Standards & management systems
From ISO 27001 and BSI IT-Grundschutz++ to C5 and TISAX — the standards and frameworks that make security certifiable.
ISO 27001, BSI IT-Grundschutz, NIS2, DORA, CRA and the EU AI Act: how to bring management systems, risk management and regulatory obligations into one audit-ready, integrated structure — without duplicating work.
Good governance is not paperwork — it is the operating system of your security: an integrated management system translates standards and regulation into clear responsibilities, measurable controls and evidence that holds up in an audit. These knowledge pages bundle our methodology on standards, EU regulation and day-to-day operations — from gap analysis and certification to vCISO and GRC as a Service.
Each topic leads to a dedicated knowledge page with deep dives, practical guides and the matching services.
From ISO 27001 and BSI IT-Grundschutz++ to C5 and TISAX — the standards and frameworks that make security certifiable.
NIS2, DORA, CRA, EU AI Act, KRITIS and MDR — obligations, deadlines and the path to demonstrable compliance.
Keeping compliance alive: external CISO and ISO roles, audits, training and automated evidence.
Third-Party-Risk-Management for your IT supply chain: from the regulatory obligations under NIS2 and DORA to the assessment of cloud providers (CSA CAIQ/CCM/STAR) and AI providers (CSA AI Controls Matrix v1.1).
In-depth knowledge pages on the topics that currently raise the most questions — with verified sources and concrete measures.
How to systematically assess and manage the security of your IT, cloud, and AI supply chain – from supplier selection through to continuous monitoring.
View knowledge pageWith ISO/IEC 42001:2023, an international, certifiable standard for an Artificial Intelligence Management System (AIMS) exists for the first time. What the standard requires, what the documentation landscape looks like — and how you can efficiently integrate an AIMS into your existing ISMS.
View knowledge pageFrom August 2, 2026, the transparency obligations of Art. 50 AI Act apply to interactive AI systems, generative content, emotion recognition and deepfakes. The European Commission's draft guidelines of May 8, 2026 specify how providers and deployers are expected to implement these obligations.
View knowledge pageRisk management for AI the NIST way: the AI Risk Management Framework and the new Cyber AI Profile (NIST IR 8596) give organizations a structured, prioritized framework for securing AI systems, using AI for defense and thwarting AI-enabled attacks.
View knowledge pageWhat the standard requires, how the path to certification works and why an ISMS based on ISO/IEC 27001 holds up as evidence towards customers, partners and supervisory authorities.
View knowledge pageHow the BSI standards, the IT-Grundschutz Compendium and the safeguarding approaches interact – and what the ongoing modernisation towards Grundschutz++ means for your ISMS.
View knowledge pageEach whitepaper has its own page with details and a direct download form.
In an initial consultation, we show you how your standards and regulatory requirements converge into one integrated, audit-ready management system.