ISO 27001 Consulting
ISMS Consulting &
ISO 27001 Certification -
from hackers who know
what really matters
We guide you through building your ISMS - from gap analysis to successful ISO 27001 certification. Practical, fixed-price and with the unique perspective of an offensive security firm.
Beispielwerte · Ihre Analyse individuell
These organisations trust us
- ISMS projects completed
- 20+
- Certification success rate
- 100%
- Months avg. to certificate
- 6-9
- Controls per ISO 27001:2022
- 93
What is an ISMS under ISO 27001?
An Information Security Management System (ISMS) is a systematic framework of policies, processes and technical controls to protect your organisational information. The international standard ISO/IEC 27001:2022 defines the requirements for such a system and enables independent certification by accredited certification bodies.
The current ISO 27001:2022 version comprises 93 controls in four categories: organisational, people, physical and technological measures. Unlike the German BSI IT-Grundschutz with its ~800 requirements, ISO 27001 offers more flexibility in selecting measures - ideal for internationally operating companies and the mid-market.
ISMS certification to ISO 27001 is increasingly business-critical: it fulfils most NIS-2 requirements, is demanded by large clients in tenders and significantly reduces cyber insurance premiums. For automotive suppliers subject to TISAX, an ISMS forms the foundation of information security.
Why act now
Why organisations need an ISMS under ISO 27001
Regulatory and economic requirements for information security are rising rapidly. Those who do not act now risk more than just fines.
NIS-2 compliance obligation
The NIS-2 Directive obliges thousands of organisations to implement systematic risk management. Management bears personal liability. An ISO 27001 ISMS fulfils most requirements.
Supply chain requirements
Major clients and public sector buyers require ISO 27001 in tenders. Without the certificate you lose contracts to competitors who can provide the evidence.
Cyber insurance & liability
Insurers are scrutinising security measures ever more closely. A certified ISMS significantly reduces premiums - and protects management from personal liability.
Our difference
ISO 27001 consultants
who actually hack
Most ISMS consultants only know attacks from textbooks. Our ISO 27001 consultants conduct penetration tests and red team assessments themselves. This makes a decisive difference:
-
Risk assessment from an attacker's perspective
We know which vulnerabilities attackers exploit first - and prioritise your ISMS accordingly.
-
Controls that work - not just exist on paper
No paper exercise: every measure is defined so that it will withstand a real attack.
-
Pentest integration from day one
We can validate the effectiveness of your ISMS directly with penetration tests - everything from one source.
-
Certified ourselves - we live what we advise
AWARE7 is itself certified to ISO 27001 and ISO 9001. We know the challenges from first-hand experience.
AWARE7 Credentials
Offensive Security + ISMS
ISO 27001:2022 certified
AWARE7 itself - not just our clients
ISO 9001:2015 certified
Quality management - standardised processes
BSI CyberRiskCheck
Authorised assessment provider per DIN SPEC 27076
OSCP, OSWA, OSWP
Offensive security certifications of our consultants
T.I.S.P. Certificate
Personal certification for ISMS teams - recognised in 32 countries
ISMS consulting services: From gap analysis to certification
From the initial inventory through ISMS implementation to ongoing operations - everything from one source.
Gap Analysis & Maturity Assessment
Review against all 93 controls of ISO 27001:2022. Detailed maturity report with heatmap, recommendations and project plan.
RequestISMS Implementation
Risk management, documentation, policies, SoA, technical and organisational measures. Training for staff and management.
RequestCertification Support
Internal audit as a dress rehearsal, preparation for the external certification audit. We are by your side until the certificate is on the wall.
RequestOperations & Continual Improvement
Surveillance audit preparation, management reviews, risk updates, re-certification. Your ISMS will be lived, not just documented.
RequestExternal CISO
Qualified information security officer as a service. Ideal for SMEs that do not need a full-time position for the role.
DetailsCustom scope?
ISO 27001 + 9001, TISAX, or IT-Grundschutz - we adapt to your needs.
Where does your organisation stand today?
In a free 30-minute initial consultation we assess your current state, define the scope and give you a realistic estimate of effort and timeline.
Kostenlos · 30 Minuten · Unverbindlich
Engagement models
ISO 27001 certification costs: Transparent and plannable
No open consultant days, no hidden costs. You know from the outset what ISO 27001 certification costs.
