Our information security packages
From free Discovery to complete Transformation. All packages are aligned with ISO/IEC 27001.
You can find an overview of the included features of each package and optionally available add-ons in our comparison table below.
DISCOVERY
Delivered within 3 business days.
New to us? Get a fast, no-commitment security snapshot to identify your most important risks and compliance blind spots.
Your Benefit
Clear understanding of your biggest security and compliance risks.
Best for: Organizations that are curious about their security exposure and want a no-risk look before committing.
Foundation
Delivered within 5 business days.
Establish your security baseline and define a concrete improvement plan aligned to ISO 27001, enabling you to focus on your business.
Your Benefit
Clear baseline, prioritized risks, and actionable next steps.
Best for: Organizations starting structured security improvement – especially those preparing for compliance audits or responding to customer security questionnaires.
Acceleration
Delivered within 15-20 business days.
Design your ISO 27001–aligned ISMS with a complete risk-based structure and a clear path to audit readiness.
Your Benefit
Operational ISMS framework ready for implementation, with documented risk treatments, ISO 27001-compliant controls, and a clear path to certification audit.
Best for: Organizations looking to improve their security posture, moving from assessment to structured ISMS design – especially those with client requirements for ISO 27001.
Transformation
End-to-end ISO 27001 planning and implementation, from gap analysis to implementation support. Delivered by an experienced security professional.
Your Benefit
Fully operational ISMS with implemented controls, prepared audit evidence, and your organization ready for ISO 27001 certification.
Best for: Organizations with complex environments requiring hands-on implementation support – especially those with compliance deadlines or client requirements.
Final pricing & delivery timeline depends on organizational size, control complexity, and implementation.
All prices are net and exclude VAT. Our services are offered to businesses only.
Feature comparison
Compare what’s included in each package
Discovery
Snapshot
Foundation⭐
Baseline
Acceleration
Design
Transformation
Implementation
from
Assessment
Executive security snapshot
Business & Risk context (SWOT/PESTLE)
High-Level
Stakeholder context
High-Level
Compliance requirements
High-Level
Threat & risk identification
High-Level
Strategic security requirements
High-Level
Preliminary gap analysis
Comprehensive assessment report
Executive presentation & decision template
Show full comparison
Planning
Customized Information Security Policy draft
ISMS Scope & Objectives definition
Preliminary
Risk treatment & action plan
High-Level
ISO 27001 gap & maturity assessment
High-Level
90-day action plan
High-Level
Statement of Applicability (SoA) (Annex A mapping)
Roles, responsibilities & resource planning
Training, awareness & communication strategy
Detailed implementation roadmap with clear timeline
ISMS setup (excl. controls)
Topic-specific policies & documentation (e.g. IAM, AI, backup…)
3 policies
10+ ISMS documents
Implementation
ISMS change management plan
High-Level
Records and documentation management plan
High-Level
Guided ISMS implementation support
Performance management & monitoring setup
Management review & internal audit facilitation
Continual improvement process setup
Collaboration & Interaction
Every package includes a defined amount of collaboration and checkpoints, so you know upfront what involvement is expected from your team.
Public information analysis (OSINT)
Internal document analysis
Up to 30 pages included
Up to 100 pages included
100+ pages included
Requirements & priority alignment
Kick-Off / scoping call
Results walkthrough & debrief
15min walkthrough
30min workshop
Virtual workshops
2×2 hours
4×2 hours
Weekly project status calls
Optional Add-Ons
Optional add-ons allow you to extend or deepen specific aspects without upgrading the full package. Add-on pricing varies by scope and package.
Additional planning & implementation workshops
Additional pages for documentation review
Internal audit simulation & findings report
Azure & on-premises infrastructure deep-dive
Certification evidence package & audit preparation support
Integration with third-party tools
Risk register & SoA
Certification body liaison & support
Technical control implementation support (hands-on deployment)
Choose your package
Not sure which package fits? Contact us for a quick recommendation.
Managed Services for your ISMS
Information security is not a one-time project. Threats evolve, requirements change, and controls require continuous attention.
Our managed services help you ensure your security framework and measures remain effective, compliant, and audit-ready – without requiring permanent internal resources. Our different support levels have been developed to accommodate your individual needs.
Essentials Care
Ideal for small teams that want peace of mind without big budgets.
Compliance+ ⭐
For SMEs that need an audit-ready ISMS without hiring full-time staff
Managed ISMS
For organizations that need dedicated ISMS leadership without full-time CISO costs
All services are provided on a monthly basis and can be upgraded with additional modules & consulting based on your individual needs, e.g. surveillance/recertification audit support packages. All prices are net and exclude VAT. Our services are offered to businesses only.
