GRC & Compliance
·FIVE SERVICE BUILDING BLOCKS

Compliance you can actually steer.

We combine ISO 27001, NIS 2, GDPR, the EU AI Act and risk management into one clear program of measures, controls and evidence.

Risk Management

Capture and assess risks and steer them in a risk register that both management and auditors can read.

ISO 27001

Implementation and certification of an ISO 27001-compliant ISMS. Strengthen the security level, build trust with customers and partners.

NIS 2

Implementation of the NIS 2 requirements. Strengthen cyber resilience, ensure compliance for critical infrastructure.

GDPR

Establish and maintain GDPR compliance. Optimize data protection processes, reduce regulatory risk.

EU AI Act

EU AI Act compliance. Make AI systems transparent, secure and trustworthy. Minimize regulatory risk.

ISO/IEC 27001:2022 certified
We live what we advise. GermanAI Defense has itself been certified to ISO/IEC 27001:2022 since May 2026, audited by the accredited certification body A-Mark Ratings Limited (certificate no. 26052601, valid until 25 May 2029). More on Security & Compliance →
USE CASES

Situations where we support you

GRC & Compliance
GRC & Compliance

Prepare ISO 27001 with structure

Problem
Many companies want to pursue ISO 27001 but don’t know which processes, controls, and evidence are missing.
Approach
We run the gap analysis, build the ISMS structure, plan the measures, and prepare documentation and the audit.
Benefit
A clear path to certification readiness, less organizational chaos, and better security governance.
GRC & Compliance Consulting
GRC & Compliance
GRC & Compliance

Implement NIS-2 requirements

Problem
The NIS-2 Directive raises requirements for cybersecurity, governance, risk management, and audit readiness.
Approach
We run the maturity analysis, plan the measures, define roles and processes, and implement in a documentable way.
Benefit
You know whether you fall under NIS 2, which of the Article 21 duties are still open, and who in the organization is responsible for what.
GRC & Compliance Consulting
GRC & Compliance
GRC & Compliance

Connect GDPR and security cleanly

Problem
Data protection and IT security are often handled separately, even though they’re operationally tightly coupled.
Approach
We connect data-protection requirements, technical and organizational measures, and security architecture into a traceable overall picture.
Benefit
One set of measures that satisfies both the data protection officer and the ISO auditor, instead of two separate lists.
GRC & Compliance Consulting / Cybersecurity Services
GRC & Compliance
GRC & Compliance / AI Solutions

EU AI Act: readiness for AI systems

Problem
Companies use or plan AI but often don’t know which requirements arise around transparency, risk, data quality, and governance.
Approach
We assess the AI use cases, classify the risk, build the governance structure, and set up documentable control processes.
Benefit
Every AI system has a documented risk class and an owner before the regulator asks.
GRC & Compliance Consulting / AI Solutions
GRC & Compliance
GRC & Compliance

Build business continuity & disaster recovery

Problem
NIS 2 and ISO 27001 demand resilient continuity plans. Yet many companies lack a business impact analysis, a documented recovery sequence, and rehearsed crisis roles.
Approach
We build the BCM framework, map critical processes, derive RTO / RPO, create disaster recovery plans, set up crisis management teams, and plan the exercises.
Benefit
Ready to act when it counts, demonstrable to regulators and customers, with recovery times you can calculate instead of guess.
GRC & Compliance Consulting
GRC & Compliance
GRC & Compliance

BSI IT-Grundschutz for public sector and critical infrastructure

Problem
Public authorities and critical-infrastructure operators must work to BSI IT-Grundschutz, often without a current asset inventory and without the evidence a procurement office asks for.
Approach
We inventory the systems, determine the protection needs, map the modules from the IT-Grundschutz compendium, and prepare the assessment.
Benefit
Ready for the assessment, with the eligibility evidence a procurement office requires.
GRC & Compliance Consulting
GRC & Compliance
GRC & Compliance

Implement DORA for financial services

Problem
DORA requires financial firms to prove digital operational resilience, an ICT risk-management framework, and defined reporting channels. Many firms don’t know where they stand.
Approach
We clarify whether you are in scope, review ICT risk management against the DORA requirements, and set up testing and reporting processes.
Benefit
Digital operational resilience you can demonstrate to the supervisor, without a parallel structure separate from ISO 27001.
GRC & Compliance Consulting
·BUSINESS CONTINUITY · BCM

When the worst case hits, operations stay able to act.

NIS 2 mandates business continuity, ISO 27001 requires it in Annex A.5.29 / A.5.30, ISO 22301 provides the framework. We build the BCM framework, identify critical processes, rehearse the crisis case and steer the recovery sequence until it is solid.

Framework & Governance

Build the BCM framework, anchor policies and governance structures, manage recurring compliance activities.

Business Impact & Risk

Map critical business processes, perform Business Impact Analyses (BIA) and risk assessments, derive RTO / RPO.

Disaster Recovery & Restart

Create disaster recovery plans, define restart sequences, regular testing and optimization of the recovery paths.

Crisis Management

Set up and coordinate crisis management teams, plan crisis exercises and BCM tests, carry lessons learned into regular operations.

·APPROACH

From gap analysis to audit-ready operations

Five phases in which frameworks, risks, controls, evidence and audit are considered together.

01Gap analysis

Systematically assess frameworks, maturity, gaps and risks.

02Target picture

Define scope, compliance goals and roadmap.

03Measures

Implement controls, processes, documentation and technical safeguards.

04Evidence

Provide risk register, RoPA, Statement of Applicability and audit trail.

05Audit & Operations

Internal audit, certification and continuous improvement.

For operational implementation, Cybersecurity can be connected as a complement, from the 24/7 SOC to penetration-testing support.

View Cybersecurity →