one-control-many-frameworks mapping beyond the automatic ISO 27002 linking, or on DORA
- We found no public information on statutory reporting clocks (NIS-2 24h/72h), on risk acceptance with a named acceptor, or on generating a statement of applicability from live control status
- The captured pages give different figures for the add-on count — over 40 on one and more than 50 on another
Best for
- You build or run an ISMS in the BSI IT-Grundschutz tradition and want protection-needs analyses and measure tracking on a CMDB that documents your actual estate
- Your compliance scope is the German NIS-2 implementation act, TISAX/VDA-ISA, BAIT/VAIT, B3S or Kritis
- You need the risk register on your own infrastructure — on-premises deployment is offered
- Your environment already runs JDisc or OCS discovery, LDAP or Active Directory, Nagios or Checkmk monitoring, or OTRS/KIX/Zammad service desks
Avoid if
- You must budget the total cost from public pages before signing — these show only from-prices, with catalogs and modules marked optional per edition
- You plan to run the cloud/SaaS variant and need hosting location, a data processing agreement and a subprocessor list documented in advance — the captured pages pose the cloud question without an answer
- You must answer several frameworks from one control set — the editions are packaged per framework and we found no public information on cross-framework mapping beyond the automatic ISO 27002 linking
The scores
Asset & risk management depth
Show reasoningHide reasoning
How this is scored
The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.
0 — No ISMS substance; "information security" is a chapter in the marketing site.
3 — A flat risk list and an asset spreadsheet import; no treatment tracking, no inheritance, incidents live in the ticket system.
5 — Asset and risk management with configurable matrices and treatment tracking; basic incident handling; inheritance and aggregation need manual work.
8 — A real risk backbone: documented methodology (ISO 27005 or equivalent), inherited protection needs across asset relations, incident workflows with statutory reporting clocks (NIS2 24h/72h), risk acceptance with ownership.
10 — Risk management a certifier works inside: complete asset-risk-treatment chain with inheritance, continuity planning, incident reporting with authority export, and risk reporting the executive level actually reads.
The CISO
This is a genuine BSI-tradition backbone, not a marketing chapter: protection-needs analyses with automatic inheritance into the infrastructure, threat assessment, and measure tracking with named responsibilities, deadlines and email notification, all on a CMDB that holds the actual estate. Incident handling is documented ISO- and NIS2-conform with affected assets mapped to measures, but we found no public information on statutory reporting clocks or authority export, and no evidence of formal risk acceptance with a named acceptor. 5 1 2
The GRC Consultant
A real risk backbone rather than a checklist: protection-needs analysis at process level with automatic inheritance into the infrastructure, threat assessment, measure tracking with owners, deadlines and automatic notification, and incident handling that maps affected assets — all sitting on a CMDB that feeds itself from discovery tools. I found no public information on statutory reporting clocks such as NIS2 24h/72h workflows or formal risk acceptance with ownership, which the strongest products in this class show. 5 1 2
The Drafted IT Officer
The risk core looks genuinely usable for someone who inherited this job: protection-requirement analyses with automatic inheritance into the infrastructure, threat assessment, and measures with named owners, deadlines and automatic email reminders, on a BSI IT-Grundschutz 200-Standards backbone, with incidents documented ISO- and NIS2-conform and assets assigned. We found no public information on statutory reporting clocks (24h/72h) or a risk-acceptance step with ownership, which is what separates this from a certifier-grade register. 5 1 2
The Lead Auditor
The captured pages show a genuine risk backbone in the BSI tradition: protection-requirement analyses at process level with automatic inheritance into the infrastructure, threat assessment, measure tracking with owners and deadlines, and ISO/NIS-2-conform incident workflows that map affected assets. I found no public information on statutory reporting clocks such as NIS-2 24h/72h, authority export, or risk acceptance with ownership, which is what separates this from certifier-grade risk management. 5 1 2
The Evidence Integrator
Protection-needs analyses with automatic inheritance into the infrastructure, threat assessment and measure tracking sit on a genuinely deep CMDB asset base, and incidents are documented ISO- and NIS2-conform with affected assets mapped and measures derived. We found no public information on statutory reporting clocks such as NIS2 24h/72h deadlines, on a named risk methodology, or on risk acceptance with ownership, so the backbone is real but not complete. 5 1 2
The Skeptic
The core is real: protection-needs analyses with automatic inheritance into the infrastructure, threat assessment and measure tracking with owners, deadlines and e-mail notification, plus ISO- and NIS2-conform incident management with affected assets assigned. I found no public information on statutory reporting clocks or risk acceptance with named ownership, which keeps this below the full risk-backbone definition. 5 1 2
Controls, SoA & measures
Show reasoningHide reasoning
How this is scored
Control catalogs, statement of applicability, measure tracking and internal audit — whether the control side of the ISMS is operable or a checklist.
