Book an Appointment
Governance, Risk & Compliance

Secure. Compliant. Future-ready.

Information security, cyber security, AI compliance, data privacy and business continuity — united in one GRC system built on the highest international standards.

Governance, Risk & Compliance

One integrated system for security, compliance and resilience

In an interconnected world, security is no longer decided by technology alone, but by the interplay of governance, risk management and compliance. Information security remains at the core: confidential information, business-critical systems and digital processes must be protected at all times. And AI compliance, data privacy, cyber security and business continuity now belong on the same agenda.

Our approach combines technology, processes and people into a governance architecture that withstands today's threats and keeps pace with tomorrow's regulation. We build on internationally recognised standards and legal frameworks such as ISO 27001, NIS2, DORA, the EU AI Act, the GDPR, BSI IT-Grundschutz and ISO 22301 — and translate them into one integrated management system.

GRC Compass

The complete GRC spectrum — four pillars, one system

Four pillars support your security and compliance organisation — every entry links straight to the in-depth service page.

01

Management Systems & Standards

Certifiable management systems as the backbone of your security organisation — from an ISO 27001 ISMS through AIMS, PIMS and BCMS to the integrated Vami IMS Framework.

02

EU & National Regulation

EU and national obligations translated into actionable measures — from NIS2, DORA and the CRA to the EU AI Act, KRITIS and MDR.

03

Attestations, Audits & Evidence

Credible assurance for customers and regulators: TISAX labels, BSI C5 attestations and cloud sovereignty under BSI C3A — including audit and certification support.

04

Managed GRC & Operations

GRC in day-to-day operations: as a service, with vCISO and vISB, practised emergency and continuity management, and automated supplier processes — including migration to the GRC tool of your choice.

Compliance

Secure. Compliant. Audit-ready.

A holistic compliance framework for sustainable information security.

Whether legal requirements such as NIS2, DORA, CRA, and AI Act or standards such as ISO 27001 and TISAX — information security compliance is more than a by-product of security processes today. It is a central proof of risk awareness, trustworthiness, and governance. We offer modular compliance management as a service that adapts to your structure, risk profile, and regulation.

Gap analysis & control mapping

We assess your existing security landscape against NIS2, DORA, CRA, AI Act, ISO 27001, and TISAX. We map controls across regulations and prioritize action-oriented.

Policy design & control frameworks

We develop and maintain your security policies, guidelines, and implementation processes. Compliance-as-code via policies, playbooks, awareness, and technical security requirements.

Control operation & review

We support the operational implementation, review, and assessment of your compliance controls. This includes control evaluation, effectiveness checks, and recommendations.

Audit preparation & reporting

We support you in internal and external audits, create management reviews, KPI dashboards, and audit-readiness matrices. Optionally including support for certification audits.

Standards & frameworks

Aligned with internationally recognized security and compliance standards

An effective information and cybersecurity strategy is based on clearly defined standards and frameworks. They ensure comparability, reliability, and compliance with regulatory requirements — at national and international level.

We consistently align our services with the leading standards and regulatory frameworks.

Regulations — Binding Law

NIS2

EU Cybersecurity Directive

Cybersecurity obligations for essential and important entities across 18 sectors — ISMS, 24/72h incident reporting, and management liability (§ 38 BSIG).

learn more

DORA

Digital Operational Resilience Act

EU regulation for the financial sector covering ICT risk management, TLPT, the Register of Information, and ICT third-party governance.

learn more

CRA

Cyber Resilience Act

EU-wide cybersecurity obligation for all products with digital elements from 11 Dec 2027 — including SBOM and Default/Important/Critical classification.

learn more

EU AI Act

Regulation for Artificial Intelligence

Risk-based AI regulation with prohibitions, high-risk duties (Art. 9–15), and GPAI; staggered applicability 2025–2027.

learn more

GDPR

General Data Protection Regulation

EU data protection law with Art. 30 (RoPA), Art. 35 (DPIA), and Art. 33/34 breach notification. Universally applicable when processing personal data.

learn more

MDR + MDCG 2019-16

Medical Device Regulation

EU medical devices regulation with cybersecurity requirements; MDCG 2019-16 is the recognized path of conformity.

learn more

EU Data Act

Regulation (EU) 2023/2854

Data access and use B2B/B2C/B2G; fair data contracts, cloud switching, and interoperability requirements.

EU Machinery Regulation

Regulation (EU) 2023/1230

New EU Machinery Regulation introducing first-time cybersecurity and AI requirements for all machinery from 20 Jan 2027.

learn more

RED DA

Radio Equipment Directive Cyber-DA

Delegated Regulation (EU) 2022/30 — cybersecurity for connected radio products via the harmonized EN 18031 series; transition to CRA by end of 2027.

