# Kopexa > Kopexa is an AI-powered GRC (Governance, Risk & Compliance) platform for small and medium-sized enterprises (SMEs). It automates Information Security Management Systems (ISMS) and compliance management for ISO 27001, NIS2, GDPR, TISAX, DORA, VdS 10000, and BSI IT-Grundschutz in a single platform. ## Key Facts - 13+ frameworks supported: ISO 27001, TISAX, NIS2, DORA, GDPR, SOC 2, BSI IT-Grundschutz, VdS 10000, CIS Controls, ISO 9001 - Pricing: starting from EUR 249/month (transparent, no hidden enterprise tiers) - 14-day free trial, no credit card required, self-serve signup at app.kopexa.com - Hosting: Germany (EU), 100% EU-sovereign, GDPR-compliant by design, no US cloud dependency - SOC 2 Type II certified - OSCAL-based (NIST standard) for machine-readable compliance - Open-source standard: KSPEC for compliance-as-code (https://github.com/kopexa-grc/kspec) - Agentic AI that creates risk scenarios, maps controls, and automates evidence collection (not a chatbot) ## Differentiators vs Competitors - Transparent pricing (DataGuard, Vanta, Drata, Secfix, Secjur all hide pricing) - 100% EU sovereignty (most US-based competitors run on US clouds) - Product-led growth: self-serve trial, no mandatory sales call - KSPEC open-source standard for compliance checks - Supports both self-service and partner/consultant delivery models ## Platform Modules - Risk Management: https://kopexa.com/en/risks - Policies: https://kopexa.com/en/policies - Asset Management: https://kopexa.com/en/asset-management - Vendor Management: https://kopexa.com/en/vendors - Incident Management: https://kopexa.com/en/incidents - Records of Processing Activities: https://kopexa.com/en/processing-activities - Data Subject Access Requests (DSAR): https://kopexa.com/en/dsar - Workforce (employee onboarding, recurring training, policy acknowledgements, knowledge base with per-department permissions, evidence linked to requirements; available from October 2026): https://kopexa.com/en/workforce ## Frameworks Catalog - ISO 27001: https://kopexa.com/en/catalog/iso-27001 - NIS2: https://kopexa.com/en/catalog/nis-2 - TISAX: https://kopexa.com/en/catalog/tisax - GDPR: https://kopexa.com/en/catalog/gdpr - DORA: https://kopexa.com/en/catalog/dora - VdS 10000: https://kopexa.com/en/catalog/vds-10000 ## Solutions by Company Size - Startups: https://kopexa.com/en/solutions/startups - Mid-Market (Mittelstand): https://kopexa.com/en/solutions/mittelstand - Enterprise: https://kopexa.com/en/solutions/enterprise ## Solutions by Industry - Automotive (TISAX, ISO 27001): https://kopexa.com/en/solutions/automotive - Financial Services (DORA, BaFin, NIS2): https://kopexa.com/en/solutions/finance - Critical Infrastructure (NIS2, BSI): https://kopexa.com/en/solutions/critical-infrastructure ## NIS2 Industry Calculators Free, open, industry-specific NIS2 affectedness assessments. Each calculator checks sector criteria (NIS2 Annex I/II), size thresholds (SME Recommendation 2003/361/EC Art. 2), and applicable KRITIS thresholds (BSI-KritisV) for the respective industry. Results include PDF report, threshold-level breakdown, and citation of legal sources. Each calculator page includes a detailed NIS2 guide for the industry (800+ words, cites relevant German/EU law articles, covers obligations, deadlines, fines, and industry-specific considerations). - Hub (all industries): https://kopexa.com/de/catalog/nis-2/rechner · https://kopexa.com/en/catalog/nis-2/rechner - Automotive-Zulieferer (Anhang II Nr. 10): https://kopexa.com/de/catalog/nis-2/rechner/automotive · https://kopexa.com/en/catalog/nis-2/rechner/automotive - Bäckerei (Anhang II Nr. 5): https://kopexa.com/de/catalog/nis-2/rechner/baeckerei · https://kopexa.com/en/catalog/nis-2/rechner/baeckerei - Brauerei (Anhang II Nr. 5): https://kopexa.com/de/catalog/nis-2/rechner/brauerei · https://kopexa.com/en/catalog/nis-2/rechner/brauerei - Chemieindustrie (Anhang II Nr. 7): https://kopexa.com/de/catalog/nis-2/rechner/chemie · https://kopexa.com/en/catalog/nis-2/rechner/chemie - Elektronik-Hersteller (Anhang II Nr. 10): https://kopexa.com/de/catalog/nis-2/rechner/elektronik · https://kopexa.com/en/catalog/nis-2/rechner/elektronik - Energieversorger (Anhang I Nr. 1): https://kopexa.com/de/catalog/nis-2/rechner/energieversorger · https://kopexa.com/en/catalog/nis-2/rechner/energieversorger - Fleischverarbeitung (Anhang II Nr. 5): https://kopexa.com/de/catalog/nis-2/rechner/fleischverarbeitung · https://kopexa.com/en/catalog/nis-2/rechner/fleischverarbeitung - IT-Dienstleister / MSP (Anhang I Nr. 8): https://kopexa.com/de/catalog/nis-2/rechner/it-dienstleister · https://kopexa.com/en/catalog/nis-2/rechner/it-dienstleister - Krankenhaus (Anhang I Nr. 5): https://kopexa.com/de/catalog/nis-2/rechner/krankenhaus · https://kopexa.com/en/catalog/nis-2/rechner/krankenhaus - Maschinenbau (Anhang II Nr. 10): https://kopexa.com/de/catalog/nis-2/rechner/maschinenbau · https://kopexa.com/en/catalog/nis-2/rechner/maschinenbau - Medizinproduktehersteller (Anhang II Nr. 5): https://kopexa.com/de/catalog/nis-2/rechner/medizinprodukte · https://kopexa.com/en/catalog/nis-2/rechner/medizinprodukte - Molkerei (Anhang II Nr. 5): https://kopexa.com/de/catalog/nis-2/rechner/molkerei · https://kopexa.com/en/catalog/nis-2/rechner/molkerei - Mühle / Getreideverarbeitung (Anhang II Nr. 5): https://kopexa.com/de/catalog/nis-2/rechner/muehle · https://kopexa.com/en/catalog/nis-2/rechner/muehle - Rechenzentrum / Colo (Anhang I Nr. 8): https://kopexa.com/de/catalog/nis-2/rechner/rechenzentrum · https://kopexa.com/en/catalog/nis-2/rechner/rechenzentrum - SaaS-Anbieter / B2B-Cloud (Anhang I Nr. 8): https://kopexa.com/de/catalog/nis-2/rechner/saas-anbieter · https://kopexa.com/en/catalog/nis-2/rechner/saas-anbieter - Tiefkühlkost-Hersteller (Anhang II Nr. 5): https://kopexa.com/de/catalog/nis-2/rechner/tiefkuehlkost · https://kopexa.com/en/catalog/nis-2/rechner/tiefkuehlkost - Wasserversorger (Anhang I Nr. 6): https://kopexa.com/de/catalog/nis-2/rechner/wasserversorger · https://kopexa.com/en/catalog/nis-2/rechner/wasserversorger ## NIS2 Threshold Database Open dataset of NIS2 and KRITIS thresholds from EU and German law. Licensed CC-BY-4.0. - Human viewer (DE): https://kopexa.com/de/datenbank/nis2-schwellenwerte - Human viewer (EN): https://kopexa.com/en/datenbank/nis2-schwellenwerte - Machine-readable JSON: https://kopexa.com/datenbank/nis2-schwellenwerte.json - License: CC-BY-4.0 (attribution required: Kopexa GmbH, kopexa.com) ## Blog (English) - [ISO 27001 Checklist: Step by Step to Certification](https://kopexa.com/en/blog/iso-27001-checkliste): ISO 27001 checklist with about 30 checkpoints for certification and ISMS setup, every step explained, free PDF download. - [Choosing ISMS Software: Requirements Catalog & Checklist](https://kopexa.com/en/blog/isms-software-auswaehlen-checkliste): Choosing ISMS software: requirements catalog with about 30 criteria, must-have vs nice-to-have, and a free checklist download. - [ISMS Software: Which One Helps with ISO 27001, TISAX and NIS2?](https://kopexa.com/en/blog/isms-software-iso-27001-tisax-nis2): ISMS software compared: