The artefact that closes the gap, fitted to your system landscape instead of a generic template. For example a cryptography standard, a logging concept or a register of evidence.
Developed against the requirements that apply to you: NIS2, DORA and its technical regulatory standards, MaGo and the German Insurance Supervision Act (VAG), or ISO 27001, depending on your sector.
A handover to your IT, not just a document. Your team understands it and produces the verification record themselves.
No software that simulates a rule. A rule that actually runs.
3,000 to 6,000 euros
Duration
Within 2 weeks of the assessment
Price
Fixed, per closed gap
Prerequisite
Assessment, 7,500 to 12,000 euros, separate
First engagement
with the assessment 10,500 to 18,000 euros; each further gap 3,000 to 6,000
Price driver
Your system landscape, not headcount
After that
You decide
The assessment measures your whole company; a gap closes a single, known finding. That is why the same amount of time costs less here.
Read-only access, no changes to your systems. Implementation stays with your IT. No framework agreement, no automatic renewal.
Executable means: system, target value, role, verification record
One criterion, not a footnote: every rule names a system, a target value, a responsible role and a verification record, and operations can implement it without further questions. If a rule does not meet that, it is not finished.
For a regulated firm, a standard is not a document you show once, it is a live register with test evidence. We map every rule against Annex A of ISO 27001, with ISO 27002 as the substantive reference, and against the DORA requirements for ICT risk management. One record per control. For firms in scope of DORA, the VAIT has been withdrawn since January 2025; we work against DORA, the related RTS and ISO 27001.
Sample data, no client material
Requirement
ISO 27001 A.8.24, DORA (RTS on ICT risk management, encryption)
System
Databases holding personal or contractually protected data
Target value
AES-256-GCM at rest; TLS 1.2 or higher in transit, AEAD suites only (e.g. ECDHE with AES-256-GCM), no legacy RC4 or CBC suites
Responsible role
The database owner implements it, IT leadership signs off
Verification record
Configuration export of the encryption setting, every six months
Written by someone who sat on both sides of the audit table as a CISO. The founder.
Case
A case
An insurer had to present a binding cryptography standard before the DORA deadline. They wanted this one gap closed, not a whole programme. We developed the standard based on DORA, its technical regulatory standards and ISO 27001. For firms outside DORA's scope, we develop just as readily against MaGo or VAG, or against ISO 27001 alone, whichever applies to you.
The ISMS was already in place. The standards could not be executed by their own IT.
Out of it: a cryptography standard and a logging concept their own team understands and can run.
When your system cannot meet the rule
A rule no system in the house can meet is not a rule. It is a risk nobody sees any more. So every rule gets an exception path, not a silent breach:
Compensating control
If a system cannot reach the target value, we define what mitigates the risk instead.
if not
Time-boxed exception
Owner and deadline are in the document, not in one person's head.
if not
Risk acceptance
A named role accepts the risk deliberately and it is documented, instead of staying open unnoticed.
Three assurances before you commission
The assessment runs first
A standard starts with an assessment of your affected systems. Without it, we do not know what target value your systems can actually carry. The assessment therefore runs first and is commissioned separately.
Your certificate stays untouched
The standard does not replace any document in your ISMS. Your ISMS controls and approves it, like any other document.
What we hand over
You get the documentation, the access and the knowledge behind it. You retain ownership of your systems. If something needs permanent support, we tell you beforehand. Then you decide whether we take it on.
Second opinion
Does an existing provider already write your standards, and you are not sure the verification record behind them really holds up? That is what the second opinion checks, independent, because we earn nothing on the operation.