Introducing an ISMS – step by step to the certificate.
We accompany your ISMS programme from the first scope definition through to successful external certification. Methodical, plannable and with real delivery – not advice alone.
When you need an ISMS
Usually the push comes from outside – and by then the timeline is already set.
Customers and the supply chain ask for proof
The certificate increasingly appears in framework agreements and supplier questionnaires. Without it you drop out of the shortlist before anyone has discussed your offer.
NIS2 puts the obligation on management
Article 21 requires appropriate risk-management measures, and responsibility for them sits explicitly with the leadership. An ISMS is the structured way to meet that duty demonstrably.
TISAX in the automotive supply chain
Anyone handling development or prototype data from manufacturers cannot avoid the TISAX assessment. Much of it can be built on an ISO 27001 foundation instead of set up separately.
Insurance and public tenders
Cyber insurers and public buyers increasingly ask for demonstrable processes rather than a list of installed products. An ISMS produces exactly that evidence.
What we take on
Six work packages – you decide which of them stay with you.
Scope and initial assessment
Define the scope, identify stakeholders, compare against the chosen framework. What comes out is a list of what is missing — and of what you have had all along without calling it that.
Risk method and inventory
A method your people will still apply after the audit, plus an asset inventory and protection-requirement analysis. Not a spreadsheet monster nobody touches once certified.
Documentation
Policy, guidelines and procedures based on proven templates — adapted to your organisation, not handed over as a collection of boilerplate.
Implementing controls
Support for the technical and organisational controls. We deliver ourselves, coordinate service providers or steer your internal team — whichever works in your setting.
Awareness and training
Build the training programme, produce the material, run the first round — and evidence its effectiveness in a way that holds up in the audit.
Certification preparation
Internal audit, management review and a pre-audit with an external body. At the certification audit we sit at the table with you.
The road to the certificate
Six phases that build on one another. How long it takes depends on scope and maturity – we estimate that after the initial assessment rather than naming a number up front.
Initial assessment
Where do you actually stand? Comparison against the framework, an honest list of gaps, a rough effort estimate.
Scope and policy
Put the scope in writing, have the policy adopted by management, name roles and responsibilities.
Risk analysis and inventory
Record assets, determine protection requirements, assess and treat risks. The step that costs the most time and carries the most weight.
Documentation and controls
Write guidelines, implement controls, collect evidence. Largely runs in parallel with the previous step.
Internal audit and management review
Check yourselves before somebody else does. Close findings, evidence effectiveness, involve the leadership.
Certification audit
Stage 1 examines the documentation, stage 2 the lived practice. We accompany both and the follow-up.
ISO 27001 or BSI IT-Grundschutz?
The answer follows your customers and your sector, not the consultant's preference.
| ISO 27001:2022 | BSI IT-Grundschutz | |
|---|---|---|
| Recognition | International, sector-neutral | German-speaking region, strong in the public sector |
| Level of detail | A framework; how you fill it is up to you | Very concrete modules and requirements |
| Who typically asks for it | Customers, tenders, the supply chain | Public authorities, critical-infrastructure operators, public buyers |
| Certification body | Accredited bodies such as DEKRA, TÜV, DQS, DNV | Auditors certified by the BSI |
| Counts towards NIS2 | Covers a large part of Article 21 | Covers Article 21, with considerably more prescriptive detail |
What you get
- An ISMS manual that describes your organisation rather than a model company
- A risk register with a method your people can carry forward
- A Statement of Applicability
- A complete set of policies, cut to your processes
- A training programme with evidence of effectiveness
- An internal audit report and documented readiness for certification
Who fills the role
An ISMS needs someone accountable for it. If you are missing that person internally, we take on the information security officer role externally and independently of your IT operations.
External information security officerTooling instead of spreadsheets
If you want the requirements carried technically, SecTepe.Core is our EU-native ISMS and GRC platform. It is not a condition – an ISMS works without our product too.
View SecTepe.CoreFrequently asked questions
- How long does introducing an ISMS take?
- That depends mostly on the scope and on how much you already have documented. A clearly bounded scope in a small company moves considerably faster than a programme spanning several sites with different processes. After the initial assessment we give you a timeframe you can plan around, rather than a guess.
- ISO 27001 or BSI IT-Grundschutz?
- ISO 27001 is internationally recognised, sector-neutral and the right choice for most organisations — particularly when customers or tenders ask for the certificate. The BSI IT-Grundschutz goes deeper into detail, is shaped by German practice and is often expected by public authorities, critical-infrastructure operators and the public sector. We decide this with you based on your customers, not on our preference.
- How much work falls on our side?
- The bulk of it sits in risk analysis, documentation and implementing controls — that is where we need your specialists, because only they know how your processes actually run. We supply method, templates and structure so your people are not starting from a blank page. We estimate the concrete effort after the initial assessment.
- What does external support cost?
- It depends on scope, maturity and how much you want to take on yourselves. After a free initial call you receive a quote with clearly bounded work packages. Terms on request.
- Do we get the certificate from you?
- No, and that is how it should be. We are a consulting partner; certification is carried out by accredited bodies such as DEKRA, TÜV, DQS or DNV. Anyone offering both advice and certification has a conflict of interest. We prepare you for the audits and sit at the table with you.
- Does an ISMS count towards NIS2?
- An ISMS to ISO 27001 covers a large part of the risk-management requirements in Article 21 of NIS2. Within the programme we use a mapping that shows which NIS2 requirement is covered by which control — and where something is still missing beyond that.
- We already have an ISMS that does not work. Can you help with that?
- Yes. A programme that has stalled does not need starting over from scratch but an honest stocktake: what is substantively usable, what is paper without effect, and where the organisational friction sits. We then restructure and keep whatever holds.
Let us draw your ISMS roadmap.
We go through the goal, the framework and the timeline in a workshop – free of charge and without obligation.
Request a roadmap workshopHow we work with you
We treat every engagement as a long-term partnership rather than a one-off delivery. Our approach is organised into four clear phases so that you always know what happens when, who owns which responsibility and which outcomes you can expect.
1. Free initial conversation
We learn about your starting position, your goals and the constraints you operate under. In 30 to 45 minutes we check whether our offering fits your situation, outline possible paths and answer your questions – no obligation attached.
2. Structured assessment
We capture the current state systematically – technically, organisationally and in regulatory terms. You receive a prioritised assessment that clearly names strengths, gaps and action areas and forms the basis for a robust offer.
3. Delivery with a dedicated lead
A senior lead guides you through the delivery with clear milestones, transparent effort and cost planning and a weekly status. All results are documented and remain fully owned by you.
4. Continuous operations & review
After project close, we stay alongside you in operations – via managed-service components, regular reviews, action tracking and proactive recommendations on new threats, regulatory changes or technology shifts.