selection criteria, features and costs for ISO 27001, TISAX and NIS2. The practical guide for your decision. - [ISO 27001 Certification Explained Simply: Process & Costs](https://kopexa.com/en/blog/iso-27001-zertifizierung-einfach-erklaert): What ISO 27001 certification means, who actually needs it, and how the process runs from Stage 1 to recertification, explained clearly for beginners. - [AI Dependency as a Compliance Risk: What the Anthropic Case Teaches Every CTO](https://kopexa.com/en/blog/ki-abhaengigkeit-compliance-risiko-anthropic-fall): A US decree cut off access to leading AI models overnight. Why AI dependency is a real compliance risk that belongs in NIS2, ISO 27001 and DORA. - [GDPR Subject Access Request: How to Answer a DSAR Lawfully](https://kopexa.com/en/blog/dsgvo-auskunftsanfrage-dsar-rechtssicher-beantworten): A DSAR (Data Subject Access Request) under Art. 15 GDPR must be answered within 30 days. We walk you through the 8-step workflow from identity verification to data extraction and redaction, and which grounds for refusal are legally defensible. - [What Is OSCAL? A Deep Dive Into Compliance as Code and BSI Grundschutz++](https://kopexa.com/en/blog/was-ist-oscal-bsi-grundschutz-plus-plus): OSCAL turns security controls into machine-readable data. BSI Grundschutz++ adopts it as its native core. We explain the architecture, PDCA methodology and what the January 1, 2026 standard switch means for your ISMS. - [NIS2 Germany: Complete Guide for International Companies (2026)](https://kopexa.com/en/blog/nis2-germany-guide-international-companies): Everything an international company with operations in Germany needs to know about NIS2 / NIS2UmsuCG: who is in scope, deadlines, registration with the BSI, fines, and how DORA and KRITIS fit in. - [Third-Party Risk: Make Your Suppliers Audit-Ready](https://kopexa.com/en/blog/lieferantenrisikomanagement-third-party-risk-2026): A practical guide to vendor risk management under NIS2, DORA and ISO 27001. With concrete checklists and documentation templates for your compliance team. - [AI Governance for SMEs: The Path to AI Act Compliance](https://kopexa.com/en/blog/ki-governance-kmu-eu-ai-act-2026): The EU AI Act will come into force in August 2026. Learn how, as an SME, you can systematically identify AI risks, integrate them into ISO 27001 and ISO 42001, and remain compliant. - [NIS2 Incident Response: The 72-Hour Reporting Obligation](https://kopexa.com/en/blog/vorfallmanagement-nis2-incident-response-kmu): Learn how to prepare your company for the new NIS2 reporting obligations and build a working incident response plan. - [What Is an ISMS? Definition, Examples and Build-Up Guide](https://kopexa.com/en/blog/isms-einfach-erklaert-leitfaden-informationssicherheit): ISMS definition, concrete mid-market examples, PDCA cycle, vulnerability management and a practical build-up guide. With ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 compared, plus fines and liability. - [Palantir: A Lesson in Vendor Risk Management](https://kopexa.com/en/blog/palantir-ein-lehrstueck-ueber-vendor-risk-management): Switzerland blocks Palantir, Germany pushes it through bypassing parliament. An analysis of devastating risks and the sell-out of digital sovereignty. - [NIS2 Executive Management: Training Obligation & Liability 2025](https://kopexa.com/en/blog/nis2-geschaeftsleitungsschulung): Mandatory training under NIS2: who is affected? What liability do directors face? All content, obligations & risks explained simply. Get informed now. - [Running Matomo in a