Frameworks — Methodological (not certifiable)

ISO/IEC 27002:2022

Code of Practice for IS Controls

Backbone for the ISO 27001 Statement of Applicability — 93 controls in 4 themes with implementation guidance.

ISO/IEC 27005:2022

IS Risk Management

Methodology for information security risk management; interlinked with ISO 27001 clause 6.1.2. Asset/event/vulnerability-based.

learn more

ISO 31000:2018

Enterprise Risk Management

Methodological backbone for enterprise-wide risk management; umbrella for ISO 27005, 22301, and 23894.

learn more

NIST CSF 2.0

Cyber risk framework

The six CSF functions as a common language for ISO 27001, NIS2 and DORA – from Current Profile to a risk-driven roadmap.

learn more

CIS Controls v8.1

Prioritised security measures

18 Controls and 153 Safeguards as a pragmatic implementation roadmap beneath ISO 27001 and NIS2.

learn more

ISO/IEC 27035

Information Security Incident Management

A structured five-phase lifecycle for handling security incidents – the process foundation behind NIS2 and DORA reporting duties.

learn more

ISO/IEC 27036

Supplier risk & supply chain security

International framework for information security in supplier relationships – the normative basis for NIS2 and DORA third-party risk.

learn more

ISO/IEC 23894:2023

AI Risk Management

Risk engine for ISO 42001 (AIMS) and EU AI Act Art. 9 (RMS); methodological depth for AI risk assessment.

MITRE ATT&CK

TTPs Knowledge Base

Tactics, techniques, and procedures — 14 tactics × ~200 techniques. Mandatory backbone for DORA TLPT (TIBER-EU) and SOC/detection engineering.

ISMS per ISO 27001 — consulting & implementation

Build a robust security foundation for your company

An information security management system (ISMS) per ISO 27001 forms the foundation for sustainably secure IT processes and reliable compliance. As a leading information security and compliance consultancy, we support you in the holistic introduction, maintenance, and evolution of an ISMS tailored to your company’s needs — including BSI IT-Grundschutz, NIS2, BSIG, DORA, and TISAX.

Our ISMS services at a glance

We jointly analyze your requirements (e.g. ISO 27001, TISAX, NIS2, DORA) and develop an individual ISMS roadmap with clear roles, responsibilities, and milestones. A risk and gap analysis surfaces deviations from the target state.
We support the ongoing operation of your ISMS with modern, AI-driven platforms. This includes automated risk management, document management, and continuous monitoring of your security measures.
Creation of all required policies, procedures, and documentation — tailored precisely to your company structure. From the information security policy to the incident response plan.
Integration of regulatory requirements such as NIS2, DORA, TISAX, CRA, and EU AI Act into your ISMS. We map controls across regulations and prioritize action-oriented.
Operational implementation of all controls, processes, and technical measures. Including asset inventory, building-block mapping, and protection-need analysis per BSI IT-Grundschutz.
Harmonization of your ISMS with international and national standards. We ensure your system is audit-ready and meets the requirements of all relevant frameworks.

Our GRC platform

VamiGRC is our own AI-powered GRC platform for ISMS, DSMS and BCM. By default we implement your management system in VamiGRC — from rollout to day-to-day operation.

Discover VamiGRC

Alternatively, we also implement your ISMS on these platforms — especially useful when one of them is already in place at your organisation:

TrustSpace
GRC Tool Migration

Switch without data loss — to the GRC tool of your choice

We migrate ISMS, DSMS and BCM completely as a service from your legacy system — with a proven phase model, a test migration in a separate test system and an agreed rollback procedure.

6 phasesfrom discovery to hypercare
Test migrationbefore every production run
Go/No-Gowith backup & rollback plan
100 %migrated or excluded with rationale
NIS2

EU-wide cybersecurity duties

We make you compliant.

With the NIS2 directive (Network and Information Security Directive), the EU tightens cybersecurity requirements for companies and organizations in critical and essential sectors. The goal is to raise digital resilience across Europe and ensure a unified protection level against cyber threats. For affected companies this means: extended duties, stricter liability, and higher fines. VamiSec supports you in implementing the NIS2 requirements in a legally sound and pragmatic way.

Our services at a glance

  • Gap analysis & maturity assessment
  • Risk management & protection measures
  • Reporting & incident response processes
  • Governance & training
  • Support up to evidence delivery
DORA

Cyber resilience in the financial sector

Digital Operational Resilience Act.

