An ISMS is not a paper exercise — it is the operational backbone of your information security. Whether building from scratch according to ISO 27001:2022, transitioning from the 2013 version, or optimizing an existing system: ADVISORI brings experience from over 50 ISMS projects. We combine standards-compliant structures with practical processes — so your ISMS not only passes the audit, but works in day-to-day operations.
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
Or contact us directly:










Years of Experience
Employees
Projects
Every organization is different — your ISMS must reflect that. We work iteratively, pragmatically, and always with certification in mind.
We offer you tailored solutions for your digital transformation
Complete ISMS implementation from risk methodology through policies and processes to technical controls. Including Statement of Applicability, asset management, and documentation framework — certification-ready in 6–12 months.
Migrating your existing ISMS to ISO 27001:2022: mapping the new 93 controls, integrating the 11 new requirements (Threat Intelligence, Cloud Security, ICT Readiness for Business Continuity), and closing audit findings.
From pre-audit readiness review through Stage 1 document review to on-site Stage 2 accompaniment. We know the typical pitfalls and prepare you specifically — including follow-up on minor/major non-conformities.
For automotive suppliers: preparation for the TISAX assessment according to VDA ISA. We identify the gaps between your existing ISMS and TISAX-specific requirements (prototype protection, data protection, integration with OEM processes).
Seamless integration of your ISMS into existing ISO 9001 or ISO 14001 systems. Harmonization of documentation, audit cycles, and management reviews — for an integrated management system without duplication of effort.
Alternative or complement to ISO 27001: building an ISMS based on the BSI IT-Grundschutz Compendium. Particularly relevant for KRITIS operators and public institutions that require the BSI standard as evidence of compliance.
Looking for a complete overview of all our services?
View Complete Service OverviewDiscover our specialized areas of information security
ISO 27001 is an international standard with a risk-based approach — you define which controls are relevant. BSI IT-Grundschutz is more detailed and prescribes specific measures (building blocks). ISO 27001 is globally recognized and suitable for international organizations. BSI IT-Grundschutz is particularly prevalent in Germany, especially among KRITIS operators and public authorities. Both can be combined: an ISO 27001 certification based on IT-Grundschutz combines the advantages of both approaches.
The typical timeframe is 6–
12 months from project start to a successful Stage
2 audit. The duration depends on the current maturity level, the scope, and the available internal resources. Organizations with an existing management system (e.g., ISO 9001) can often achieve certification faster, as structures such as internal audit and management review are already established.
The pure certification costs (auditor fees) range from EUR 10,000–30,
000 depending on company size and scope. The larger investment block is preparation: internal resources, consulting, tool implementation, and training. A realistic total budget for a mid-sized company is EUR 50,000–150,000. ADVISORI helps deploy this budget efficiently and avoid overengineering.
NIS 2 does not mandate a specific framework, but requires systematic risk management, incident management, supply chain security, and governance structures — all core elements of an ISMS based on ISO 27001. In practice, an ISO 27001 certification is the most efficient way to demonstrate NIS 2 compliance. In addition, management bears personal responsibility for cybersecurity — another reason for a structured ISMS.
The key changes concern Annex A: instead of
114 controls in
14 groups, there are now
93 controls in
4 categories (organizational, people, physical, technological).
11 new controls have been introduced, including Threat Intelligence, Cloud Security, ICT Readiness for Business Continuity, and Data Masking. The transition deadline was
31 October
2025 — certifications based on the
2013 version are no longer valid.
TISAX (Trusted Information Security Assessment Exchange) is the information security standard of the automotive industry, based on the VDA ISA questionnaire. If you are a supplier or service provider for OEMs such as VW, BMW, or Mercedes, a TISAX assessment is generally a prerequisite for collaboration. TISAX and ISO 27001 have significant overlaps — an existing ISMS considerably facilitates TISAX readiness.
Discover how we support companies in their digital transformation
Bosch
KI-Prozessoptimierung für bessere Produktionseffizienz

Festo
Intelligente Vernetzung für zukunftsfähige Produktionssysteme

Siemens
Smarte Fertigungslösungen für maximale Wertschöpfung

Klöckner & Co
Digitalisierung im Stahlhandel

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Our clients trust our expertise in digital transformation, compliance, and risk management
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
Direct hotline for decision-makers
Strategic inquiries via email
For complex inquiries or if you want to provide specific information in advance
Discover our latest articles, expert knowledge and practical guides about Information Security Management Strategy

NIS-2 verpflichtet Unternehmen zu nachweisbarer Informationssicherheit.Der KI-gestützte vCISO bietet einen strukturierten Weg: Ein 10-Module-Framework deckt alle relevanten Governance-Bereiche ab – von Asset-Management bis Awareness.

Die BaFin-Meldefrist für das DORA-Informationsregister läuft vom 9.–30. März 2026. 600+ IKT-Vorfälle in 12 Monaten zeigen: Die Aufsicht meint es ernst. Was jetzt zu tun ist.

Am 11. September 2026 tritt die CRA-Meldepflicht in Kraft. Hersteller digitaler Produkte müssen Schwachstellen innerhalb von 24 Stunden melden. Dieser Guide erklärt die Fristen, Pflichten und konkreten Vorbereitungsschritte.

Schritt-für-Schritt-Anleitung zur NIS2-Registrierung im BSI-Portal: ELSTER-Zertifikat prüfen, MUK einrichten, Portal-Registrierung abschließen. Frist: 6. März 2026.

44% der Finanzunternehmen kämpfen mit der DORA-Umsetzung. Erfahren Sie, wo die größten Lücken liegen und welche Maßnahmen jetzt Priorität haben.

NIS2, DORA, AI Act und CRA treffen 2026 gleichzeitig. Fristen, Überschneidungen und konkrete Maßnahmen — der komplette Leitfaden für Entscheider.