0 — A static control checklist; applicability, implementation status and evidence are the consultant's spreadsheet.
3 — Control catalogs with status fields, but no SoA generation, no measure ownership, no link between controls and risks.
5 — Controls linked to risks and measures with owners and due dates; SoA producible with manual assembly; internal audit supported by checklists.
8 — SoA on demand from live control status, measure tracking with delegation and escalation, internal audit workflows with findings management, controls carrying their own evidence.
10 — The control fabric as a living system: catalog updates versioned, SoA always current, audit programs with recurring schedules, and every control answerable with linked evidence at any moment.
The CISO
DIN EN ISO/IEC 27001 and 27002 catalogues are integrated with automatic 27002 linking, measures carry owners, due dates and automatic notification, and audit management generates reports automatically — more than a checklist. We found no public information on producing a statement of applicability from live control status, on delegation or escalation in measure tracking, or on findings management in internal audit workflows. 5 2
The GRC Consultant
A dozen-plus catalogs from ISO 27001/27002 through BSI IT-Grundschutz, TISAX/VDA-ISA, B3S, VAIT, BAIT and VdS 10000, with ISO 27002 automatically linked, measures carrying responsibilities and due dates, and audits planned, documented and reported centrally — the control side is operable, not a spreadsheet. I found no public information on generating a statement of applicability from live control status, or on delegation and escalation within measure tracking, which is exactly the reuse I need for my twelfth client. 5 2
The Drafted IT Officer
ISO 27001/27002 catalogs are integrated with ISO 27002 automatically linked, measures carry responsibilities, deadlines and automatic email notification, and gap analyses assign documents, maturity and responsibilities per control — enough to run the control side without a consultant's spreadsheet. We found no public information on statement-of-applicability generation from live status, or on delegation and escalation in measure tracking. 5 2
The Lead Auditor
ISO 27001/27002 catalogs are integrated with automatic linking, measures carry responsibilities, deadlines and automatic e-mail notification, and gap analyses assign maturity ratings and documents. I found no public information on generating a statement of applicability from live control status, on delegation or escalation in measure tracking, or on findings management in the audit workflows, so the control side reads as operable but not self-generating. 5 2
The Evidence Integrator
Risks, measures and controls form one linked module with owners, deadlines and automatic email notification, backed by a broad catalog set from ISO 27001/27002 to BAIT, VAIT, TISAX/VDA-ISA, B3S and BSI Standard 200-1, plus central audit management with automatic audit reports. We found no public information on statement-of-applicability generation from live control status, on measure delegation or escalation, or on audit findings management; catalogs are also marked optional per edition. 5 2
The Skeptic
ISO 27001/27002 catalogs are integrated with automatic linking, measures carry responsibilities and deadlines, and audits are planned with results documented and reports generated automatically. I found no public information on statement-of-applicability generation, on delegation or escalation in measure tracking, or on audit findings management beyond documenting results. 5 2
Framework & standard coverage
Show reasoningHide reasoning
How this is scored
Which regimes the product actually operationalizes — ISO 27001, NIS2, TISAX/VDA ISA, DORA, BSI IT-Grundschutz, SOC 2 — and whether one control maps across them or each framework is a fresh island.
0 — One framework, hard-coded; anything else is "on the roadmap".
3 — Two or three frameworks as separate checklists; the same control is answered once per framework.
5 — The major regimes for its market with partial cross-mapping; newer regimes (NIS2, DORA) present as content packs of varying depth.
8 — Broad current coverage including NIS2/TISAX/DORA where relevant, one-control-many-frameworks mapping, and visible maintenance as regimes evolve.
10 — Framework coverage as a living product: dozens of regimes, genuine multi-compliance mapping on one data basis, per-industry profiles, and documented update cadence when the standard moves.
