ISO 27001, BSI IT-Grundschutz, NIS2
Information Security Consulting
Security on a solid foundation. We guide you from the initial analysis step to the tailored implementation of your security strategy. Ensuring requirements become resilient processes—not just documents that look good in an audit.
Request ConsultationAll ServicesInformation Security
Consulting
Frameworks
Services
3 specific consulting areas
Starting Point
In-depth gap analysis
Outcome
Prioritized action plan
When You Need Us
Very few companies seek information security consulting without a specific reason. Most often, there is a concrete trigger:
- A customer requires proof of ISO 27001 or BSI IT-Grundschutz compliance in a supplier audit, and the deadline is already set.
- You are not sure whether NIS2 applies to you and need a reliable assessment rather than guesswork.
- Your cyber insurance provider asks questions about measures that you cannot readily answer.
- Information security rests on a single person who is primarily responsible for IT and handles security on the side.
- Policies exist, but no one can say whether they are actually lived in day-to-day operations.
- Following a security incident, isolated measures finally need to become a cohesive system.
Which Framework Fits You
Three frameworks appear most frequently in practice, and they answer different questions.
ISO 27001
An international standard for an information security management system (ISMS). Relevant when customers or partners require certification, often in B2B business and with an international focus.
BSI IT-Grundschutz
A German framework with a highly specific catalog of measures. Relevant for public-sector clients, government agencies, and companies operating around public administration, and as a practical starting point beyond it.
NIS2
An EU directive, implemented nationally, obliging specific sectors to implement minimum measures and reporting obligations. Relevant as soon as your company falls into the affected sectors and size categories, regardless of whether you are aiming for certification.
The frameworks are not mutually exclusive. NIS2 is often the legal obligation in the background, while ISO 27001 or BSI IT-Grundschutz provide the structured path to meet it.
Where to Start
| Your Situation | Recommended Starting Point |
|---|---|
| Customer requires certification | ISO 27001 or BSI IT-Grundschutz |
| Unclear whether NIS2 applies | NIS2 Consulting for applicability assessment |
| Public sector client | BSI IT-Grundschutz Consulting |
| Security ownership lacks organizational structure | CISO as a Service |
| No formal requirements yet, but a diffuse sense of uncertainty | Gap analysis without framework commitment |
When in doubt, we begin with the gap analysis regardless of the target framework. It shows the current status and makes choosing the right framework easier afterward.
What We Do and What You Receive
| Service | What You Receive |
|---|---|
| Gap Analysis | Gap report with target-vs-actual comparison against the relevant framework, including protection needs assessment |
| Risk Assessment | Risk register with classification, responsibilities, and treatment decisions per risk |
| Action Planning | Prioritized action plan based on risk and effort, with assigned responsibilities and a realistic timeframe |
| Policy Development | Fully drafted set of policies tailored to your organization rather than boilerplate templates |
| Training | Workshops and briefings to ensure security does not depend on isolated individuals |
| Audit Support | Preparation, support during the audit, and an executive summary of key results |
Our Focus Areas
Implementation of the IT-Grundschutz Compendium, from structural analysis to the action plan.
External security responsibility with a dedicated contact person and a clear time budget.
Assessment of applicability and implementation of obligations under the NIS2 directive.
How Consulting Works
Current State Assessment
We record your systems, processes, and existing measures and compare them against the framework relevant to you.
Prioritization
Dogether, we define what is needed in the short term and what can follow in the medium term.
Implementation Support
We guide the implementation and are on hand as your point of contact without taking decisions out of your hands.
Audit & Fine-Tuning
We prepare you for audits, accompany you on-site upon request, and refine measures based on the results.
How Long It Takes
Initial certification according to ISO 27001 or BSI IT-Grundschutz is not a weekend project. As a rough guide:
- Gap analysis: a few weeks, depending on the size and complexity of the organization.
- Implementation up to certification readiness: usually several months up to a year, depending on how much is already in place.
- The certification itself: conducted by an independent, accredited body. We prepare and accompany you; the certificate is issued by that body.
- Maintenance: ongoing internal audits and recertification typically after three years, with annual surveillance audits in between.
The exact timeframe depends heavily on the starting point. You will receive a realistic estimate following the gap analysis.
Why It Is Worth It
Improve IT Security
A structured approach protects your infrastructure sustainably instead of treating individual symptoms.
Ensure Compliance
Meet regulatory requirements and build trust with customers, partners, and auditors.
Reduce Risks Efficiently
Target attack surfaces effectively instead of investing everywhere at once.
Hands-on Technical Expertise
We come from penetration testing. Our measures are aligned with what attackers actually do, not with what is easiest to document.
Information Security Consulting
Tell us what triggered your inquiry. In an initial conversation, we assess the framework and identify the next steps.
- Assessment regarding ISO 27001, BSI, or NIS2
- Start with an in-depth gap analysis
- Prioritized action plan
- Resilient processes instead of audit documents
Frequently Asked Questions
What clients want to know before working together.
Do you certify us yourselves?
No. We prepare you for the audit; the certificate is issued by an independent, accredited certification body. This separation is required by standard.
Do we strictly need a certificate?
Not always. Sometimes a structured gap analysis with an action plan is sufficient if no customer or regulation explicitly requires certification. We do not automatically recommend the most extensive process.
What if we already have policies in place?
Then we verify whether they fit the selected framework and are actually practiced in everyday operations, rather than starting from scratch.
Does this make sense for small businesses as well?
Yes, the scope scales with size. A gap analysis for a small business is correspondingly more compact.
Do you provide binding legal assessments on NIS2 applicability?
We assess applicability and obligations from a technical perspective. The legally binding evaluation in individual cases belongs in the hands of your legal counsel.
What happens after certification?
The work does not end there. Internal audits, updating the risk register, and annual surveillance audits continue; we can support this upon request.