Important: Managed services require an established ISMS baseline. For new clients with an existing ISMS, onboarding begins with a Foundation assessment (included with a 12-month commitment).
Individual consulting & expert support
Can’t find the right package for your situation, need highly specialized guidance, or more workshops than included? A senior architect designs each engagement around your specific needs. We scope and price each engagement individually based on your goals, timeline, and complexity.

From the first hour to the last, you benefit from concentrated expertise that directly advances your goals. Each consulting day is dedicated to your priorities – focused value, not overhead.
Consulting projects can be structured as intensive sprints or distributed over time to match your team’s capacity. We adapt the engagement model to your project and your team’s rhythm.
Every consulting engagement is aligned with your specific context – from M&A carve-outs to cloud security or optimization of your AI agents. No generic checklists, only targeted expertise where you need it most.
Frequently Asked Questions (FAQ)
We typically begin with a Discovery or Foundation assessment to establish transparency and define next steps.
Organizations with a clear understanding of their requirements may also
choose to start directly with the Acceleration package (ISMS design) or Transformation project (guided implementation).
All packages are designed to keep the effort on your side to a minimum.
For the Discovery assessment we only need basic details about your organization – we derive the rest from industry knowledge, regional regulations and publicly available information. A debriefing call afterwards is optional.
Every paid engagement starts with a dedicated scoping call and concludes with a structured debriefing. Acceleration and Transformation packages additionally include intermediate workshops, so you can steer the direction before the final delivery.
Paid packages also include analysis of relevant documents you provide – typically policies, internal guidelines, asset inventories, system documentation, or existing ISMS material. We may follow up with a short questionnaire. Both are optional, but they significantly improve the quality of what you receive.
Managed Services are built to take information security management off your desk as far as possible and keep your involvement minimal. Automatic or manual notifications about changes or incidents keep your security posture current and respond to relevant changes. We will be glad to implement the best working solution together with you.
Yes. Our packages, managed services, and individual consulting can be combined flexibly and tailored to your specific needs – either sequentially or in parallel.
Common combinations:
- Foundation → Acceleration → Compliance+ (sequential path)
- Transformation project + Individual consulting for specialized needs
(e.g., Azure architecture deep-dive) - Ongoing Managed ISMS + ad-hoc project work as your organization grows (e.g., M&A due diligence, new control implementation)
No. We prepare and support you throughout the certification process to ensure your ISMS is audit-ready for the scope provided, but certification decisions are always made by independent auditors.
That said, organizations that implement our recommendations will be well-prepared for successful certification. If findings are identified during certification, we’ll be glad to support your corrective action response.
Yes. While project-based engagements are scoped and contracted upfront and cannot be downgraded once started, you can upgrade to a higher-tier package during delivery by paying only the difference.
Ongoing managed services, however, are flexible and can be upgraded, downgraded, adjusted and cancelled at any time with 30 days’ notice unless agreed otherwise. Changes take effect at the start of your next billing cycle.
Optional Add-Ons can be added anytime, subject to availability.
Not necessarily. A fully mature ISMS is not required, but we do need an established security and ISMS baseline before ongoing managed services can begin.
If no suitable baseline exists yet, we typically establish it through one of our project packages. If you already operate an ISMS, we begin with a Foundation assessment to validate the baseline, align expectations and define the ongoing support scope.
All prices are net and exclude VAT. Our services are offered exclusively to businesses (Unternehmer within the meaning of §14 BGB).
You will receive an invoice compliant with German requirements (§14 UStG) once agreed project milestones or deliverables have been completed. German VAT is added where applicable. For business clients in other EU member states holding a valid VAT identification number, the reverse-charge procedure applies. Without a valid VAT ID, German VAT is charged. For clients outside the EU, our services are generally not subject to German VAT.
Managed services are billed monthly in advance, with discounted rates available for annual prepayment.
Depending on your location, payment is possible via:
- Bank transfer (SEPA) for EU payments
- Stripe – Secure online payment portal, providing local payment instructions for international clients and supporting both bank transfers and credit cards
Unless stated otherwise on the invoice, payment is due within 14 days of the invoice date.
Purchase orders (POs) are supported where required. Work begins after written confirmation of the proposed scope and pricing.
That’s a common and perfectly reasonable position – and our packages are built for it.
Our objective is to improve your security posture in a way that supports your business rather than obstructing it. An ISO 27001-aligned ISMS is an effective vehicle for getting there: it provides structure, prioritisation and evidence. But the certificate itself is a by-product, not the goal.
A customer sent a security questionnaire, an investor asked during due diligence, NIS2 brought them into scope, or an incident made the gaps visible: In each case the work is the same, the certificate is optional.
If you later decide to certify, most of the work will already be done. The structure is already in place.