The CISO
The catalogue breadth is real and current for the German market — ISO 27001/27002, BSI IT-Grundschutz 200-standards, a full mapping of the NIS-2 implementation act, TISAX/VDA-ISA, B3S, Kritis, BAIT, VAIT, VdS 10000 and DSGVO. The editions are packaged per framework (ISO, BSI, NIS-2), and we found no public information on a documented update cadence when a standard moves, which keeps the shared-data-basis multi-compliance claim short of the top band. 5 2 4
The GRC Consultant
Coverage is broad and current for the German-speaking market: separate ISO, BSI and NIS-2 editions, full mapping of the German NIS-2 implementation act, and a long tail of sector catalogs including TISAX, B3S, VAIT/BAIT and Kritis, running on a shared data basis with the CMDB. The per-framework edition structure suggests each regime is bought and answered separately, and I found no public information on DORA or on a documented update cadence when standards move. 5 2 1
The Drafted IT Officer
The German regimes are covered deeply: BSI IT-Grundschutz 200-Standards, TISAX/VDA-ISA, BAIT/VAIT, B3S, ISO 9001/27019, VdS 10000 and more, plus a full depiction of the German NIS-2 implementation act — that last one reads as real regime maintenance rather than a static checklist. We found no public information on DORA or on explicit one-control-many-frameworks mapping beyond the shared data basis. 5 2 4
The Lead Auditor
The catalog list is broad and current for its market — ISO 27001/27002, the NIS-2 implementation act, TISAX/VDA-ISA, BSI Standard 200-1, BAIT/VAIT, B3S, KRITIS, DSGVO, VdS 10000, ISO 9001/27019 — offered on a shared data basis across the suite. I found no public information on DORA, on one-control-many-frameworks mapping beyond the automatic ISO 27001/27002 linking, or on a documented update cadence as regimes evolve. 5 2 1
The Evidence Integrator
Coverage is broad and current for its market — ISO 27001/27002, BSI IT-Grundschutz with the 200-standards, full mapping of the NIS-2 implementation act, TISAX/VDA-ISA, B3S, Kritis, DSGVO and more. But the product ships as separate ISO, BSI and NIS-2 editions, and we found no public information on one-control-many-frameworks mapping across those editions; DORA is also absent from every captured list. 5 2 4
The Skeptic
The German-market spread is genuine: BSI IT-Grundschutz 200-standards, B3S, TISAX/VDA-ISA, VAIT, BAIT, VdS 10000, ISO 9001/27019, Kritis and a claimed full depiction of the NIS-2 implementation act. But the ISMS is sold as separate ISO, BSI and NIS-2 editions, and I found no public information on one-control-many-frameworks mapping or on update cadence when a standard moves — the automatic ISO/IEC 27002 linking is the only cross-link evidenced. 5 2 4
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators, evidence attachments per control; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous evidence status per framework and scope, exportable proof packs an external auditor accepts as-is, and a defensible answer to "show me the state on date X".
The CISO
Documents are managed revision-safely with versioning and templates, audits are planned centrally with results documented and reports generated automatically, and gap analyses carry maturity assessments with responsibilities and document assignment. We found no public information on audit-scoped evidence packs on demand, dedicated auditor access roles, or reconstructing the state of a scope on a given date. 5 1
The GRC Consultant
Revision-safe document versioning, automatic audit report generation, traceable documentation for internal and external audits, and evidence assignment in the NIS-2 checklist give a credible trail. I found no public information on auditor access roles or on assembling audit-scoped evidence packs on demand, so the full audit file still looks like assembly work before each review. 5 2 1
The Drafted IT Officer
Audits are steered centrally with automatic audit reports, documents are managed revision-safe with versioning and templates, and gap analyses tie responsibilities and documents to controls — a working audit file, not screenshots. We found no public information on audit-scoped evidence packs on demand, auditor access roles, or an answer to "show me the state on date X". 5 2 1
The Lead Auditor
Documents are managed revision-safe with versioning, audits are planned and documented centrally with automatically generated audit reports, and the ISO path advertises traceable documentation for internal and external audits. I found no public information on audit-scoped evidence packs on demand, auditor access roles, or point-in-time reconstruction of control status — the answer to "show me the state on date X" is not evidenced. 5 2 1
The Evidence Integrator
Revision-safe, versioned document management with templates and imports, traceable documentation for internal and external audits, evidence assignment in the NIS-2 checklist, and automatic audit report generation are all evidenced. We found no public information on audit-scoped evidence packs on demand, auditor access roles, or reconstructing the state as of a given date. 5 2 1
The Skeptic
Revision-safe, versioned document management, automatic audit reports, traceable documentation for internal and external audits, and evidence assignment in the NIS-2 checklist are all stated plainly. I found no public information on audit-scoped evidence packs, auditor access roles, or any defensible answer to "show me the state on date X". 5 2 1
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, CMDB, ticketing, scanners, API — and automates evidence collection instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing, CMDB or SSO); automation is reminders and recurrence.
8 — Real connector set (Jira/ServiceNow-class ticketing, CMDB, cloud and endpoint sources), webhooks, SSO/SCIM, automated evidence tests with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, continuous control monitoring against the live estate, and automation that measurably removes the recurring toil rather than renaming it.
