Information Security Management (ISMS)

Demonstrable information security to ISO 27001 and BSI IT-Grundschutz.

ISO 27001 certified ourselves

Our own information network is certified by the BSI to ISO 27001 on the basis of IT-Grundschutz (BSI-IGZ-0718-2026). We advise what we live ourselves.

Evidence: Certificate (PDF) · Report (PDF)

BSI-certified consultants

Our ISMS consultants are trained and certified as IT-Grundschutz consultants and practitioners to the requirements of the BSI.

Consulting and implementation from one team

Fixed, experienced points of contact instead of junior rotation. Management advises alongside and estimates the effort realistically.

Arrange a free initial consultation

Customers, tenders and regulations such as NIS-2 increasingly demand proof that your information security is organized and does not depend on chance. An information security management system (ISMS) provides exactly this proof: clear responsibilities, assessed risks and effective measures that are reviewed and lived. We build it with you, to ISO 27001 or BSI IT-Grundschutz, appropriate to your size instead of bureaucracy that no one lives.

What our customers build an ISMS for:

  • provide ISO 27001 evidence for customers, tenders and supplier audits
  • implement and demonstrate the requirements of the NIS-2 directive in a structured way
  • build information security and data protection (GDPR) together instead of side by side
  • evolve security from isolated solutions into a verifiable, lived organization

Risk management is the core of every ISMS: identifying, assessing and treating risks, and making the remaining residual risks transparent. We build this process so that it works day to day, not just on paper.

BSI IT-Grundschutz ConsultantIT-Grundschutz Practitioner (BSI)

„Certified competence in the ISMS: our consultants are trained and certified to the requirements of the BSI.“

Not sure yet where you stand? The free CyberRisikoCheck per DIN SPEC 27076 is the simplest entry point and gives you an initial assessment of where you stand, together with a roadmap.

Why zentrust?

ISO 27001 certified ourselves

We don’t just advise, we had our own ISMS certified to ISO 27001 on the basis of IT-Grundschutz (BSI-IGZ-0718-2026) and know every step from our own experience. Evidence: Certificate (PDF) · Certification report (PDF)

BSI-certified consultants

Our ISMS consultants are trained and certified as IT-Grundschutz consultants and practitioners to the high requirements of the BSI. Not knowledge picked up from reading, but proven methodology.

Consulting and implementation from one team

No handover break, fixed points of contact instead of shifting junior rotation. Management advises alongside, estimates the effort realistically and is accountable for the result itself.

Appropriate instead of oversized

An ISMS that fits your size and your risk. Lean and auditable, with a clear scope and a focus on the essential risks, instead of a document monster that no one maintains.

We enable your team

We build up internal knowledge instead of making you permanently dependent. If a role is missing internally, we take on that of the information security officer (ISB) on an interim or shared basis.

Independence preserved

We advise and support you up to the audit, the certification itself is done by an independent, accredited body. This separation is mandatory and keeps your certificate robust.

Two paths to your ISMS

Which standard fits you depends above all on who requires the evidence from you. We place this in context in the initial consultation and support you on both paths.

ISO 27001

The international, risk-based standard with a freely selectable scope, recognized worldwide and common among customers. Fits when international customers, tenders or group requirements demand the evidence. Leads to a certificate from an accredited body.

BSI IT-Grundschutz

The German methodology with very concrete building blocks that can lead to an ISO 27001 certificate on the basis of IT-Grundschutz. Fits for public administration, critical infrastructure (KRITIS) or when a BSI reference is required. We actively follow the coming expansion stage Grundschutz++ of the BSI, it is still in development.

Still unsure where you stand? The free CyberRisikoCheck per DIN SPEC 27076 gives small and mid-sized companies a neutral assessment of where they stand and a prioritized roadmap in a structured conversation, before you decide on a path.

Your path to an ISMS

We turn the standard into a plannable project with clear milestones. A typical path to a certifiable ISMS:

  1. Assessment
    Free initial consultation, optionally CyberRisikoCheck or gap analysis.
  2. Scope & objectives
    Define the scope, protection needs and target picture.
  3. Risk analysis
    Identify, assess and treat risks.
  4. Measures & documentation
    Policies, roles and the Statement of Applicability (SoA).
  5. Internal audit
    Review effectiveness, carry out the management review.
  6. Certification audit
    Guidance through the external audit in two stages.

How long it takes depends on your starting point and size, usually 6 to 12 months. After that, you keep the ISMS running in daily operation through the continuous improvement process (PDCA). On request, we support this operation too.

Show the assessment and evaluation formats in detail

Depending on your starting point, size and maturity, we choose the right format to determine your security level or to review an existing ISMS:

CyberRisikoCheck per DIN SPEC 27076

For small and micro enterprises (up to about 50 employees) without their own information security function, the free CyberRisikoCheck is the simplest entry point. It assesses around 27 requirements across six topic areas and provides prioritized recommendations for action.

IT-Grundschutz check

For companies building or developing an ISMS on the basis of BSI IT-Grundschutz, the IT-Grundschutz check systematically assesses structures, processes and measures in line with the BSI requirements and shows which steps are needed to reach the desired security level.

