KRITIS · NIS2 · ISO 27001 · Munich

Compliance that survives the audit.

I help operators of critical infrastructure (KRITIS) and mid-market companies implement NIS2, BSI requirements and ISO 27001, as a project partner or as an external information security officer. No binders full of policies: programs that work in operation and pass the audit.

IT-Grundschutz-Praktiker · ISO/IEC 27001:2022 Security Officer · PSM I

Career & projects: Siemens (assignments at Airbus, KUKA, MAN) · targens (LBBW Group) · DGC · Core42 (G42)

Why now

~29,500

companies under NIS2. BSI registration is mandatory.

17 July 2026

KRITIS umbrella act: the joint BBK/BSI operator registry goes live

every 3 years

§39 BSIG compliance audit cycle for KRITIS operators, plus mandatory attack detection systems (SzA)

Sources: BSIG, KRITIS umbrella act, BSI

Services

From the first gap assessment to a passed audit and beyond.

Project

KRITIS & NIS2: ISMS implementation

Applicability and gap analysis against §30/§31 BSIG, risk management per BSI standard 200-3, policies and reporting processes, attack detection systems (SzA), supply-chain security. Implemented along ISO 27001 or BSI IT-Grundschutz, aligned with your sector's B3S where available.

Get in touch →

Retainer

External ISO / vCISO

Ongoing ownership of your information security, including KRITIS environments: management reporting, risk steering, NIS2 board training per §38 BSIG (half-day, documented as evidence), single point of contact for auditors and authorities. A predictable monthly mandate.

Get in touch →

Project / support

Audit readiness: §39 evidence & ISO 27001

Internal audits, management review, SzA maturity assessment, remediation of open findings from your last audit. Preparation for the KRITIS compliance audit per §39 BSIG or your ISO 27001 certification audit (Stage 1/2). I make your ISMS audit-proof before the auditor puts it to the test.

Get in touch →

Fixed-price entry point

KRITIS/NIS2 applicability & gap check

Within 2–4 weeks you know what applies, what's missing and what it costs. Fixed price. Deliverable: a prioritized action plan for management.

Request a gap check

For certification bodies & audit providers

I support certification bodies and audit providers as a freelance auditor: for ISO/IEC 27001 (lead auditor certification completing 08/2026) and as a technical/co-auditor in KRITIS compliance audits per §39 BSIG, with implementation experience from finance, AI infrastructure and industry. Capacity and references on request.

Request auditor profile →

Why me

Implementation, not just advice

Built an ISO 27001-conformant ISMS for a hyperscale AI data centre, implemented NIST SP 800-53 (High), ran export-control compliance across three continents.

Project management in the blood

Certified Scrum Master with an engineering background: compliance programs with a plan, budget and deadline, not a permanent construction site.

Regulation as an advantage

KRITIS, NIS2, ISO 27001, NIST CSF and AI governance from one source, so security accelerates tenders, audits and sales instead of slowing them.

Process

  1. 1 Intro call (30 min, free)
  2. 2 Gap analysis & roadmap
  3. 3 Implementation in sprints
  4. 4 Audit & steady state

Profile

Julian Sauer

Senior cybersecurity consultant based in Munich. Roles at Siemens, targens (LBBW Group), DGC and Core42 (G42 Group), where I ran security and compliance programs for AI infrastructure in the US, France and the UAE. I translate regulation into workable technology and processes, in German and English.

  • IT-Grundschutz-Praktiker
  • ISO/IEC 27001:2022 Security Officer
  • Professional Scrum Master I (PSM I)
  • Stanford Advanced Product Management
  • Google Project Management

Let's talk.

A free 30-minute intro call. Afterwards you'll know where you stand and what to do.

Free 30-minute intro call

julian@sauer-cyber-consulting.de

Available from August 2026 · Remote & on-site (DACH)