Skip to content

Compliance: NIS2, ISO/IEC 27001 & data protection

Turn requirements into practical controls and usable evidence.

Customer expectations, regulatory requirements and internal security goals must be addressed with existing systems and finite resources. We structure technical and organizational work and help build suitable evidence. Risks, responsibilities and practical measures become part of a manageable operational process.

Symbolic image: Plan goals and implementation together.

Your options

Services that move your project forward

Define requirements and scope

We record the requirements, affected companies, processes and systems confirmed for your project. Open legal questions are addressed to the responsible departments.

Your benefit

A clear scope of work and comprehensible responsibilities.

Assess the current position

Existing guidelines, contracts, technical controls and evidence are considered in a structured manner. Missing or insufficiently implemented processes become visible.

Your benefit

A prioritized basis for the next improvements.

Connect risks and measures

Business impact and existing controls determine priorities. Actions are labeled with owners, dependencies, and audit criteria.

Your benefit

Investments can be justified on the basis of their specific impact.

Implement technical controls

Access control, logging, backup, hardening and vulnerability processing are integrated into the existing environment. Implementation and maintenance belong together.

Your benefit

Requirements are given a verifiable technical implementation.

Maintain documentation and evidence

Policies and procedures are connected to records of actual practice. Document owners, approvals and review dates help keep the information current.

Your benefit

Evidence becomes easier to find and trace.

Prepare reviews and improvements

Internal review, management decisions and the preparation of external audits are supported. Findings are incorporated into further action planning.

Your benefit

A continuous improvement process with specific tasks.

Where to start

Compliance: NIS2, ISO/IEC 27001 & data protection Use cases

Three example situations show how we can help.

Responding to a customer's requirements

A customer requires clear security evidence. We organize existing documents, identify gaps and connect statements with the measures actually in place.

Systematically building up information security

An organization wants clearer responsibility and risk management. A defined ISMS scope connects processes, technical controls and regular reviews.

Implementing regulatory changes

Confirmed new requirements relate to existing IT processes. We structure the technical implementation and coordinate dependencies with the responsible departments.

From requirements to results

A clear process with agreed milestones

  1. Agree the scope

    Scope, confirmed requirements and the responsible parties involved are clarified.

  2. Prioritize gaps and risks

    Existing evidence and implementation are checked against the agreed criteria.

  3. Implement measures and evidence

    Teams implement prioritized tasks and document their effectiveness.

  4. Establish ongoing reviews

    Recurring controls, decisions and improvements are given fixed responsibilities.

Your benefit

What you receive

  • Coordinated catalogue of requirements and comprehensible scope.
  • A prioritized view of gaps, actions and the responsibilities to assign.
  • Technical implementation and evidence to the agreed extent.
  • Documents and schedule for further internal or external audits.

Ways to work with us

Choose a starting point that fits your needs. We agree the scope and required effort in a tailored proposal.

Questions before you get started

Can you help determine whether NIS2 applies to our organization?

We can gather relevant information about processes, systems and organizational scope. The binding legal assessment is handled by the responsible functions or legal advisers. Implementation is planned on that confirmed basis.

What is the difference between ISO/IEC 27001 and NIS2?

ISO/IEC 27001 describes requirements for an information security management system. NIS2 concerns regulatory obligations for certain entities. A management system can support structured processing; a certificate does not automatically replace the fulfilment of all legal requirements.

Do you guarantee successful certification?

No. We support preparation and implementation to the agreed extent. The certification decision lies with the commissioned certification body and depends, among other things, on the scope of application and the actual proven implementation.

How are data protection requirements taken into account?

Data types, purposes, access, storage and technical data flows are considered with the responsible data protection officers. Technical and organizational measures derived from this are classified in architecture and IT operations.

Are ready-made policy templates sufficient?

Templates can make it easier to get started. It is crucial that responsibilities, procedures and actual implementation fit your company. Documents need appropriate evidence and regular maintenance.

Can we reuse existing evidence?

Yes, where its content, scope and currency meet the relevant requirements. We map existing documentation and identify missing evidence. This can reduce duplicate work while preserving distinctions between requirements.

Who needs to be involved internally?

In addition to IT and information security, management, departments, human resources, purchasing and data protection may be required. The necessary participation is specified precisely for the agreed area of application.

How will measures remain relevant after the project?

Named owners, review dates and clear change procedures are integrated into existing processes. Regular reviews examine actual implementation and changing risks as well as documentation.

Discuss your next step

Which requirement do you need to demonstrate next?

Tell us what prompted the project, its scope and the documents already available. We will define suitable work packages and clear deliverables.

Discuss your project

Compliance: NIS2, ISO/IEC 27001 & data protection

Your next step

Tell us what you need. We will route your enquiry to the right team and discuss the next steps with you.

Fields marked * are required. Phone, company and postal address are optional.

Your enquiry

Your enquiry

Compliance: NIS2, ISO/IEC 27001 & data protection

What would you like to discuss? *

How to reach you

Your message

Add a postal address (optional)

Only provide an address if it is useful for your enquiry. Please enter the complete address. We check the format; this does not verify actual deliverability.

We use your details to handle your enquiry and send an acknowledgement by email. This does not subscribe you to a newsletter. Please do not send passwords, bank details or highly confidential information.

Privacy information for enquiries

Quick contact