Maturity and implementation level assessment (BSI RUN)

For operators of critical infrastructure and within the scope of verification audits under the BSIG, the BSI maturity and implementation level assessment (RUN) offers a standardized procedure to determine the maturity and implementation level of information security. A KRITIS or verification-audit format, not a general maturity model.

IS audits

Organizations that already operate an ISMS to BSI IT-Grundschutz (common in public administration) we support with IS audits: from the compact IS short audit and the IS partial audit of individual areas to the comprehensive IS cross-sectional audit. They assess the effectiveness of existing measures and secure ongoing conformity with the BSI requirements.

Companies that trust us

CAOS AG
zubischuhe.ch AG
Wölfel Engineering GmbH + Co. KG
TeleClinic GmbH
Spital Bülach AG
QuickBird GmbH
NORDFROST GmbH & Co. KG
MD-IT GmbH
Kasparund AG
ITSG GmbH
Garrio GmbH
eHealth Experts GmbH
CompuGroup Medical Deutschland AG
BARMER

The way your new reports link MITRE to the vulnerabilities is seriously impressive … really well done. That is worth its weight in gold for our threat analyses.

Customer, statutory health insurer

The pentest surfaced real issues, led to concrete fixes, and gives us a solid baseline to build on.

Erlang Ecosystem Foundation, on our security audit, public report on hex.pm

Frequently asked questions

How long does it take to reach ISO 27001 certification?

Depending on your starting point and the size of your organization, plan on roughly 6 to 12 months for building and certifying the system, and longer for more complex organizations. What matters is that the ISMS has actually been lived for a few weeks to months before the certification audit, including an internal audit and a management review, so that auditable evidence exists. The external audit runs in two stages (document review, then on-site audit). The certificate is valid for three years with annual surveillance audits.

ISO 27001 or BSI IT-Grundschutz, which one fits us?

ISO/IEC 27001 is the international, risk-based standard with a freely selectable scope, recognized worldwide and common among customers. BSI IT-Grundschutz is a German methodology with very concrete building blocks that can lead to an ISO 27001 certificate on the basis of IT-Grundschutz. Rule of thumb: ISO 27001 for international or customer-driven needs, IT-Grundschutz for public administration, critical infrastructure (KRITIS) or when a BSI reference is required. In the free initial consultation we place this in context for your situation.

Do we absolutely need a certified ISMS for NIS-2?

No, a certificate is not required by law. However, NIS-2 does require appropriate technical and organizational risk management measures, a registration, reporting obligations for significant security incidents and accountability of top management. An ISMS to ISO 27001 or BSI IT-Grundschutz is the most practical way to implement and demonstrate these obligations in a structured way. First clarify whether you are affected, based on sector, size and revenue.

More on NIS-2

Internal or external information security officer (ISB)?

An internal ISB knows the company and builds up internal knowledge, but needs a time budget, training and a certain independence from IT operations to avoid conflicts of interest. An external ISB brings expertise and neutrality immediately and spares you from building up internal staff. In practice, a hybrid model often proves its worth: an external ISB handles the setup and interim role while internal competence grows step by step. For small teams, an external or shared ISB is frequently the most economical solution.

How much effort is involved for a small team?

The ISMS can be scaled to size and risk, ISO 27001 requires appropriateness, not a maximum. For a small team that means a narrow scope, a focus on the essential risks and lean but auditable documentation. In ongoing operation, expect roughly a fraction of a full-time position, and during the introduction project temporarily higher effort over a few months. External support reduces the internal load and keeps a single person from burning out.

What does building an ISMS cost?

The cost depends heavily on size, scope, existing maturity and the chosen standard, so a reliable figure is only possible after a brief stocktake. Certification by an accredited body is billed separately, is based on audit days and recurs annually for the surveillance audits. On top of this come internal effort and, where applicable, tool costs. Starting with a gap analysis or CyberRisikoCheck creates cost transparency early, before you commit.

What does the CyberRisikoCheck offer as an entry point?

The CyberRisikoCheck per DIN SPEC 27076 is a standardized format designed specifically for small and micro enterprises (up to about 50 employees). In a structured interview, around 27 requirements across six topic areas are assessed, and you receive a report with the current status, risk priorities and concrete recommendations for action. It does not replace a full ISMS, but works as a low-threshold entry point to determine your maturity level and derive a roadmap toward ISO 27001 or IT-Grundschutz. We carry it out for you free of charge.

To the free CyberRisikoCheck

As a Swiss company, are we affected by NIS-2?

Switzerland does not transpose NIS-2, and Swiss companies are not directly subject to EU supervision. You can still be affected through EU subsidiaries, through digital services in the EU area and, above all, through the supply chain, when EU customers pass the requirements on to you via contracts, audit rights and reporting obligations. In addition, the Information Security Act (ISG) applies in Switzerland. An ISMS to ISO 27001 is the usual way to meet such customer and contractual requirements in a demonstrable way.

Do you advise us, or do you also certify us yourselves?

We advise and support you during the setup and up to the audit. The certification itself is deliberately performed by an independent, accredited certification body. This separation is mandatory: the same body may not both advise and certify you. This keeps your certificate independent and robust. We work smoothly and routinely with the accredited bodies.

Effective security for your organization.

We build your management system to BSI IT-Grundschutz or ISO 27001, just as we run our own. Arrange a free initial call.