Privacy-Compliant Way: How to Do It Without a Cookie Banner](https://kopexa.com/en/blog/matomo-datenschutzkonform-betreiben-so-geht-s-ohne-cookie-banner): Cookie banners are annoying? With Matomo you can finally run analytics in a privacy-compliant, banner-free way. Step-by-step guide plus audit evidence. - [5 Benefits of Automated Risk Analysis for Mid-Sized Companies](https://kopexa.com/en/blog/automatisierte-risikoanalyse-effizienz-sicherheit-mittelstand): Learn how automated risk analysis helps SMEs detect risks early, ensure compliance and improve decision-making. - [Compliance Software Costs for SMEs: Comparison & Kopexa](https://kopexa.com/en/blog/compliance-software-kosten-fuer-kmu): Guide to compliance software: features, pricing models, audit and certification costs for SMEs, including comparison. - [Incident Management for SMEs: What, How & Who Helps](https://kopexa.com/en/blog/vorfallmanagement-kmu-leitfaden): An SME guide to what incident management is, how to implement it, plus tools, reporting obligations, and risk management with Kopexa. - [NIS2: The Underestimated Obligation for SMEs and Suppliers](https://kopexa.com/en/blog/nis2-die-unterschaetzte-pflicht-fuer-mittelstand-und-zulieferer): NIS 2 obliges SMEs and suppliers to meet higher cybersecurity standards, reporting channels and ISMS integration for greater digital resilience. - [TISAX Roadmap for SMEs in the Automotive Industry](https://kopexa.com/en/blog/tisax-roadmap): Achieve the highest information security standards with TISAX certification. Your path to greater trust and competitive advantage! - [Why IT Security in 2025 Is Different from Ever Before](https://kopexa.com/en/blog/it-security-2025-automatisierung-cyberangriffe): Discover the cyber threats of 2025: AI and automation are challenging organisations. Are you ready for the paradigm shift? - [The Hidden Costs of Manual Compliance and How to Avoid Them](https://kopexa.com/en/blog/versteckte-kosten-manuelle-compliance): Manual compliance processes cost more than you think. Discover the hidden costs involved and how automation helps. - [Automotive Compliance: Mastering the Transformation](https://kopexa.com/en/blog/was-ist-automotive-compliance): How the automotive industry integrates ESG, cyber and supply chain compliance, and how digital solutions can reduce costs by up to 30%. - [Certification Roadmap: ISO 9001 to 27001](https://kopexa.com/en/blog/zertifizierungs-roadmap-reihenfolge-iso9001-iso27001): Certification roadmap for ISO standards: Start with ISO 9001, leverage synergies with ISO 14001/27001. Reduce implementation time by 50% and save costs. - [DevOps & GDPR: Anonymising Data Automatically](https://kopexa.com/en/blog/datenschutz-software-entwicklung-anonymisierung-neon-postgres): How to maintain GDPR compliance in DevOps: automated anonymisation and pseudonymisation, PostgreSQL RLS/data masking, CI/CD integration for risk-free testing. ## Blog (German) - [ISO 27001 Checkliste: Schritt für Schritt zur Zertifizierung](https://kopexa.com/de/blog/iso-27001-checkliste): ISO 27001 Checkliste mit rund 30 Prüfpunkten für Zertifizierung und ISMS-Aufbau, alle Schritte erklärt, kostenloser Download als PDF. - [ISMS Software auswählen: Anforderungskatalog & Checkliste](https://kopexa.com/de/blog/isms-software-auswaehlen-checkliste): ISMS Software auswählen: Anforderungskatalog mit rund 30 Kriterien, Muss vs. nice-to-have und Checkliste zum kostenlosen Download. - [ISMS Software: Welche hilft bei ISO 27001, TISAX und NIS2?](https://kopexa.com/de/blog/isms-software-iso-27001-tisax-nis2): ISMS