We carry out the CyberRisikoCheck per DIN SPEC 27076 with you, free of charge: an assessment of your information security level developed by Germany’s Federal Office for Information Security (BSI). At the end, you hold an evaluated report with prioritized recommendations. This holds whether or not we work together afterwards.
Arrange a free initial call (15 minutes)
When is the CyberRisikoCheck the right step?
Typical situations in which organizations come to us:
- A customer asks for security evidence. A NIS-2-regulated client passes security requirements down to its suppliers. Suddenly there is a security questionnaire on your desk.
- NIS-2, CRA and new obligations. Your own scope is unclear, yet management must already implement and oversee the cybersecurity measures itself and is liable for breaches of duty (Section 38 BSIG).
- Your cyber insurer requires evidence of your security level at renewal.
- An audit or certification is coming up, or a customer asks for proof of a penetration test. First you need clarity on where you stand.
- An incident nearby. A competitor made the news. You want to know how your own organization is doing.
What you get
The CyberRisikoCheck is a standardized procedure developed by the BSI (DIN SPEC 27076): a structured interview along 27 requirements across 6 topic areas, carried out by a BSI-qualified expert. It is not an automated scan.
As a result you receive an evaluated report with:
- an assessment of your current information security level (maturity score),
- prioritized recommendations: what comes first and what can wait,
- a document you can present: to management, customers, insurers or auditors.
How it works
- Free initial call (about 15 minutes). We clarify whether the CyberRisikoCheck is the right step for your organization and schedule the interview sessions.
- The CyberRisikoCheck (about one to two hours, in two sessions if needed). A structured interview, remote or on site. There is no extra work for your team: you only keep relevant documents at hand if they exist. DIN SPEC 27076 provides for the participation of management. Where they exist, IT managers and external IT service providers join as well.
- Evaluation and report handover. You receive the evaluated report with prioritized measures and an honest assessment of the next step. The CyberRisikoCheck is an organizational assessment. Where you need to demonstrate the effectiveness of your measures technically, a penetration test is the next step.
Who is the CyberRisikoCheck for?
Suitable for organizations without their own information security function, from small businesses to mid-sized companies: there is (as yet) no dedicated information security officer and no lived ISMS, but growing requirements from customers, insurers or regulation.
Not the right instrument if you already have an information security officer (ISO/CISO) and an established ISMS. In that case, starting directly with a penetration test or red teaming makes more sense.
Frequently asked questions
What does the CyberRisikoCheck really cost?
Nothing. The CyberRisikoCheck is free for you, including evaluation and report. You take on no obligation. We invest this time because some participants choose to work with us afterwards. Whether you do is your decision.
How much effort does it take on our side?
For the interview itself, plan one to two hours, depending on size and IT landscape, in two sessions if needed. Add the 15-minute initial call. What matters most is having the right people present: management and your IT manager or external IT service provider, where they exist. No elaborate preparation is needed. Two things simply make the conversation more efficient: keep existing documents at hand (such as security policies, backup and contingency plans, role and access concepts, or reports from earlier audits) and have your most important assets in mind, that is the data, systems, and processes your business cannot do without.
Is this a penetration test?
No. The CyberRisikoCheck is an organizational assessment by structured interview. Nothing is scanned and nothing is attacked. The technical effectiveness check of your security measures is done by a penetration test.
Who carries out the check?
A senior consultant from our management team, qualified by the BSI for the CyberRisikoCheck. These are the same people who are responsible for our testing and consulting projects. We do not hand off to a different team.