With the Digital Operational Resilience Act (DORA), the EU establishes a unified legal framework for the digital resilience of banks, insurers, payment providers, financial service providers, and their IT service providers. From January 2025, the regulation becomes mandatory — affecting both large financial institutions and their supply chains. DORA obligates companies to systematically strengthen their cyber resilience, manage risks transparently, and design IT services securely. Violations can lead to substantial sanctions and reputational damage.

Our services at a glance

  • Gap analysis & roadmap
  • ICT risk management
  • Incident management & reporting
  • Resilience tests & TLPT
  • Third-party management
  • Training & awareness
TISAX®

Information security in the automotive industry

With TISAX® (Trusted Information Security Assessment Exchange), the automotive industry has created a binding standard to ensure the secure handling of sensitive information between manufacturers, suppliers, and service providers. The basis is ISO/IEC 27001, supplemented by industry-specific requirements. Today, a TISAX label is a prerequisite for many companies to work with OEMs and large suppliers — and thus a decisive competitive factor.

Our services at a glance

  • Gap analysis & readiness check
  • ISMS implementation
  • Implementation of industry-specific controls
  • Audit preparation & support
  • Awareness & training
CRA (Cyber Resilience Act)

Cybersecurity as a duty for digital products

With the Cyber Resilience Act (CRA), the EU establishes a binding legal framework to ensure the security of products with digital elements across their entire lifecycle. Manufacturers, distributors, and importers are now required to consider cybersecurity already during development (security by design) and to provide regular updates.

For companies, this means: clear responsibilities, extensive duties, and high fines for non-compliance.

Sep 2026reporting duties active
Dec 2027full CRA compliance
€15Mmax. fine for violations

Our services for your CRA compliance

Gap analysis & compliance check

Assessment of your products, processes, and documentation against the CRA requirements.

Integration of security by design

Advisory on implementing secure development processes (SDLC) and integrating threat analyses (threat modeling).

Vulnerability and patch management

Building processes for continuous vulnerability monitoring, risk assessment, and update delivery.

Documentation & evidence

Support in preparing the required technical documentation, declarations of conformity, and security reports.

Incident response & reporting

Introduction of clear processes for reporting and handling security incidents in line with CRA requirements.

Training & awareness

Trainings for product development, management, and compliance teams to sustainably implement the new regulatory requirements.

EU CRA Navigator

Are you prepared?

Your benefits from the CRA Navigator

In a strategic collaboration between VamiSec and JUN Legal, we developed the CRA Navigator. This tool gives you a sound initial orientation to understand and implement the complex requirements of the EU Cyber Resilience Act (CRA) for your products with digital elements.

Affectedness check & structured assessment

Answer targeted questions and get an immediate assessment of whether and how your products fall under the binding cybersecurity requirements of the CRA.

Quick gap analysis

Quickly identify structural gaps in your security and development processes to react proactively to the new statutory requirements.

Legally sound orientation

Benefit from a clear classification of your compliance requirements — from secure development methods to vulnerability handling and security updates.

Expert note

While the tool offers an important first orientation, the VamiSec experts are happy to advise you informally on technical implementation. For a legally binding assessment, we work closely with our partners at JUN Legal.

EU AI Act

Legally sound and trustworthy use of artificial intelligence

With the EU AI Act, the European Union introduces the world’s first comprehensive regulation for artificial intelligence. The goal is to foster innovation while ensuring safety, transparency, and fundamental rights when using AI systems. The legal framework applies to providers, deployers, and importers of AI systems within the EU — regardless of whether they were developed in or outside Europe.

For companies, the AI Act means: new duties, clear documentation requirements, and high sanctions for violations.

Our services for your AI compliance

Gap analysis & risk classification

Assessment of your AI systems regarding the AI Act risk classes and derivation of necessary measures.

Compliance-by-design

Integration of regulatory requirements into development processes — including documentation, data management, and testing.

Governance & policies

Creation of guidelines for the safe and compliant use of AI in the company.

Transparency & traceability

Support in implementing processes for explainable AI and user information.

Technical security measures

Advisory on cybersecurity, monitoring, and incident response specifically for AI systems.

Training & awareness

Trainings for developers, management, and business areas on safe and compliant use of AI.

Conformity assessment per Article 43 EU AI Act

Evidence of safety, transparency, and legal conformity

What does the conformity assessment cover?

The EU AI Act introduces — for the first time across Europe — binding requirements for the use of artificial intelligence. A central element is the conformity assessment per Article 43, which ensures that high-risk AI systems meet legal requirements before being placed on the market or used in production. This assessment is comparable to certifications in other areas (e.g. CE marking) and serves as evidence of safety, transparency, robustness, and legal compliance.