The CISO
The platform feeds from the live estate rather than re-typing: JDisc and OCS discovery, imports from ServiceNow, Matrix42, ACMP, GLPI and vmware, LDAP and Active Directory for user and rights management, Nagios and Checkmk monitoring, an API add-on for automated read, write and update, plus no-code scheduled automations and AI add-ons. We found no public information on webhooks, SCIM provisioning, or automated evidence tests with human review. 2 1
The GRC Consultant
The platform feeds from a real estate: directory services via LDAP and Active Directory, discovery via JDisc and OCS, monitoring via Nagios and Checkmk, ticketing via OTRS, KIX and Zammad, importers from ServiceNow and Matrix42, an API add-on for automated read/write/update, and no-code scheduled automations. I found no public information on webhooks, SSO/SCIM or automated evidence tests with human review, and the captured pages give different figures for the add-on count, over 40 versus 50+. 2 1
The Drafted IT Officer
This feeds from the real IT estate: LDAP/Active Directory, an API add-on for automated read/write/update, imports from ServiceNow, Matrix42, ACMP, VMware and others, JDisc/OCS discovery, Nagios/Checkmk monitoring, service-desk connectors and no-code flow automations — more than re-typing, and it can run alongside the day job. We found no public information on webhooks, SSO/SCIM, or automated evidence tests with human review. 2 1
The Lead Auditor
The estate feeds in through directory integration (LDAP/Active Directory), discovery tools (JDisc, OCS), importers for Excel, ServiceNow, Matrix42, ACMP, GLPI and VMware, monitoring connections to Nagios and Checkmk, service-desk compatibility with OTRS, KIX and Zammad, and a read/write API add-on plus no-code automations. The ServiceNow-class systems appear as import sources rather than evidenced live connectors, and I found no public information on webhooks, SSO/SCIM, or automated evidence collection with human review. 2 1
The Evidence Integrator
The estate connects: directory services via LDAP/Active Directory, automated asset feed from discovery systems like JDisc and OCS, monitoring via Nagios and Checkmk, imports from ServiceNow, Matrix42, ACMP and GLPI, service desk compatibility with OTRS, KIX and Zammad, an API add-on for automated read/write/update, and no-code Flows automation. We found no public information on webhooks, SSO/SCIM, or automated evidence tests with continuous control checks against the live estate — and the API itself is positioned as an add-on rather than a core capability, which is exactly the kind of gate I distrust. 2 1
The Skeptic
A working estate connection exists: LDAP/Active Directory, JDisc and OCS inventory, imports from ACMP, GLPI, VMware, Matrix42 and ServiceNow-class sources, Nagios/Checkmk monitoring, OTRS/KIX/Zammad ticketing, and no-code automations. The API ships as a paid add-on rather than core, I found no public information on webhooks or SSO/SCIM, and the captured pages give different figures for the add-on ecosystem — "Über 40" on one and "über 50" on another — which keeps this short of the real-connector-set definition. 1 2 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the security posture of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. The risk register is itself a target.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your risk register.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The CISO
The vendor is a German GmbH registered in Düsseldorf with an EU parent and offers both on-premises operation and a purchase licence alongside rental licences, so my risk register can stay inside my own walls under German law. We found no public information on where the cloud variant is hosted, on a published data processing agreement, or on subprocessors — for the system holding the register, that documentation gap keeps it low. 5 2 4 1
The GRC Consultant
The vendor is a German GmbH in Düsseldorf with German court registration and VAT ID, and the product runs on-premises or in the cloud — on-premises lets the risk register stay inside my client's own perimeter, which matters for public-sector work. For the cloud variant I found no public information on hosting location, a data processing agreement, or any subprocessor list, so the SaaS chain is undocumented. 2 4 1
The Drafted IT Officer
A German GmbH in Düsseldorf, "Made in Germany" positioning and an on-premises deployment option mean my risk register can live in my own server room, which settles most of the jurisdiction question for me. But we found no public information on a published DPA, on subprocessors, or on where the cloud variant hosts — the captured FAQ page poses the cloud/SaaS question without including the answer in the captured text. 5 2 4 1
The Lead Auditor
The vendor is a German GmbH with German license terms for rental, purchase and support, and an on-premises deployment is offered, which can keep the risk register on the customer's own ground. I found no public information on where the cloud variant runs — the captured FAQ poses the cloud question without an answer in the text — nor on a published DPA or a subprocessor list, so the jurisdictional chain beyond the entity is undocumented. 2 4 1
The Evidence Integrator
A German entity in Düsseldorf with "Made in Germany" positioning and an on-premises deployment option means the risk register can live entirely on the buyer's own estate. However, the cloud/SaaS variant is raised only as a FAQ question with the answer not in the captured text, and we found no public information on hosting locations, a DPA, a subprocessor list or datacenter naming — subprocessor exposure is undocumented. 5 2 4 1
The Skeptic
A German entity with a complete imprint, terms for rental and purchase licenses, and an on-premises deployment option are solid ground for a system holding the risk register. But the cloud/SaaS variant appears as an FAQ question whose answer is not in the captured text, and I found no public information on hosting location, subprocessors, DPA or TOMs for the cloud path. 2 4 1
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, scale steps or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a certification project is a two-minute exercise.
