Cybersecurity · NIS2 · ISO 27001
Compliance Navigator
Understand requirements and prepare your next management decisions.
ITCST Compliance Navigator
What does your management need to clarify now?
Four short steps provide an indicative assessment, three concrete management decisions and a shareable executive brief in about 90 seconds.
NIS2 · ISO/IEC 27001 · BSI
Concise management guidance—not an audit in the browser.
No sign-up · unverified self-assessment · not an audit or legal advice. For a download or enquiry, the Navigator passes selection identifiers only; contact details are processed only in the separate enquiry form.
- 01Possible classificationImportant, essential or requiring review
- 02Control areasTen measure areas plus the ISMS view
- 03Reporting & governance24h, 72h, final report and internal incident record
01 · Assessment objective
What do you want to clarify first?
02 · Sector and size
Which primary activity best describes your organisation?
For critical infrastructure, the specific facility—not the size band—is decisive. Otherwise, classification may depend on group, linked-enterprise, turnover/balance-sheet and special rules. DORA, energy, telecommunications and cross-border cases require individual review.
03 · Existing baseline
How is information security currently organised?
04 · Operational readiness
Which foundations do you consider established?
Multiple-choice self-assessment; evidence is not verified here. Confirm explicitly if nothing has been assessed yet.
Your indicative management assessment
Unverified assumptions
Validate the classification and decision path professionally, or share the executive brief internally.
03Review the basis of the assessment
- Objective
- Sector
- Size
- Baseline
- Self-assessed foundations
04Review special regimes and legal boundaries
Special regimes: for certain activities regulated under German telecommunications or energy law and for DORA financial entities, the duties shown here under sections 30, 32, 35 and 38 BSIG may not apply in whole or in part. Critical infrastructure is subject to additional duties. For digital entity types named in section 30(3), more specific EU requirements take precedence. Other activities and cross-border constellations require separate review.
Special case unresolved: for the digital entity types named in section 30(3), the more specific EU implementing requirements take precedence; telecommunications services may be subject to more specific rules. General duties and reporting deadlines are therefore not inferred here.
Critical-infrastructure add-on review: attack-detection systems, extended reporting data and recurring evidence may additionally be required (sections 31, 32(3) and 39 BSIG). In addition to the NIS2 entity logic shown here, separate facility registration under section 33(2) BSIG and physical-resilience duties under Germany’s KRITIS umbrella law must be reviewed.
05Open duties and ISMS requirements
- Management: implement and supervise proportionate measures; management participates regularly in training.
- Risk management: document technical and organisational measures.
- Registration: no later than three months after the entity first or again qualifies as an essential or important entity; submit changes without undue delay and no later than two weeks after becoming aware of them.
- Reporting: assess significant incidents and submit them within the statutory sequence.
- Information: recipients affected by an incident may also need to be informed.
ISO/IEC 27001 structures scope, leadership, risk treatment, documented operation, performance evaluation and improvement. Necessary Annex A controls follow from risk and the Statement of Applicability—not from a blanket checklist.
No NIS2 duty is inferred from these inputs. This is not an exemption; precise activities, group indicators and special regimes still require review.
06Open the high-level control map
Ten measure areas if section 30 applies
Concise management guidance—not a reproduction of individual controls, a control mapping or audit evidence.
Risk analysis & security policies
Security incident handling
Business continuity & crisis management
Supply-chain security
Secure acquisition, development & maintenance
Effectiveness assessment
Security awareness & training
Cryptography & encryption
People, access & assets
MFA, authentication & secure communications
The requirements form the management system. Necessary controls are determined from risk and justified in the Statement of Applicability.
The 93 Annex A controls are not an automatic checklist. Relevant controls are selected and justified through risk treatment and the Statement of Applicability. These four themes provide only the top-level view.
07Open BSI reporting and internal incident governance
BSI reporting and internal incident record
This deadline sequence applies only where BSIG applicability has been confirmed and the security incident has been assessed as significant. The internal incident record is not a statutory BSI ticket format and never replaces the BSI notification.
Initial threshold for “significant”: the incident has caused or can cause severe service disruption or financial loss; alternatively, it has caused or can cause significant material or non-material harm to others. Any specification under section 56(5) BSIG must be checked for the individual case.
- Internal · immediatelyOpen incident recordCapture awareness time, accountable person, assessment, decisions and reporting references.
- Without undue delay · no later than 24hEarly notificationState suspected unlawful or malicious activity and possible cross-border impact.
- Without undue delay · no later than 72hIncident notificationSeverity, impact and available indicators of compromise.
- BSI requestInterim reportSubmit separately if requested by the BSI while the incident is being handled.
- No later than 1 month after submission of the incident notificationFinal notificationIncluding cause, measures and cross-border impact; if handling continues, submit a progress notification first.
The entity must register through the BSI portal no later than three months after it first or again qualifies as an essential or important entity; changes must be submitted without undue delay and no later than two weeks after becoming aware of them. Access, reporting authority, deputy coverage, management escalation and local deadline control should be ready before an incident. During the transition, critical-facility operators and federal authorities use MIP as the primary incident-reporting route; an identical duplicate report in the BSI portal is not required.
Indicative guidance from unverified self-assessment; legal position as of 4 September 2026. Not legal advice, authority guidance, a conformity assessment or certification statement.
Defined engagement frameworks
Transparent investment framework.
The compact assessment remains free. Validation, readiness and implementation use clearly scoped B2B engagement frameworks.
Executive Compliance Validation
€3,300 netDocument review, 90-minute workshop, validated assessment and management note with three prioritised decisions.
Clarify the scope →NIS2 & ISO Control Readiness
€13,200–€19,800 netHigh-level gap analysis, control-area mapping, evidence position and review of governance, reporting and internal incident governance.
Frame readiness →Compliance Implementation Sprint
€22,000–€33,000 net90-day roadmap, RACI, incident and reporting templates, action governance and management cadence through dependable handover.
Scope implementation →Full Compliance Navigator · software
Enterprise scope-based frameworkThe later full version will manage control mappings, evidence, actions, accountability and maturity. It is deliberately not part of this free high-level check; licensing and implementation will be scoped separately.
Register interest in the roadmap →B2B fees exclude applicable VAT. The project corridor is fixed before engagement based on entities, sites, IT/OT scope and available evidence.