Technical documentation

Complete documentation of the AI system, including training data, algorithms, and risk assessments.

Data & quality management

Evidence of the origin, completeness, and quality of the data used.

Risk management processes

Systematic analysis and treatment of risks such as bias, discrimination, wrong decisions, or manipulation.

Cybersecurity & robustness

Protective measures against attacks on AI models and data integrity.

Transparency & traceability

Ensuring that AI decisions are explainable (Explainable AI).

Continuous monitoring

Processes to track AI performance in operations and adapt for risks or changes.

Our conformity assessment service

  • Gap analysis per EU AI Act
  • Preparation of technical documentation
  • Preparation for external assessment bodies
  • Integration into management systems
  • Training & awareness
AI management systems per ISO/IEC 42001

Responsible and safe use of artificial intelligence

With ISO/IEC 42001, the world’s first international standard for AI management systems was published. Its goal is to provide companies with a structured framework to develop, operate, and continuously improve AI systems responsibly, safely, transparently, and compliantly.

For companies this means: a clear guide for safe handling of AI — comparable to ISO 27001 in information security.

Structured and safe use of AI

A clear framework for development, operation, and continuous improvement of your AI systems.

Efficiency gains

Through clear processes and standards.

Demonstrable compliance

Towards customers, partners, and supervisory authorities.

Future readiness

Through proactive fulfillment of regulatory requirements.

Our services for ISO/IEC 42001

  • Gap analysis & maturity assessment
  • Building an AI management system (AIMS)
  • Policies & governance
  • Risk management for AI
  • Training & awareness
  • Audit preparation & certification

With ISO/IEC 42001 you build trust in your AI systems — combining innovation with safety and responsibility.

AI Officer as a Service

External expertise for safe and compliant AI use

With the EU AI Act, the responsible handling of artificial intelligence becomes a central corporate task. Organizations that develop, deploy, or distribute AI systems need clear governance structures, accountability, and compliance processes. This is where our "AI Officer as a Service" comes in: we provide experienced AI experts who take on the role of an internal AI officer — flexibly, scalably, and without additional fixed costs.

Your benefits with an external AI Officer

Regulatory certainty

Support in complying with the EU AI Act, GDPR, and relevant standards such as ISO/IEC 42001.

Hands-on implementation

A combination of legal, technical, and organizational know-how for sustainable AI governance.

Clear accountability

A defined contact for authorities, auditors, customers, and internal stakeholders.

Reputation & trust

Demonstrably responsible handling of AI strengthens trust with customers and partners.

Flexibility & cost control

External role on demand, without the fixed costs of an internal full-time hire.

Our managed services at a glance

  • Risk classification & compliance checks
  • Governance & policy development
  • Monitoring & reporting
  • Transparency & explainability
  • Awareness & training
  • Interface to auditors & authorities

With AI Officer as a Service you get the necessary expertise and regulatory competence for the safe, compliant, and responsible use of artificial intelligence — individual, flexible, and cost-efficient.

vCISO & vISO services

Leadership and security expertise — flexible and on demand

Not every company can — or wants to — staff a full-time information security position. At the same time, requirements from regulations such as DORA, NIS2, ISO 27001, TISAX, or BSI IT-Grundschutz are growing. Our vCISO and vISO services offer a flexible, scalable, and legally sound solution to ensure both strategic steering and operational execution of professional information security management.

Our services at a glance

  • Role & responsibility
  • Policies & governance
  • Steering of the security program
  • Awareness & training
  • Regulatory compliance & communication
  • Audit support & review
IT emergency management

Stay capable of action — even in a crisis

An emergency is not a question of "if", but "when".

A cyber attack, a system outage, or the loss of critical data can paralyze any company in a very short time. With structured IT emergency management, you ensure that your business stays resilient even in a crisis and can quickly return to normal operations. Our approach combines preventive measures, clear emergency plans, and practiced procedures so your company is prepared in any situation.

Business Impact Analysis (BIA)

Identification and evaluation of business-critical processes and systems to set priorities in an emergency.

Technical and organizational measures

Implementation of backup strategies, redundancies, failover systems, and communication paths for the worst case.

Risk & threat analysis

Assessment of potential threats such as cyber attacks, power outages, natural disasters, or internal error sources.

Trainings & crisis exercises

Training of staff and management for the safe execution of the emergency plans — including realistic scenarios and simulations.

