Applicability check
A structured look at which requirements are likely relevant for you — as input for your legal assessment.
Cybersecurity & compliance
NIS2, the Cyber Resilience Act, the EU AI Act, GDPR security requirements — regulation is growing faster than most teams can read it. We help you understand what actually applies to you, what is missing and how to implement it in a way that also improves security.
A structured look at which requirements are likely relevant for you — as input for your legal assessment.
Comparing requirements with your current measures, documentation and processes.
A prioritized plan of technical and organizational measures with owners and timelines.
A cybersecurity risk management approach that satisfies NIS2 expectations — ideally inside an ISMS.
Incident and vulnerability reporting processes that work under time pressure (NIS2, CRA).
For manufacturers: secure development, vulnerability handling and SBOM practices for the CRA.
Roles, responsibilities and management reporting — including the accountability of management bodies.
Processes to identify, assess and remediate vulnerabilities in systems and products.
Which regulations are relevant and which obligations follow from them — explained in plain language.
Where do you stand? What do existing management systems and measures already cover?
What matters first: deadlines, risk and effort — not everything at once.
Technical and organizational measures, together with your teams.
Documentation and evidence that hold up — and stay current.
Compliance implementation, not legal advice
We are cybersecurity and management-system consultants, not a law firm. We translate requirements into technical and organizational measures and implement them with you. Binding legal assessments — for example whether your company legally falls under NIS2 — should be confirmed by legal counsel. We are happy to work alongside your lawyers.
NIS2 is an EU directive that sets cybersecurity obligations for “essential” and “important” entities in many sectors — including risk management measures, incident reporting and management accountability. In Germany it is implemented by the NIS2 Implementation Act, which has been in force since December 2025 and requires affected companies to register with the BSI.
The Cyber Resilience Act (CRA) is an EU regulation that sets cybersecurity requirements for products with digital elements — hardware and software — across their lifecycle. Manufacturers have had to report actively exploited vulnerabilities and severe incidents since 11 September 2026; most other obligations apply from December 2027.
Not automatically, but substantially. An ISO/IEC 27001 ISMS provides the risk management framework and many measures NIS2 expects. Specific obligations — such as registration, reporting deadlines and management training — have to be addressed in addition.
DIN SPEC 27076 is a standardized IT security check (“CyberRisikoCheck”) for small companies, developed with the participation of the German Federal Office for Information Security (BSI). It is a pragmatic first step for companies that are not yet ready for a full ISMS.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Develop a clear incident response plan with your team: roles, escalation, communication, reporting and lessons learned.
Get an overview of AI use, set clear rules, assess risks and prepare for the EU AI Act and ISO/IEC 42001 — without creating another silo.
NIS2, the Cyber Resilience Act and the EU AI Act explained: who is affected, which 2026 deadlines apply and how one ISMS covers shared requirements.
What an incident response plan must contain: roles, escalation, communication, NIS2 and CRA reporting deadlines, evidence and lessons learned.
What AI governance means, what ISO/IEC 42001 is, what the EU AI Act requires after the 2026 Digital Omnibus amendment, and how both connect to an existing ISMS.
Tell us about your company and your products. We will help you sort out what matters.