{"id":24266,"date":"2026-09-23T09:00:00","date_gmt":"2026-09-23T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=24266"},"modified":"2026-09-29T09:12:47","modified_gmt":"2026-09-29T09:12:47","slug":"kertos-three-founders-turn-compliance-into-advantage","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/09\/23\/kertos-three-founders-turn-compliance-into-advantage\/","title":{"rendered":"Kertos: Three Founders Turn Compliance into an Advantage"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">8 min read<\/p>\n<p><strong>As a lawyer, Dr. Kilian Schmidt knew compliance mainly as a burden. In 2021, he founded Kertos in Munich with Johannes Hussak and Alexander Prams: a compliance automation platform that generates evidence for standards such as ISO 27001 and NIS2. Today Kertos has more than 75 employees and ranks 20th among the fastest-growing startups in DACH and Central and Eastern Europe.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"color:#69d8ed;text-transform:uppercase;letter-spacing:0.08em;font-size:0.82em;font-weight:700;margin:0 0 16px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">A problem born from his own working life.<\/strong> Kilian Schmidt experienced data protection work firsthand as a lawyer at Home24, TIER Mobility and Gorillas, and in 2021 turned that experience into a product of his own, together with Johannes Hussak and Alexander Prams.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">European rules as the starting point.<\/strong> The platform covers standards including ISO 27001, GDPR, NIS2, the EU AI Act and TISAX, and runs on European infrastructure.<\/li>\n<li style=\"margin-bottom:0;\"><strong style=\"color:#69d8ed;\">Rank 20 on the Sifted 100.<\/strong> On the Sifted 100 list for the DACH region and Central and Eastern Europe, Kertos ranks 20th with revenue growth of 248.91 percent over two years &#8211; the only compliance platform on the list.<\/li>\n<\/ul>\n<\/div>\n<p style=\"border-top:1px solid rgba(230,227,218,0.14);border-bottom:1px solid rgba(230,227,218,0.14);padding:14px 0;margin:28px 0;font-size:0.92em;color:#b8c5ce;\"><strong style=\"color:#69d8ed;\">Related:<\/strong> <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/\">NIS2 enforcement hits 29,500 German companies<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">A Lawyer with a Grievance<\/h2>\n<p>Kilian Schmidt encountered compliance from the side where the work actually piles up. He began his career at Home24 as Senior Legal Counsel and Group Data Protection Officer, then moved to the law firm Freshfields Bruckhaus Deringer before joining TIER Mobility. There, according to <a href=\"https:\/\/www.kertos.io\/en\/about-us\">Kertos&#8217;s company page<\/a>, he helped build out the legal and public-policy functions as the scooter rental company grew from operating in a single city to 65 and expanded its workforce from 50 to 800 employees. He later advised the delivery service Gorillas.<\/p>\n<figure class=\"evm-inline-figure inarticle-visual\" style=\"display:block;max-width:100%;width:100%;margin:28px auto;border-radius:8px;overflow:hidden;border:1px solid #69d8ed33;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/kertos-kilian-schmidt-quer-hero.jpg\" alt=\"Kertos co-founder and CEO Dr. Kilian Schmidt\" style=\"width:100%;height:auto;display:block;\" loading=\"lazy\"\/><figcaption style=\"font-size:.85em;color:#667;margin-top:.5em;font-style:italic;line-height:1.45;\">Dr. Kilian Schmidt worked as a lawyer at Home24, Freshfields, and TIER Mobility before founding Kertos. Image: Kertos<\/figcaption><\/figure>\n<p>This period is where the experience that still shapes Kertos today comes from. &#8220;When I started my career as a lawyer and legal counsel, compliance wasn&#8217;t exactly a passion,&#8221; Schmidt writes in an <a href=\"https:\/\/www.kertos.io\/en\/blog\/announcing-kertos-series-a-to-build-europes-compliance-desk\">open letter announcing the Series A<\/a>. He identified data subject access requests &#8211; where individuals want to know what data a company holds on them &#8211; as the most burdensome process under the GDPR (the EU&#8217;s General Data Protection Regulation).<\/p>\n<p>It was exactly this process that Schmidt set out to automate. What began as a single tool for handling data subject requests gradually grew into a full suite that today covers, among other things, ISO 27001, ISO 42001, NIS2, DORA, and TISAX. Schmidt had experienced compliance as a mandatory chore. Now he was building a tool for the people who fulfill that duty every day.<\/p>\n<p><strong>What is compliance automation?<\/strong> Compliance automation refers to software that continuously generates and verifies evidence for standards such as ISO 27001, GDPR, NIS2, or SOC 2 directly from a company&#8217;s systems. The goal is to let proof accumulate where teams actually work, rather than scrambling to assemble it right before an audit.