Emergency manual & plans

Creation of tailored emergency and recovery plans (Disaster Recovery, BCM) with clear responsibilities and escalation levels.

Continuous improvement

Regular tests, reviews, and updates so your emergency management stays current and effective.

Business Continuity Management (BCM)

Secure stability — even in times of crisis

A serious IT outage, a cyber attack, natural disasters, or supply chain problems — every company can be affected by unexpected crises. With a structured Business Continuity Management (BCM), you ensure that your business-critical processes can be maintained or restored as quickly as possible, even in an emergency. BCM goes beyond pure IT emergency management and considers the entire organization — from IT and communications to suppliers and business processes.

Business Impact Analysis (BIA)

Identification and prioritization of business-critical processes, systems, and resources.

Crisis team organization

Building clear structures for decision paths, communication, and escalations.

Risk assessment & scenario planning

Analysis of possible threats (e.g. cyber attacks, supply chain disruptions, natural events) and their impacts.

Tests, exercises & awareness

Conducting tabletop exercises, crisis drills, and trainings to ensure BCM effectiveness and prepare staff.

Strategy and action planning

Development of tailored strategies to ensure business continuity, including redundancies and contingency scenarios.

Continuous improvement

Regular review, auditing, and adaptation of BCM to new risks, technologies, and regulatory requirements.

Emergency and recovery plans

Creation of concrete instructions for crisis cases, aligned with management, business units, and IT.

Supplier management

Security across the entire supply chain

Today, companies are heavily dependent on external service providers, partners, and suppliers — whether in IT, production, or logistics. But these dependencies bring substantial risks: cyber attacks, data breaches, or compliance violations at suppliers can have direct impact on your company. Structured supplier management ensures that external partners meet the required security and quality standards and that your supply chain remains resilient.

Supplier risk assessment

Systematic analysis of security and compliance risks at existing and new partners — including criticality classification.

Continuous monitoring

Establishing processes to regularly check and assess the security posture of suppliers — also when the risk situation changes.

Due diligence reviews

Conducting security and compliance audits at suppliers, aligned with industry standards and regulatory requirements.

Awareness & training

Sensitizing internal teams in dealing with third parties and their security responsibility.

Contractual safeguards

Support integrating security requirements, data protection clauses, and SLAs into contracts.

Integration into the ISMS

Embedding supplier management into existing information security management systems (ISMS) and governance structures.

Audits & certifications

Demonstrable security — building trust

Audit, certify, build trust — with structured preparation, deep expertise, and regulatory certainty.

In an increasingly regulated environment, auditable evidence of information security and compliance is not just a plus — it is a prerequisite for market access, customer approval, and operational security. We support you comprehensively in conducting internal audits, preparing for external certifications, and operating audit programs sustainably.

Our services at a glance

  • Gap analyses & audit preparation
  • Audit documentation & evidence structure
  • Internal audits & management reviews
  • Certification planning & recertification
  • External certification & audit support
Vami IMS framework

Mastering regulatory and contractual complexity — with the VamiSec IMS framework

How companies steer NIS2, DORA, AI Act, CRA, and GDPR in an integrated, scalable, and audit-ready way.

One framework. One tool. Many regulations and standards.

European regulations such as NIS2, DORA, the AI Act, the Cyber Resilience Act (CRA), and GDPR don’t require point-in-time measures, but lasting governance, risk, and steering structures at executive level.

The VamiSec IMS framework consistently translates this regulatory logic into an integrated, tool-supported management system (IMS). Instead of treating each rule in isolation, regulatory and contractual requirements are brought together in a single framework.

Strategic level: unified governance at management level

Consolidated regulatory overview

A central, unified view of all relevant regulations such as NIS2, DORA, AI Act, CRA, and GDPR within an integrated management framework.

Clear leadership and accountability structures

Clearly defined roles, accountabilities, and decision/escalation paths at executive and management level.

Linking regulation, strategy, and risk

Systematic translation of regulatory requirements into strategic goals, risk appetite, and enterprise-wide steering mechanisms.

Transparency across all compliance domains

A unified governance structure across information security, resilience, data protection, AI governance, and other regulatory areas.

Compliance as a steerable management responsibility

Shifting from isolated implementation projects to a continuously steered, management-driven compliance organization.

Central steering via an integrated framework and tool

Unified steering of all regulatory requirements via a single IMS framework and a central tooling landscape, instead of scattered individual tools and parallel compliance initiatives.

Protect your business now!

Contact us for individual consulting and a security solution tailored to your requirements.

"Only when all instruments are well tuned to one another will your organization be secure and compliant."— Valeri Milke, CEO of VamiSec
Contact us now