Kertos
A Munich-based no-code platform that automates GDPR, ISO 27001, SOC 2, TISAX, and NIS2 compliance evidence-gathering for European companies.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Kertos builds a no-code compliance automation platform aimed at fast-growing European companies that need to demonstrate adherence to GDPR, ISO 27001, SOC 2, TISAX, NIS2, and the EU AI Act simultaneously. The platform connects to a company’s existing SaaS and cloud stack, continuously pulls evidence for control requirements, and generates audit-ready documentation, reducing the manual spreadsheet-and-screenshot work that compliance teams typically do by hand.
The company’s differentiator is regional: rather than building a generic US-style GRC tool and retrofitting European frameworks, Kertos was built compliance-first for the overlapping, often-conflicting patchwork of EU regulations, including newer requirements like NIS2 and the EU AI Act that many larger incumbents have been slower to support natively.
Founded in Munich in November 2021 by Kilian Schmidt, Johannes Hussak, and Alexander Prams, Kertos raised a €4M seed round in 2023 and a €14M Series A in September 2025 led by fintech investor Portage, with Pi Labs, Redstone, 10x Founders, and Seed+Speed Ventures also participating.
Innovation Matrix Assessment
Two funding rounds and rapid framework coverage expansion (GDPR to NIS2 and EU AI Act) in under four years shows steady, if not breakneck, product iteration.
Automating evidence collection for overlapping EU frameworks addresses a real, recurring compliance-team burden, though the underlying workflow is not fundamentally new.
A €14M Series A led by a known fintech investor in late 2025 is genuine momentum, but the company remains a regional player without disclosed customer-count scale.
Compliance automation is a crowded, well-established category; Kertos's EU-first framework coverage is a meaningful niche angle rather than a category redefinition.
No independent audits, analyst reports, or named customer case studies with measured outcomes were found; effectiveness claims are vendor-sourced.
NIS2 and EU AI Act enforcement are ongoing multi-year processes, keeping demand for EU-specific compliance tooling durable through the next few years.
Why CISOs Should Care
Gives compliance and security teams at EU-headquartered or EU-operating companies a single system of record for GDPR, ISO 27001, SOC 2, TISAX, NIS2, and EU AI Act evidence instead of juggling separate trackers per framework.
What Makes It Different
Built compliance-first around the specific, overlapping combination of EU regulatory frameworks rather than adapting a US-centric SOC 2/GDPR tool after the fact.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
An Incremental Innovator: a well-funded, EU-focused compliance automation vendor solving a real operational pain point in a crowded category, without evidence yet of category-defining differentiation.
Editorial Note: Claims vs. Verified Findings
Funding amounts and investor names are independently verifiable via press coverage; specific efficacy claims (e.g., time saved per audit) come only from company materials.
Sources
Alternatives to Kertos
Chainalysis
The dominant, category-defining incumbent in blockchain analytics -- broad government and financial-institution adoption, a decade-plus track record, and…
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.