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Three Founders from Munich<\/h2>\n<p>Schmidt didn&#8217;t found Kertos alone in 2021. Johannes Hussak and Alexander Prams already knew each other from a previous company and brought experience in engineering and the day-to-day realities of founding a startup. Kertos today operates out of Munich and Berlin.<\/p>\n<figure class=\"evm-inline-figure inarticle-visual\" style=\"display:block;max-width:100%;width:100%;margin:28px auto;border-radius:8px;overflow:hidden;border:1px solid #69d8ed33;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/kertos-gruender-cover-hero.jpg\" alt=\"Die drei Kertos-Gr\u00fcnder Kilian Schmidt, Johannes Hussak und Alexander Prams\" style=\"width:100%;height:auto;display:block;\" loading=\"lazy\"\/><figcaption style=\"font-size:.85em;color:#667;margin-top:.5em;font-style:italic;line-height:1.45;\">Kilian Schmidt, Johannes Hussak, and Alexander Prams founded Kertos in Munich in 2021. Image: Kertos<\/figcaption><\/figure>\n<p>For Hussak, Kertos is, according to the company, his third venture. He studied mechanical engineering and international management at the Technical University of Munich, completing a master&#8217;s degree in both, and went through UnternehmerTUM&#8217;s Manage&amp;More program. He then founded an e-commerce company and spent more than two years heading the innovation department at a Munich-based development firm.<\/p>\n<p>Prams started programming at age eleven and, by 16, was already contributing to a game engine. While studying computer science at the Technical University of Munich, he released two apps in the App Store; he later spent more than five years leading the AI and computer vision division at a Munich development company. In 2020, Hussak and Prams co-founded Aitaro GmbH together, a year before joining Schmidt to launch Kertos.<\/p>\n<p>Today the roles are clearly divided. Schmidt runs Kertos as CEO, Hussak oversees day-to-day operations as COO, and Prams leads the technology as CTO. A lawyer, an engineer, and a computer scientist &#8211; bringing together legal expertise, operations, and software within a single founding team.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">European Rules First<\/h2>\n<p>The founders put European rules at the very beginning. Schmidt explains the reasoning this way. &#8220;Compliance automation has long been dominated by providers optimized for North American frameworks. The European counterpart had to be built differently from the ground up, with European frameworks first and data sovereignty as the default. That&#8217;s exactly the position we wanted to claim when we started in Munich in 2021,&#8221; he said in mid-September in a <a href=\"https:\/\/www.kertos.io\/blog\/eu-spitze-compliance-automation\">statement on the Sifted ranking<\/a>.<\/p>\n<p>In its Series A letter, the company describes itself as &#8220;lawyer-founded, EU-native&#8221; &#8211; founded by lawyers and rooted in Europe. The platform is built for European law and runs on European infrastructure.<\/p>\n<p>Johannes Hussak knows the starting point at many companies. &#8220;Many companies still see data protection and compliance as a necessary evil. It is necessary, since there are laws that are binding for companies,&#8221; he said in early 2025 in an <a href=\"https:\/\/www.business-punk.com\/zwischen-regulierung-und-innovation-unterwegs-im-europaeischen-compliance-dschungel-mit-kertos\/\">interview with Business Punk<\/a>. In the same conversation, Schmidt outlined the counter-approach: &#8220;Seeing compliance not as a brake but as an accelerator for digital growth &#8211; that&#8217;s our goal with Kertos.&#8221;<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Capital for its own path<\/h2>\n<p>A seed round financed the start: in 2023, Kertos raised 4 million euros, according to <a href=\"https:\/\/www.munich-startup.de\/news\/kertos-sichert-sich-4-millionen-euro-in-seed-runde\">Munich Startup<\/a>. In 2024, funding from the European Union followed. Under the EUProFIT project, Kertos received 2.2 million euros, which it planned to use, according to its <a href=\"https:\/\/www.kertos.io\/blog\/kertos-kofinanziert-von-der-europaischen-union\">own statement<\/a>, to develop a knowledge graph, chatbot and autofill functions, and a compliance monitor, among other things. The goal was to make GDPR (General Data Protection Regulation) compliance easier for small and medium-sized enterprises.