01Continuous compliance instead of a one-off project
Traditionally, an ISMS is built as a project and, in organisational terms, ends with the certificate – yet the real work only begins afterwards. ISO/IEC 27001:2022 explicitly requires the management system to be maintained and continually improved; the certificate is valid within a three-year cycle with at least annual surveillance audits (ISO/IEC 17021-1). NIS2, too, is designed as a permanent obligation: risk management measures must be implemented, monitored and reviewed for effectiveness – binding in Germany since the German NIS2 implementation act (NIS-2-Umsetzungsgesetz) entered into force in December 2025. Managed GRC means running these recurring tasks not as ad-hoc engagements but as an ongoing service with a defined scope, cadence and reporting.
02Typical service components of a managed GRC model
At the core is ISMS operation: document control, tracking of measures, preparation of the management review and maintenance of evidence. Added to this are ongoing risk management (risk register, periodic reassessments, risk treatment plans), an internal audit programme in line with clause 9.2 of ISO/IEC 27001, plus metrics and reporting to the management level. The provider frequently also operates the GRC platform, including data maintenance and framework updates; external officer roles (such as information security officer or data protection officer) and audit support are offered on top. The exact scope varies considerably – the scope of services, the cadence and the client's duties to cooperate should be precisely defined in the contract.
03Why SMEs benefit in particular
According to Bitkom's study on the IT labour market, around 109,000 IT positions in Germany were unfilled in 2025; 85 percent of the companies surveyed report a shortage of IT professionals, and 79 percent expect the situation to worsen further. For small and medium-sized enterprises, a dedicated full-time GRC role is often neither economically viable nor fillable on the market – especially since the required knowledge spans several specialist areas, from interpreting standards and regulation to audit practice and tool expertise. A managed service pools these competencies in shared capacity, brings deputisation arrangements and experience from many audit cycles, and reduces the internal effort to a defined interface role. Decisions, resource approvals and the involvement of the business units remain internal, however – no model works entirely without in-house capacity.
04Distinction: traditional consulting vs. operational responsibility
Traditional consulting is limited in time and delivers recommendations, concepts and documents – implementation and upkeep remain with the client. In the managed model, by contrast, the provider assumes responsibility for the outcomes of defined operational processes: audits take place, risk assessments are up to date, reports are delivered. Two limits are essential: first, overall accountability cannot be delegated – under Art. 20 of the NIS2 Directive, management bodies must “approve” the risk management measures and “oversee their implementation”, and they can be held liable for infringements; likewise, an ISO 27001 certificate is issued to the organisation, not to the provider. Second, ISO/IEC 27001 requires objective and impartial internal audits – if the same provider operates the ISMS, this calls for a separation at the personnel or organisational level.
05Meaningful metrics for GRC operations
The obligation to measure is anchored in the standards: clause 9.1 of ISO/IEC 27001 requires monitoring and evaluation of security performance and ISMS effectiveness, and Art. 21(2)(f) of NIS2 demands policies and procedures to assess the effectiveness of risk management measures. Proven operational metrics include the implementation rate of measures from the risk treatment plan, overdue measures and audit findings including time to remediation, the age of risk assessments, the currency of controlled documents, training and awareness rates, and detection and remediation times for security incidents. Methodological guidance is provided by ISO/IEC 27004:2016 (a revision is currently available only as a draft) and NIST SP 800-55 (2024). What matters is selection rather than volume: a small number of decision-relevant metrics with a defined data source, target value and report recipient.
06The GRC tool landscape at a glance
Broadly, three categories can be distinguished: integrated GRC platforms that combine several disciplines such as risk, compliance, internal audit and policy management in a single data model; specialised ISMS tools with prebuilt framework catalogues and measure tracking; and compliance automation solutions that collect evidence automatically via interfaces to cloud, identity and endpoint systems. Alongside these, office-based in-house solutions remain widespread but hit their limits when it comes to versioning, traceability and multi-user operation. In the managed model, tool operation is part of the service scope – for instance catalogue updates for new versions of standards, mapping several frameworks onto each other and ongoing data maintenance. A tool does not replace an operating model, however: without defined processes and owners it merely depicts the standstill more clearly; in addition, the exportability of the data should be contractually secured for a later change of provider.