Skip to content

Kertos

A Munich-based no-code platform that automates GDPR, ISO 27001, SOC 2, TISAX, and NIS2 compliance evidence-gathering for European companies.

Visit Website ↗ + Add to Compare Claim This Company
52/100Incremental Innovator

Overview

Kertos builds a no-code compliance automation platform aimed at fast-growing European companies that need to demonstrate adherence to GDPR, ISO 27001, SOC 2, TISAX, NIS2, and the EU AI Act simultaneously. The platform connects to a company’s existing SaaS and cloud stack, continuously pulls evidence for control requirements, and generates audit-ready documentation, reducing the manual spreadsheet-and-screenshot work that compliance teams typically do by hand.

The company’s differentiator is regional: rather than building a generic US-style GRC tool and retrofitting European frameworks, Kertos was built compliance-first for the overlapping, often-conflicting patchwork of EU regulations, including newer requirements like NIS2 and the EU AI Act that many larger incumbents have been slower to support natively.

Founded in Munich in November 2021 by Kilian Schmidt, Johannes Hussak, and Alexander Prams, Kertos raised a €4M seed round in 2023 and a €14M Series A in September 2025 led by fintech investor Portage, with Pi Labs, Redstone, 10x Founders, and Seed+Speed Ventures also participating.

Innovation Matrix Assessment

Innovation Velocity 6/10

Two funding rounds and rapid framework coverage expansion (GDPR to NIS2 and EU AI Act) in under four years shows steady, if not breakneck, product iteration.

Operational Value 6/10

Automating evidence collection for overlapping EU frameworks addresses a real, recurring compliance-team burden, though the underlying workflow is not fundamentally new.

Market Momentum 5/10

A €14M Series A led by a known fintech investor in late 2025 is genuine momentum, but the company remains a regional player without disclosed customer-count scale.

Category Disruption 4/10

Compliance automation is a crowded, well-established category; Kertos's EU-first framework coverage is a meaningful niche angle rather than a category redefinition.

Real-World Efficacy 4/10

No independent audits, analyst reports, or named customer case studies with measured outcomes were found; effectiveness claims are vendor-sourced.

Enduring Relevance 6/10

NIS2 and EU AI Act enforcement are ongoing multi-year processes, keeping demand for EU-specific compliance tooling durable through the next few years.

Why CISOs Should Care

Gives compliance and security teams at EU-headquartered or EU-operating companies a single system of record for GDPR, ISO 27001, SOC 2, TISAX, NIS2, and EU AI Act evidence instead of juggling separate trackers per framework.

What Makes It Different

Built compliance-first around the specific, overlapping combination of EU regulatory frameworks rather than adapting a US-centric SOC 2/GDPR tool after the fact.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

An Incremental Innovator: a well-funded, EU-focused compliance automation vendor solving a real operational pain point in a crowded category, without evidence yet of category-defining differentiation.

Editorial Note: Claims vs. Verified Findings

Funding amounts and investor names are independently verifiable via press coverage; specific efficacy claims (e.g., time saved per audit) come only from company materials.

Sources