<\/p>\n<p>The Series A followed in September 2025. A total of 14 million euros flowed into the company, according to <a href=\"https:\/\/financefwd.com\/de\/kertos-14-millionen\/\">Finance Forward<\/a>, with fintech-focused investor Portage joining as a new backer. Existing investors PiLabs, Redstone, 10x Founders (led by Felix Haas) and seed + speed Ventures invested again, after Kertos had received around 5 million euros in earlier rounds. According to Finance Forward&#8217;s assessment, the sector is riding a global tailwind &#8211; around the same time, US-based provider Myriad AI also raised fresh capital.<\/p>\n<div style=\"overflow-x:auto;-webkit-overflow-scrolling:touch;margin:24px 0;\">\n<table style=\"width:100%;min-width:520px;border-collapse:collapse;font-size:0.92em;\">\n<thead>\n<tr style=\"border-bottom:2px solid #69d8ed;\">\n<th style=\"text-align:left;padding:12px 14px;\">Funding<\/th>\n<th style=\"text-align:left;padding:12px 14px;\">Amount<\/th>\n<th style=\"text-align:left;padding:12px 14px;\">Source<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom:1px solid rgba(230,227,218,0.12);\">\n<td style=\"padding:11px 14px;\">Earlier rounds<\/td>\n<td style=\"padding:11px 14px;\">around 5 million euros<\/td>\n<td style=\"padding:11px 14px;\">Finance Forward<\/td>\n<\/tr>\n<tr style=\"border-bottom:1px solid rgba(230,227,218,0.12);\">\n<td style=\"padding:11px 14px;\">EU funding EUProFIT, 2024<\/td>\n<td style=\"padding:11px 14px;\">2.2 million euros<\/td>\n<td style=\"padding:11px 14px;\">Kertos statement<\/td>\n<\/tr>\n<tr style=\"border-bottom:1px solid rgba(230,227,218,0.12);\">\n<td style=\"padding:11px 14px;\">Series A, September 2025<\/td>\n<td style=\"padding:11px 14px;\">14 million euros<\/td>\n<td style=\"padding:11px 14px;\">Finance Forward<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>With the Series A funds, Kertos aims to deepen its automation and expand what it calls the Trust Graph. The idea is for companies to reuse controls already vetted once with customers and suppliers, instead of producing fresh evidence for every business partner each time. AI agents handle the legwork, while the customer&#8217;s team retains sign-off authority.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">One Product for Many Rules<\/h2>\n<p>The platform brings information security, data protection, and AI management together in a single system. According to the company, it covers ISO 27001, ISO 42001, ISO 27701, GDPR, NIS2, the EU AI Act, SOC 2, TISAX, and C5. The agentic assistant KAIA drafts policies, reviews evidence, and monitors controls.<\/p>\n<p>In early 2026, Kertos had itself <a href=\"https:\/\/www.kertos.io\/en\/blog\/kertos-achieves-iso-42001-certification-setting-a-standard-for-governed-ai-systems\">certified to ISO 42001<\/a>, the international standard for AI management systems. The platform maps the same standard for its own customers.<\/p>\n<p>Kertos says it serves hundreds of customers. According to Finance Forward, these include companies such as Personio, Enpal, Flink, and Pliant. The software uses AI to check compliance with, among other things, the General Data Protection Regulation (GDPR) and AI regulation, automating the tasks this involves.<\/p>\n<p>Speaking to <a href=\"https:\/\/deutsche-wirtschafts-nachrichten.de\/716937\/ki-agenten-fuer-compliance-startup-kertos-will-den-mittelstand-mit-ki-compliance-von-der-buerokratie-befreien\">Deutsche Wirtschafts Nachrichten<\/a> in September 2025, CTO Alexander Prams named GDPR, ISO 27001, NIS2, and the AI Act as the frameworks the platform aims to be measured against.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Advisors and the Public Stage<\/h2>\n<p>Kertos is also growing through partnerships. At the end of April 2026, the company announced a partnership with compliance consultancy Axipro. According to the <a href=\"https:\/\/www.kertos.io\/blog\/kertos-and-axipro\">announcement of the partnership<\/a>, the consultants&#8217; expertise is meant to feed directly into product development.<\/p>\n<p>The founder himself takes the stage as an explainer. At the German Compliance Conference in Frankfurt, Schmidt appeared on the program on June 11, 2026, with a <a href=\"https:\/\/www.kertos.io\/events\/deutsche-compliance-konferenz\">talk on NIS2 and AI<\/a>, addressing the question of whether AI is more of a gateway for risk or a driver of better cybersecurity. On the company blog, he explains topics such as the <a href=\"https:\/\/www.kertos.io\/blog\/datenschutzvorfall-meldepflicht\">obligation to report data protection incidents<\/a> and the 72-hour deadline under Article 33 of the GDPR (the EU&#8217;s General Data Protection Regulation).<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Strong Rivals from the US<\/h2>\n<p>Kertos is entering a market that is growing fast and dominated by US vendors. Analyst firm Frost &amp; Sullivan <a href=\"https:\/\/www.gii.tw\/report\/fs1883968-compliance-automation-market-global.html\">expects<\/a> the global compliance automation market to grow by nearly 40 percent annually between 2024 and 2029. Among the leading providers, it counts Vanta and Drata. Vanta is used by more than 16,000 companies, <a href=\"https:\/\/aijourn.com\/vanta-named-a-leader-among-governance-risk-and-compliance-platforms-in-first-ever-inclusion\/\">according to its own figures<\/a>, while Drata supports more than 8,500 organizations, according to <a href=\"https:\/\/www.gartner.com\/reviews\/market\/devops-continuous-compliance-automation-tools\">Gartner Peer Insights<\/a>.