The CISO
All three INDITOR editions carry public annual from-prices in euros — "ab 588 €/ Jahr" for ISO and "ab 1.908 €/ Jahr" for BSI and NIS-2 — with a 30-day free trial. Every figure is a from-price, catalogues and the purchase licence are marked optional, and we found no public information on add-on or scale-step pricing, so the real invoice for a 400-employee operation remains incomputable from the public pages. 5 1 2
The GRC Consultant
Three ISMS editions carry public annual starting prices — the ISO edition "ab 588 €/ Jahr", the BSI edition "ab 1.908 €/ Jahr" and the NIS-2 edition "ab 1.908€/ Jahr" — plus a 30-day free trial. But starting prices without the scale basis behind "ab", optional catalogs and extended modules per edition, and a separate purchase-license model leave the real invoice for a given client incomputable from public pages alone. 5 2
The Drafted IT Officer
Three editions carry public from-prices with the billing period stated — INDITOR ISO ab 588 €/ Jahr, INDITOR BSI ab 1.908 €/ Jahr, INDITOR NIS-2 ab 1.908€/ Jahr — plus a 30-day free trial, which is more than most of this market shows. Catalogs and add-ons are marked optional without public prices, so the real invoice for a working setup with the pieces I would actually need is not computable from these pages. 5
The Lead Auditor
All three INDITOR editions carry public annual prices with the billing period stated — "ab 588 €/ Jahr" for ISO, "ab 1.908 €/ Jahr" for BSI and NIS-2 — plus a 30-day free trial and rental, purchase and support licensed separately. I found no public information on add-on pricing for the API and automation add-ons, on user or entity scale steps, or on the cost of the modules marked optional per edition, so the real total is only partially computable. 5 2 4
The Evidence Integrator
All three editions carry real entry figures with the billing period stated — "ab 588 €/ Jahr" for INDITOR ISO, "ab 1.908 €/ Jahr" for INDITOR BSI and INDITOR NIS-2 — plus a 30-day free trial. But these are floor prices with no scale steps shown, and the captured pages give different figures for the add-on count (over forty on some, more than fifty on another) while we found no public information on any add-on price — including the API add-on — so the real total invoice is not computable from public pages. 5 1 2 1
The Skeptic
Three editions carry real annual entry prices with a 30-day free trial — "ab 1.908 €/ Jahr" for BSI, "ab 588 €/ Jahr" for ISO, "ab 1.908€/ Jahr" for NIS-2. Everything that decides the real invoice hides behind "ab" and "Optional": catalogues and several modules are optional per edition, and the add-on ecosystem including the API add-on carries no public prices, so a buyer cannot compute the total from these pages. 5 2 1
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 24 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 237 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 35 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 34 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 11 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (15)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.i-doit.com Checked 5 Oct 2026 +2 earlier captures: 21 Sep 2026, 11 Sep 2026 Details →
- 2 GRC suite overview www.i-doit.com Checked 5 Oct 2026 +3 earlier captures: 28 Sep 2026, 11 Sep 2026, 24 Aug 2026 Details →
- 3 Company page www.i-doit.com Checked 5 Oct 2026 Details →
- 4 Imprint www.i-doit.com Checked 5 Oct 2026 +3 earlier captures: 28 Sep 2026, 11 Sep 2026, 24 Aug 2026 Details →
- 5 INDITOR ISMS product page www.i-doit.com Checked 5 Oct 2026 +3 earlier captures: 28 Sep 2026, 16 Sep 2026, 24 Aug 2026 Details →
- 6 Privacy policy www.i-doit.com Checked 5 Oct 2026 Details →
- 7 Asset & risk management depth — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
- 8 Asset & risk management depth — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
- 9 Controls, SoA & measures — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
- 10 Framework & standard coverage — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
- 11 Framework & standard coverage — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
- 12 Audit readiness & evidence — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
- 13 Audit readiness & evidence — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
- 14 Integrations & automation — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
- 15 Integrations & automation — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →