Project
KRITIS & NIS2: ISMS implementation
Applicability and gap analysis against §30/§31 BSIG, risk management per BSI standard
200-3, policies and reporting processes, attack detection systems (SzA), supply-chain
security. Implemented along ISO 27001 or BSI IT-Grundschutz, aligned with your
sector's B3S where available.
Get in touch → Retainer
External ISO / vCISO
Ongoing ownership of your information security, including KRITIS environments:
management reporting, risk steering, NIS2 board training per §38 BSIG (half-day,
documented as evidence), single point of contact for auditors and authorities.
A predictable monthly mandate.
Get in touch → Project / support
Audit readiness: §39 evidence & ISO 27001
Internal audits, management review, SzA maturity assessment, remediation of open
findings from your last audit. Preparation for the KRITIS compliance audit per §39
BSIG or your ISO 27001 certification audit (Stage 1/2). I make your ISMS audit-proof
before the auditor puts it to the test.
Get in touch →