Skip to content
IT Security Management Systems
ISO 27001:2022 · BSI IT-Grundschutz · TISAX

Introducing an ISMS – step by step to the certificate.

We accompany your ISMS programme from the first scope definition through to successful external certification. Methodical, plannable and with real delivery – not advice alone.

ISO 27001:2022
internationally recognised
BSI IT-Grundschutz
public sector and CRITIS
TISAX
automotive supply chain
93 controls
in Annex A of ISO 27001

When you need an ISMS

Usually the push comes from outside – and by then the timeline is already set.

Customers and the supply chain ask for proof

The certificate increasingly appears in framework agreements and supplier questionnaires. Without it you drop out of the shortlist before anyone has discussed your offer.

NIS2 puts the obligation on management

Article 21 requires appropriate risk-management measures, and responsibility for them sits explicitly with the leadership. An ISMS is the structured way to meet that duty demonstrably.

TISAX in the automotive supply chain

Anyone handling development or prototype data from manufacturers cannot avoid the TISAX assessment. Much of it can be built on an ISO 27001 foundation instead of set up separately.

Insurance and public tenders

Cyber insurers and public buyers increasingly ask for demonstrable processes rather than a list of installed products. An ISMS produces exactly that evidence.

What we take on

Six work packages – you decide which of them stay with you.

Scope and initial assessment

Define the scope, identify stakeholders, compare against the chosen framework. What comes out is a list of what is missing — and of what you have had all along without calling it that.

Risk method and inventory

A method your people will still apply after the audit, plus an asset inventory and protection-requirement analysis. Not a spreadsheet monster nobody touches once certified.

Documentation

Policy, guidelines and procedures based on proven templates — adapted to your organisation, not handed over as a collection of boilerplate.

Implementing controls

Support for the technical and organisational controls. We deliver ourselves, coordinate service providers or steer your internal team — whichever works in your setting.

Awareness and training

Build the training programme, produce the material, run the first round — and evidence its effectiveness in a way that holds up in the audit.

Certification preparation

Internal audit, management review and a pre-audit with an external body. At the certification audit we sit at the table with you.

The road to the certificate

Six phases that build on one another. How long it takes depends on scope and maturity – we estimate that after the initial assessment rather than naming a number up front.

01

Initial assessment

Where do you actually stand? Comparison against the framework, an honest list of gaps, a rough effort estimate.

02

Scope and policy

Put the scope in writing, have the policy adopted by management, name roles and responsibilities.

03

Risk analysis and inventory

Record assets, determine protection requirements, assess and treat risks. The step that costs the most time and carries the most weight.

04

Documentation and controls

Write guidelines, implement controls, collect evidence. Largely runs in parallel with the previous step.

05

Internal audit and management review

Check yourselves before somebody else does. Close findings, evidence effectiveness, involve the leadership.

06

Certification audit

Stage 1 examines the documentation, stage 2 the lived practice. We accompany both and the follow-up.

ISO 27001 or BSI IT-Grundschutz?

The answer follows your customers and your sector, not the consultant's preference.

Comparison of ISO 27001 and BSI IT-Grundschutz
  ISO 27001:2022 BSI IT-Grundschutz
Recognition International, sector-neutral German-speaking region, strong in the public sector
Level of detail A framework; how you fill it is up to you Very concrete modules and requirements
Who typically asks for it Customers, tenders, the supply chain Public authorities, critical-infrastructure operators, public buyers
Certification body Accredited bodies such as DEKRA, TÜV, DQS, DNV Auditors certified by the BSI
Counts towards NIS2 Covers a large part of Article 21 Covers Article 21, with considerably more prescriptive detail

What you get

  • An ISMS manual that describes your organisation rather than a model company
  • A risk register with a method your people can carry forward
  • A Statement of Applicability
  • A complete set of policies, cut to your processes
  • A training programme with evidence of effectiveness
  • An internal audit report and documented readiness for certification

Who fills the role

An ISMS needs someone accountable for it. If you are missing that person internally, we take on the information security officer role externally and independently of your IT operations.

External information security officer

Tooling instead of spreadsheets

If you want the requirements carried technically, SecTepe.Core is our EU-native ISMS and GRC platform. It is not a condition – an ISMS works without our product too.

View SecTepe.Core

Frequently asked questions

How long does introducing an ISMS take?
That depends mostly on the scope and on how much you already have documented. A clearly bounded scope in a small company moves considerably faster than a programme spanning several sites with different processes. After the initial assessment we give you a timeframe you can plan around, rather than a guess.
ISO 27001 or BSI IT-Grundschutz?
ISO 27001 is internationally recognised, sector-neutral and the right choice for most organisations — particularly when customers or tenders ask for the certificate. The BSI IT-Grundschutz goes deeper into detail, is shaped by German practice and is often expected by public authorities, critical-infrastructure operators and the public sector. We decide this with you based on your customers, not on our preference.
How much work falls on our side?
The bulk of it sits in risk analysis, documentation and implementing controls — that is where we need your specialists, because only they know how your processes actually run. We supply method, templates and structure so your people are not starting from a blank page. We estimate the concrete effort after the initial assessment.
What does external support cost?
It depends on scope, maturity and how much you want to take on yourselves. After a free initial call you receive a quote with clearly bounded work packages. Terms on request.
Do we get the certificate from you?
No, and that is how it should be. We are a consulting partner; certification is carried out by accredited bodies such as DEKRA, TÜV, DQS or DNV. Anyone offering both advice and certification has a conflict of interest. We prepare you for the audits and sit at the table with you.
Does an ISMS count towards NIS2?
An ISMS to ISO 27001 covers a large part of the risk-management requirements in Article 21 of NIS2. Within the programme we use a mapping that shows which NIS2 requirement is covered by which control — and where something is still missing beyond that.
We already have an ISMS that does not work. Can you help with that?
Yes. A programme that has stalled does not need starting over from scratch but an honest stocktake: what is substantively usable, what is paper without effect, and where the organisational friction sits. We then restructure and keep whatever holds.

Let us draw your ISMS roadmap.

We go through the goal, the framework and the timeline in a workshop – free of charge and without obligation.

Request a roadmap workshop

How we work with you

We treat every engagement as a long-term partnership rather than a one-off delivery. Our approach is organised into four clear phases so that you always know what happens when, who owns which responsibility and which outcomes you can expect.

1. Free initial conversation

We learn about your starting position, your goals and the constraints you operate under. In 30 to 45 minutes we check whether our offering fits your situation, outline possible paths and answer your questions – no obligation attached.

2. Structured assessment

We capture the current state systematically – technically, organisationally and in regulatory terms. You receive a prioritised assessment that clearly names strengths, gaps and action areas and forms the basis for a robust offer.

3. Delivery with a dedicated lead

A senior lead guides you through the delivery with clear milestones, transparent effort and cost planning and a weekly status. All results are documented and remain fully owned by you.

4. Continuous operations & review

After project close, we stay alongside you in operations – via managed-service components, regular reviews, action tracking and proactive recommendations on new threats, regulatory changes or technology shifts.