<\/p>\n<p>This pace has a downside. In March 2026, <a href=\"https:\/\/techcrunch.com\/2026\/03\/22\/delve-accused-of-misleading-customers-with-fake-compliance\/\">TechCrunch reported<\/a> on allegations against US provider Delve. Its platform is said to have lulled customers into a false sense of security with fabricated evidence. Delve denied the allegations, stressing that only independent auditors issue audit reports. Adam Shnider of audit service provider Coalfire <a href=\"https:\/\/coalfire.com\/the-coalfire-blog\/fraudulent-grc-allegations-cautionary-tale-or-wake-up-call\">subsequently described<\/a> a market in which some platforms compete primarily on price and speed.<\/p>\n<p>For providers like Kertos, this is a litmus test. An automatically generated piece of evidence is only as good as an auditor&#8217;s trust in it. Kertos points to customer case studies. Desktop-as-a-service provider Designair passed its first ISO 27001 audit without any deviations, roughly six months after the project began, <a href=\"https:\/\/www.kertos.io\/success-stories\/designair-iso-27001-audit-bestanden-ohne-abweichungen\">according to Kertos<\/a>. Such case reports have not been independently verified.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Evidence from everyday work<\/h2>\n<p>On September 22, 2026, Kertos and Aikido Security announced a strategic partnership. Aikido was founded in Ghent, Belgium, and offers a software security platform that, according to the joint announcement, is used by more than 150,000 teams, including Revolut, SoundCloud, Deel, and Niantic.<\/p>\n<p>&#8220;Evidence is generated where the work actually happens,&#8221; Schmidt said in the <a href=\"https:\/\/www.news-bloggen.de\/id-107471\">announcement of the partnership<\/a>. A spreadsheet filled in three weeks before the audit, he added, is the wrong place for that. Eric Gallegos, Head of Tech Alliances at Aikido Security, added: &#8220;Development teams fix security issues where they originate: in the code and in the pipeline.&#8221;<\/p>\n<p>The integration pulls findings from Aikido&#8217;s vulnerability management into Kertos, where they serve as evidence for ISO 27001, SOC 2, and NIS2. According to <a href=\"https:\/\/www.kertos.io\/en\/blog\/kertos-aikido-integration\">Kertos&#8217;s technical description<\/a>, the connection is read-only and changes nothing within Aikido. It refreshes once a day in the background, or on demand.<\/p>\n<p>Kertos checks daily whether the remediation deadlines set by the customer have been exceeded. The result, pass or fail, is logged as audit evidence against the ISO 27001 requirements for vulnerability management, secure development, and security testing. According to Kertos, this is meant to let documentation emerge as a byproduct of daily work.<\/p>\n<p>Since September 2026, the two companies have been jointly marketing their platforms. Aikido is already connected to compliance platforms from the US market; with Kertos, both ends of the process now sit with European vendors. Schmidt expects European customers and their auditors to increasingly take note of that. Whether the combination actually shortens the path to certification remains, for now, a claim made by the two companies themselves.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Rank 20 in the Sifted 100<\/h2>\n<p>In mid-September 2026, the Sifted 100 for DACH and Central and Eastern Europe was published &#8211; a ranking of the fastest-growing startups across 25 countries. According to its <a href=\"https:\/\/www.kertos.io\/en\/press\/kertos-ranks-20-sifted-100-eu-leader-compliance-automation\">own press release<\/a>, Kertos placed 20th and is the only compliance platform on the list.<\/p>\n<p>The ranking is based on revenue growth over two years. Kertos reports 248.91 percent growth, compared with a list-wide average of 157.61 percent according to the same release.<\/p>\n<p>The team has also grown fast. At the time of the study, 32 people worked at Kertos; according to the company, that number has since risen to more than 75. Per the company website, around 40 percent of employees are women, and the team spans 21 nationalities.<\/p>\n<p>&#8220;I&#8217;m proud of the number,&#8221; Schmidt said of the ranking. He said he&#8217;s even prouder of the path that got them there, since &#8220;none of it was down to chance.