One-time
ISO 27001 Certification Project
From gap analysis through ISMS implementation to the certificate - everything included.
from EUR 20,000
Fixed price, depending on scope & maturity
- Gap analysis & maturity report
- Risk management & SoA
- Policies & documentation
- Internal audit & certification support
- Dedicated point of contact
Monthly
ISMS Retainer
Certification + ongoing support - your ISMS in the best hands.
from EUR 2,500/mo
12-month minimum term
- Everything from the certification project
- Surveillance audit preparation
- Quarterly management reviews
- Ongoing risk updates
- Re-certification support
- Annual penetration test included
Monthly
External CISO
Your information security officer - without a full-time position.
from EUR 1,500/mo
Flexible cancellation, scalable
- Operational ISMS management
- Audit coordination
- Training & awareness
- Management reporting
- Incident response coordination
Individual pricing for your organisation
Scope, company size and existing maturity level determine the price. We provide a binding fixed-price quote within 48 hours.
ISO 27001 vs. BSI IT-Grundschutz: Which standard fits?
| Criterion | ISO 27001 | BSI IT-Grundschutz |
|---|---|---|
| Scope | Internationally recognised | Primarily DACH region & public sector |
| Requirements | 93 controls (flexibly selectable) | ~800 requirements (catalogue-based) |
| Effort (SME) | 6-12 months | 12-24 months |
| Cost | from EUR 20,000 | from EUR 40,000 |
| Ideal for | Internationally operating companies, mid-market | Public administration, critical infrastructure operators |
| NIS-2 conformity | Yes, accepted as evidence | Yes, accepted as evidence |
Our recommendation: For most organisations, ISO 27001 is the more efficient path. ISO 27001 certification based on IT-Grundschutz is also possible - we advise vendor-neutrally.
NIS-2 Compliance
ISO 27001 fulfils most NIS-2 requirements
The NIS-2 Directive requires a cybersecurity risk management system with concrete measures: incident handling, business continuity, supply chain security, encryption. An ISO 27001-compliant ISMS covers these requirements and is accepted as evidence.
Important: Management bears personal liability for NIS-2 violations. A certified ISMS is the best protection - for your organisation and for you personally.
NIS-2 requirements in detailYour ISMS grows with you
Not a one-time project - security that improves itself
ISO 27001 is based on the proven PDCA principle: you plan measures, implement them, check their effectiveness - and improve continuously. The result: an ISMS that does not become obsolete, but grows with your organisation. We guide you through all four phases.
- Erstgespräch und Bedarfsanalyse
- Bestandsaufnahme Ihrer IT-Landschaft
- Risikobewertung und Priorisierung
- Maßgeschneiderter Projektplan
Building an ISMS: The path to ISO 27001 certification in 5 phases
How the ISMS implementation works - five clearly defined phases from initial assessment to certificate.
Gap Analysis & Scope Definition
Where does your organisation stand today? We capture the current state, review against all 93 controls, define the ISMS scope and identify the biggest gaps.
Duration: 1-2 weeks
Risk Assessment & Treatment
Systematic identification and assessment of your information security risks per ISO 27005. Risk treatment plan with economically sensible measures.
Duration: 2-4 weeks
Documentation & Policies
Creation of all required documents: information security policy, guidelines, procedures, Statement of Applicability (SoA). Practical, not bureaucratic.
Duration: 4-8 weeks
Implementation & Training
Deployment of technical and organisational measures. Training for staff and management. Integration into existing business processes.
Duration: 4-12 weeks
Internal Audit & Certification Support
Conducting the internal audit as a dress rehearsal. Supporting the external certification audit - we are by your side until the certificate is on the wall.
Duration: 2-4 weeks
Why AWARE7 for your ISMS
Was uns von anderen Anbietern unterscheidet
Reine Awareness-Plattformen testen keine Systeme. Reine Beratungskonzerne sind zu weit weg. AWARE7 verbindet beides: Wir hacken Ihre Infrastruktur und schulen Ihre Mitarbeiter - mittelstandsgerecht, persönlich, ohne Enterprise-Overhead.