Software im Vergleich: Auswahlkriterien, Funktionen und Kosten für ISO 27001, TISAX und NIS2. Der Praxis-Guide für deine Entscheidung. - [ISO 27001 Zertifizierung einfach erklärt: Ablauf & Kosten](https://kopexa.com/de/blog/iso-27001-zertifizierung-einfach-erklaert): Was die ISO 27001 Zertifizierung bedeutet, wer sie braucht und wie der Prozess von Stage 1 bis Rezertifizierung abläuft, verständlich erklärt für Einsteiger. - [KI-Abhängigkeit als Compliance-Risiko: Was der Anthropic-Fall jeden CTO lehrt](https://kopexa.com/de/blog/ki-abhaengigkeit-compliance-risiko-anthropic-fall): Ein US-Dekret sperrte über Nacht den Zugang zu führenden KI-Modellen. Warum KI-Abhängigkeit ein echtes Compliance-Risiko ist und in NIS2, ISO 27001 und DORA gehört. - [ISO 27001 und DSGVO: So stützt dein ISMS den Datenschutz](https://kopexa.com/de/blog/iso-27001-datenschutz): Wie ein ISO 27001 ISMS deine DSGVO-Pflichten stützt. 8 konkrete Empfehlungen für Art. 32 DSGVO, Meldepflichten und Nachweise. Praxisnah erklärt. - [Sovereign Washing: Wann ist eine Cloud wirklich europäisch?](https://kopexa.com/de/blog/sovereign-washing-souveraene-cloud-erkennen): Sovereign Washing erkennen: Wie du in 5 Schritten prüfst, ob ein Cloud-Anbieter echte digitale Souveränität liefert oder nur EU-Marketing macht. Mit Schrems-II-Bezug, US Cloud Act, BYOK und Vendor-Assessment-Checkliste für CISOs und Datenschutzbeauftragte. - [DSGVO-Auskunftsanfrage: Wie du eine DSAR rechtssicher beantwortest](https://kopexa.com/de/blog/dsgvo-auskunftsanfrage-dsar-rechtssicher-beantworten): Eine DSAR (Data Subject Access Request) muss innerhalb von 30 Tagen beantwortet werden. Wir zeigen dir den 8-Schritt-Workflow von Identitätsprüfung über Datenextraktion bis zur Redaktion und welche Ablehnungsgründe rechtssicher sind. - [Was ist OSCAL? Der Deep-Dive zu Compliance as Code und BSI Grundschutz++](https://kopexa.com/de/blog/was-ist-oscal-bsi-grundschutz-plus-plus): OSCAL macht Sicherheitskontrollen maschinenlesbar, BSI Grundschutz++ baut darauf auf. Wir zeigen dir Architektur, PDCA-Methodik und was der Standard-Wechsel zum 1. Januar 2026 für dein ISMS bedeutet. - [Third-Party Risk: Lieferanten audit-ready machen](https://kopexa.com/de/blog/lieferantenrisikomanagement-third-party-risk-2026): Praktischer Leitfaden für Vendor Risk Management unter NIS2, DORA und ISO 27001. Mit konkreten Checklisten und Dokumentationsmustern für dein Compliance-Team. - [KI-Governance für KMU: Der Weg zur AI-Act-Compliance](https://kopexa.com/de/blog/ki-governance-kmu-eu-ai-act-2026): Der EU AI Act tritt im August 2026 in Kraft. Erfahre, wie du als KMU KI-Risiken systematisch erfasst, in ISO 27001 und ISO 42001 integrierst und compliant bleibst. - [NIS2 Incident Response: Meldepflicht in 72 Stunden](https://kopexa.com/de/blog/vorfallmanagement-nis2-incident-response-kmu): Erfahre, wie du dein Unternehmen auf die neuen NIS2-Meldepflichten vorbereitest und einen funktionierenden Incident-Response-Plan aufbaust. - [Was ist ein ISMS? Definition, Beispiele und Aufbau-Leitfaden](https://kopexa.com/de/blog/isms-einfach-erklaert-leitfaden-informationssicherheit): ISMS Definition, konkrete Beispiele aus dem Mittelstand, PDCA-Zyklus, Schwachstellenmanagement und Aufbau-Anleitung. Mit ISO 27001, BSI IT-Grundschutz, TISAX und NIS2 im Vergleich, plus Bußgelder und Haftungsrisiken. - [Palantir: Ein Lehrstück über Vendor Risk Management](https://kopexa.com/de/blog/palantir-ein-lehrstueck-ueber-vendor-risk-management): Schweiz blockiert Palantir, Deutschland forciert es am Parlament vorbei. Eine Analyse über