&#8221; Whether the pace holds remains to be seen &#8211; the list measures revenue growth over two years and says nothing about profitability.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What others can take away<\/h2>\n<p>Kertos&#8217; story shows how a company can grow out of firsthand experience with an annoying problem. Schmidt knew the workload behind data subject requests and audits from his time as a lawyer, while Hussak and Prams brought the expertise to turn that into software. The result was software designed to generate evidence from ongoing operational processes.<\/p>\n<p>For security officers, the thinking behind the Aikido integration is particularly interesting. If evidence is generated daily from the development teams&#8217; work, the last-minute scramble before an audit shrinks considerably.<\/p>\n<p>Whether European vendors actually have an edge with auditors remains an open question. Kertos bet on this back in 2021. The answer will come from its customers&#8217; audits in the years ahead.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Who founded Kertos?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Dr. Kilian Schmidt, Johannes Hussak, and Alexander Prams founded Kertos in Munich in 2021. Schmidt serves as CEO, Hussak as COO, and Prams as CTO. The company operates out of Munich and Berlin.<\/p>\n<\/details>\n<details>\n<summary><strong>What does the integration with Aikido Security provide?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The integration pulls findings from Aikido&#8217;s vulnerability management as evidence for ISO 27001, SOC 2, and NIS2. It is read-only and refreshes once daily or on demand. Kertos checks whether the required remediation deadlines were met.<\/p>\n<\/details>\n<details>\n<summary><strong>How fast is Kertos growing?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">In Sifted&#8217;s 100 for the DACH region and Central and Eastern Europe 2026, Kertos ranks 20th with revenue growth of 248.91 percent over two years. According to the company, the team grew from 32 employees at the time of the study to more than 75.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/10\/what-is-iso-27001-definition-certification-differences\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/was-ist-iso-27001-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">What Is ISO 27001? Definition, Certification, and Differences<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/17\/nis2-patchwork-four-states-face-eu-court\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/cover-hero-13-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">NIS2 Patchwork: Four States Face EU Court<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/en\/ai-act-from-2-august-transparency-before-high-risk\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/net-ai-act-ab-2-august-transparenz-vor-hochr-47522255-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">AI Act from 2 August: Transparency Before High Risk<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n<p style=\"font-style:italic;text-align:right;font-size:0.85em;margin-top:8px;\">Image source: AI-generated (September 2026)<\/p>\n","protected":false},"excerpt":{"rendered":"A lawyer, an engineer and a computer scientist are building a compliance platform based on European law in Munich. They rank 20th in the Sifted 100.","protected":false},"author":50,"featured_media":24240,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"compliance automation","_yoast_wpseo_title":"Kertos: Three Founders Turn Compliance into an Advantage","_yoast_wpseo_metadesc":"A lawyer, an engineer and a computer scientist are building a compliance platform based on European law in Munich. They rank 20th in the Sifted 100.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"hermes-content-st-translate-260929|2026-09-29T09:09:45Z||ttl=120","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"en","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["kertos-drei-grunder-machen-compliance-zum-vorsprung"],"footnotes":""},"categories":[3,217],"tags":[227],"class_list":["post-24266","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","category-innovation","tag-reboot-germany"],"evm_reading_time_minutes":14,"wpml_language":"en","wpml_translation_of":24184,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24266","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=24266"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24266\/revisions"}],"predecessor-version":[{"id":24318,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24266\/revisions\/24318"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/24240"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=24266"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=24266"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=24266"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}