Forschung und Lehre als Fundament
Rund 20% unseres Umsatzes stammen aus Forschungsprojekten für BSI und BMBF. Unsere Studien analysieren Millionen von Websites und Zehntausende Phishing-E-Mails - publiziert auf ACM- und Springer-Konferenzen. Drei unserer Führungskräfte sind gleichzeitig Professoren an deutschen Hochschulen.
Digitale Souveränität - keine Kompromisse
Alle Daten werden ausschließlich in Deutschland gespeichert und verarbeitet - ohne US-Cloud-Anbieter. Keine Freelancer, keine Subunternehmer in der Wertschöpfung. Alle Mitarbeiter sind sozialversicherungspflichtig angestellt und einheitlich rechtlich verpflichtet. Auf Anfrage VS-NfD-konform.
Festpreis in 24h - planbare Projektzeiträume
Innerhalb von 24 Stunden erhalten Sie ein verbindliches Festpreisangebot - kein Stundensatz-Risiko, keine Nachforderungen, keine Überraschungen. Durch eingespieltes Team und standardisierte Prozesse erhalten Sie einen klaren Zeitplan mit definiertem Starttermin und Endtermin.
Ihr fester Ansprechpartner - jederzeit erreichbar
Ein persönlicher Projektleiter begleitet Sie vom Erstgespräch bis zum Re-Test. Sie buchen Termine direkt bei Ihrem Ansprechpartner - keine Ticket-Systeme, kein Callcenter, kein Wechsel zwischen wechselnden Beratern. Kontinuität schafft Vertrauen.
Für wen sind wir der richtige Partner?
Mittelstand mit 50–2.000 MA
Unternehmen, die echte Security brauchen - ohne einen DAX-Konzern-Dienstleister zu bezahlen. Festpreis, klarer Scope, ein Ansprechpartner.
IT-Verantwortliche & CISOs
Die intern überzeugend argumentieren müssen - und dafür einen Bericht mit Vorstandssprache brauchen, nicht nur technische Findings.
Regulierte Branchen
KRITIS, Gesundheitswesen, Finanzdienstleister: NIS-2, ISO 27001, DORA - wir kennen die Anforderungen und liefern Nachweise, die Auditoren akzeptieren.
Mitwirkung an Industriestandards
OWASP · 2023
OWASP Top 10 for Large Language Models
Prof. Dr. Matteo Große-Kampmann als Contributor im Core-Team des international anerkannten OWASP LLM-Sicherheitsstandards.
BSI · Allianz für Cyber-Sicherheit
Management von Cyber-Risiken
Prof. Dr. Matteo Große-Kampmann als Mitwirkender des offiziellen BSI-Handbuchs für die Unternehmensleitung (dt. Version).
Security is also social responsibility
AWARE7 is committed beyond day-to-day business: as the founder of a scholarship at Ruhr University Bochum we support the next generation of IT security professionals. We are a member of the Alliance for Cyber Security of the BSI and train our own specialists. Our R&D certificate confirms our innovative strength in cybersecurity research.
More about AWARE7Frequently asked questions about ISMS consulting & ISO 27001 certification
What is an ISMS?
How long does ISO 27001 certification take?
What does ISO 27001 consulting cost?
Can you build ISO 27001 and ISO 9001 simultaneously?
Do we really need ISO 27001?
What happens after certification?
What is the difference between ISO 27001 and BSI IT-Grundschutz?
Is there a connection to the NIS-2 Directive?
How does the gap analysis work?
Does AWARE7 work vendor-neutrally?
What makes AWARE7 special as an ISMS consultant?
Can AWARE7 also act as an external CISO?
What does ISO 27001:2022 require?
What changed with ISO 27001:2022?
How does an ISO 27001 audit work?
Three steps to ISMS certification
No project marathon. Starting your ISO 27001 consulting with AWARE7 is this simple.
Initial consultation
30 minutes, free of charge. We assess your current state and define the scope.
Fixed-price quote in 48h
Binding, transparent, no hidden costs. Including a realistic timeline.
ISMS build begins
Your dedicated contact starts with the gap analysis. Regular status updates guaranteed.
Aus dem Blog
Weiterführende Artikel
Alle ArtikelReady for the next step?
NIS-2 requires a cybersecurity risk management system. Management bears personal liability. An ISO 27001 ISMS protects your organisation - and you.
Kostenlos · 30 Minuten · Unverbindlich