verheerende Risiken und den Ausverkauf digitaler Souveränität. - [NIS2 Schulung für Geschäftsleitung: Pflicht, Inhalte und Haftung](https://kopexa.com/de/blog/nis2-geschaeftsleitungsschulung): NIS2 Schulung der Geschäftsleitung ist Pflicht nach Art. 20: Wer ist betroffen, welche Inhalte gehören rein, welche Haftung droht ohne Nachweis. Mit Checkliste, Bußgeld-Cases und Praxis-Tipps für KMU und Mittelstand. - [Matomo datenschutzkonform betreiben – so geht’s ohne Cookie-Banner](https://kopexa.com/de/blog/matomo-datenschutzkonform-betreiben-so-geht-s-ohne-cookie-banner): Cookie-Banner nerven? Mit Matomo kannst du Analytics endlich datenschutzkonform und bannerfrei betreiben – Schritt-für-Schritt-Anleitung + Audit-Nachweis. - [5 Vorteile automatisierter Risikoanalyse für mittelständische Unternehmen](https://kopexa.com/de/blog/automatisierte-risikoanalyse-effizienz-sicherheit-mittelstand): Erfahre, wie automatisierte Risikoanalyse KMUs hilft, Risiken früh zu erkennen, Compliance zu sichern und Entscheidungen zu verbessern. - [Compliance‑Software Kosten für KMU: Vergleich & Kopexa](https://kopexa.com/de/blog/compliance-software-kosten-fuer-kmu): Leitfaden zu Compliance‑Software: Funktionen, Kostenmodelle, Audit‑ und Zertifizierungskosten für KMU, inklusive Vergleich. - [Vorfallmanagement für KMU: Was, wie & wer hilft](https://kopexa.com/de/blog/vorfallmanagement-kmu-leitfaden): Guide für KMU: Was Vorfallmanagement ist, wie du es umsetzt, plus Tools, Meldepflichten & Risikomanagement mit Kopexa. - [NIS2: unterschätzte Pflicht für Mittelstand und Zulieferer](https://kopexa.com/de/blog/nis2-die-unterschaetzte-pflicht-fuer-mittelstand-und-zulieferer): NIS 2 verpflichtet Mittelstand und Zulieferer zu höheren Cybersecurity-Standards, Meldewegen und ISMS-Integration für mehr digitale Resilienz. - [TISAX Roadmap für KMU der Automobilbranche](https://kopexa.com/de/blog/tisax-roadmap): Erreiche höchste Standards in der Informationssicherheit mit einer TISAX-Zertifizierung. Dein Weg zu mehr Vertrauen und Wettbewerbsvorteil! - [Warum IT-Security 2025 anders ist als je zuvor](https://kopexa.com/de/blog/it-security-2025-automatisierung-cyberangriffe): Erlebe die Cyberbedrohungen 2025: KI und Automatisierung fordern Unternehmen heraus. Bist du bereit für den Paradigmenwechsel? - [Die versteckten Kosten manueller Compliance und wie du sie vermeidest](https://kopexa.com/de/blog/versteckte-kosten-manuelle-compliance): Manuelle Compliance-Prozesse kosten mehr als du denkst. Erfahre, welche versteckten Kosten entstehen und wie Automatisierung hilft. - [Automotive Compliance: Transformation meistern](https://kopexa.com/de/blog/was-ist-automotive-compliance): Wie die Automobilindustrie ESG-, Cyber- und Supply-Chain-Compliance integriert und digitale Lösungen Kosten um bis zu 30 % senken können. - [Zertifizierungs-Roadmap: ISO 9001 bis 27001](https://kopexa.com/de/blog/zertifizierungs-roadmap-reihenfolge-iso9001-iso27001): Zertifizierungs-Roadmap für ISO Standards: Beginne mit ISO 9001, nutze Synergien zu ISO 14001/27001. Reduziere Implementierungszeit um 50% und spare Kosten. ## Contact & Sign-up - Demo: https://kopexa.com/en/contact/demo - Pricing: https://kopexa.com/en/pricing - Free trial: https://app.kopexa.com - Blog (EN): https://kopexa.com/en/blog - Blog (DE): https://kopexa.com/de/blog ## Company Kopexa GmbH, headquartered in Germany. Building the European GRC platform for SMEs. - Website: https://kopexa.com - App: https://app.kopexa.com - GitHub: https://github.com/kopexa-grc - KSPEC standard: https://github.com/kopexa-grc/kspec