Compliance: NIS2, ISO/IEC 27001 & data protection
Turn requirements into practical controls and usable evidence.
Customer expectations, regulatory requirements and internal security goals must be addressed with existing systems and finite resources. We structure technical and organizational work and help build suitable evidence. Risks, responsibilities and practical measures become part of a manageable operational process.

Your options
Services that move your project forward
Define requirements and scope
We record the requirements, affected companies, processes and systems confirmed for your project. Open legal questions are addressed to the responsible departments.
A clear scope of work and comprehensible responsibilities.
Assess the current position
Existing guidelines, contracts, technical controls and evidence are considered in a structured manner. Missing or insufficiently implemented processes become visible.
A prioritized basis for the next improvements.
Connect risks and measures
Business impact and existing controls determine priorities. Actions are labeled with owners, dependencies, and audit criteria.
Investments can be justified on the basis of their specific impact.
Implement technical controls
Access control, logging, backup, hardening and vulnerability processing are integrated into the existing environment. Implementation and maintenance belong together.
Requirements are given a verifiable technical implementation.
Maintain documentation and evidence
Policies and procedures are connected to records of actual practice. Document owners, approvals and review dates help keep the information current.
Evidence becomes easier to find and trace.
Prepare reviews and improvements
Internal review, management decisions and the preparation of external audits are supported. Findings are incorporated into further action planning.
A continuous improvement process with specific tasks.
Where to start
Compliance: NIS2, ISO/IEC 27001 & data protection Use cases
Three example situations show how we can help.
Responding to a customer's requirements
A customer requires clear security evidence. We organize existing documents, identify gaps and connect statements with the measures actually in place.
Systematically building up information security
An organization wants clearer responsibility and risk management. A defined ISMS scope connects processes, technical controls and regular reviews.
Implementing regulatory changes
Confirmed new requirements relate to existing IT processes. We structure the technical implementation and coordinate dependencies with the responsible departments.
From requirements to results
A clear process with agreed milestones
Agree the scope
Scope, confirmed requirements and the responsible parties involved are clarified.
Prioritize gaps and risks
Existing evidence and implementation are checked against the agreed criteria.
Implement measures and evidence
Teams implement prioritized tasks and document their effectiveness.
Establish ongoing reviews
Recurring controls, decisions and improvements are given fixed responsibilities.
Your benefit
What you receive
- Coordinated catalogue of requirements and comprehensible scope.
- A prioritized view of gaps, actions and the responsibilities to assign.
- Technical implementation and evidence to the agreed extent.
- Documents and schedule for further internal or external audits.
Ways to work with us
Choose a starting point that fits your needs. We agree the scope and required effort in a tailored proposal.
Gap analysis and action plan
For orientation: confirmed requirements, existing implementation and prioritized next steps.
Request a quote: Gap analysis and action planImplementation within a defined scope
For specific progress: technical controls, procedures and related evidence.
Request a quote: Implementation within a defined scopeISMS and audit preparation
For a maintained management system: responsibilities, periodic review and organized audit evidence.
Request a quote: ISMS and audit preparationQuestions before you get started
Can you help determine whether NIS2 applies to our organization?
We can gather relevant information about processes, systems and organizational scope. The binding legal assessment is handled by the responsible functions or legal advisers. Implementation is planned on that confirmed basis.
What is the difference between ISO/IEC 27001 and NIS2?
ISO/IEC 27001 describes requirements for an information security management system. NIS2 concerns regulatory obligations for certain entities. A management system can support structured processing; a certificate does not automatically replace the fulfilment of all legal requirements.
Do you guarantee successful certification?
No. We support preparation and implementation to the agreed extent. The certification decision lies with the commissioned certification body and depends, among other things, on the scope of application and the actual proven implementation.
How are data protection requirements taken into account?
Data types, purposes, access, storage and technical data flows are considered with the responsible data protection officers. Technical and organizational measures derived from this are classified in architecture and IT operations.
Are ready-made policy templates sufficient?
Templates can make it easier to get started. It is crucial that responsibilities, procedures and actual implementation fit your company. Documents need appropriate evidence and regular maintenance.
Can we reuse existing evidence?
Yes, where its content, scope and currency meet the relevant requirements. We map existing documentation and identify missing evidence. This can reduce duplicate work while preserving distinctions between requirements.
Who needs to be involved internally?
In addition to IT and information security, management, departments, human resources, purchasing and data protection may be required. The necessary participation is specified precisely for the agreed area of application.
How will measures remain relevant after the project?
Named owners, review dates and clear change procedures are integrated into existing processes. Regular reviews examine actual implementation and changing risks as well as documentation.
Discuss your next step
Which requirement do you need to demonstrate next?
Tell us what prompted the project, its scope and the documents already available. We will define suitable work packages and clear deliverables.
Compliance: NIS2, ISO/IEC 27001 & data protection
Your next step
Tell us what you need. We will route your enquiry to the right team and discuss the next steps with you.
Fields marked * are required. Phone, company and postal address are optional.