Your situation

Audits and IS audit for ISO 27001 and IT-Grundschutz

You operate an ISMS (information security management system) and need an ISO 27001 audit, a certification on the basis of IT-Grundschutz or an IS audit (IS-Revision)? We clarify the evidence required and plan the audit in the appropriate procedure.

Free of charge and without obligation.

  • BSI-certified for IS consulting and IS audit
  • BSI audit team leaders for ISO 27001 on the basis of IT-Grundschutz
  • ISO 27001 Lead Auditors on the team
A secuvera consultant explaining the joint plan to her team at a map
Certification to ISO 27001 and IT-Grundschutz: independent and transparent.

Your situation

Your ISMS is to be certified or reviewed in an IS audit – and you are looking for experienced auditors?

You have built an ISMS to ISO 27001 or based on BSI IT-Grundschutz and now need the evidence: initial certification or recertification to ISO 27001, an ISO 27001 certification on the basis of IT-Grundschutz, an IS audit without a certificate or, as a vehicle registration office, evidence of compliance with the i-Kfz minimum security requirements of the KBA (German Federal Motor Transport Authority).

Which procedure fits depends on who requires the evidence. Hardly anyone undergoes an IT-Grundschutz certification voluntarily – which makes it all the more important that the audit delivers more than just the certificate.

This is where we come in: our certified auditors for ISO 27001 on the basis of IT-Grundschutz, IS auditors and ISO 27001 Lead Auditors audit thoroughly and objectively. We care about the quality of our audits: we plan enough time so that findings are well founded and help you in substance. If we have previously advised you, for example on implementing IT-Grundschutz, we do not carry out the certification audit – the certification scheme rules this out.

Testing portfolio

Which audits we carry out

For organisations that already operate an ISMS and need the evidence.

ISMS certification and IS audit

  • Certification audit for ISO 27001 on the basis of IT-Grundschutz
  • Attestation for Basic Protection under IT-Grundschutz
  • IS audit and IS short audit according to the BSI guideline
  • ISO 27001 audit (initial certification and recertification) with partner certification bodies
  • Internal audits for preparation

i-Kfz (KBA MSA-i-Kfz)

Services & results

Four audit procedures, one standard: added value in substance, not a mandatory appointment

You get initial certification and recertification audits for ISO 27001 on the basis of IT-Grundschutz, IS audits or audits of the KBA's i-Kfz minimum security requirements, carried out by certified auditors, IS auditors and ISO 27001 Lead Auditors. The audits are planned so that findings are well founded and help you in substance; for IT-Grundschutz, the BSI decides on the certificate.

ISO 27001 audit, IT-Grundschutz certification, IS audit and i-Kfz audit follow different procedures. We first clarify which evidence you need and then audit according to the scheme prescribed in each case.

ISO 27001 on the basis of IT-Grundschutz

You need to have your organisation or part of it certified based on BSI IT-Grundschutz? Our experienced, certified auditors for ISO 27001 on the basis of IT-Grundschutz carry out the audit and submit the audit report to the BSI, which decides on certification.

Our standard: a professional and objective audit atmosphere, and added value in substance from the audit – not just the certificate at the end.

Audit report for the BSI

An audit report as the basis for the BSI's certification decision – with findings you can also learn from in substance.

IS audit according to the BSI guideline

Your ISMS must meet the requirements of BSI IT-Grundschutz but does not need certification? Then an IS audit according to the BSI guideline for IS audits (Leitfaden IS-Revision) demonstrates the security level achieved. There are different levels; in most cases, an IS short audit is sufficient. Our IS auditors ensure:

  • a thorough review along the topics described in the guideline
  • an honest and open assessment, mapped to your processes and your documentation
  • visibility of critical areas requiring urgent action
  • a clear assessment and a jointly defined set of next steps

IS audit report

An assessment of the security level achieved, with prioritised next steps.

ISO 27001 certification

You have built an ISMS to ISO 27001 and want to make your level visible with a certificate? We work with several certification bodies and carry out ISO 27001 audits in a pragmatic, goal-oriented and open way – including recertifications.

Our auditors know not only the standards but also the technologies and processes needed to reach a meaningful assessment. The certification body decides on the certificate.

i-Kfz: minimum security requirements of the KBA

Your vehicle registration office is subject to the KBA's minimum security requirements for internet-based vehicle registration (MSA-i-Kfz)? We have already audited a high double-digit number of registration offices across Germany. Our audit approaches are efficient, transparent and easy for you to prepare for:

  • i-Kfz audit / IS short audit
  • IS penetration test of the specialised application systems
  • IS penetration test of the connectors
  • IS web check of the specialised applications

Our expertise

Since December 2011, secuvera has been recognised by the BSI as a certified IT security service provider for IS audit. Several experienced, certified auditors for ISO 27001 on the basis of IT-Grundschutz, IS auditors and ISO 27001 Lead Auditors work in our company. For ISO 27001 audits, we work with several certification bodies.

Under the KBA's i-Kfz minimum security requirements, we have already audited a high double-digit number of registration offices across Germany – organisationally by audit or IS short audit and technically by IS penetration test and IS web check.

Because audits and penetration tests come from one company, you receive coordinated organisational and technical audits from a single source.

Getting started

Define the type of audit and the certification body

Clarify the evidence you need

Tell us the underlying standard, your scope and the planned certification or audit date. Existing certificates and previous audit findings are also part of the preparation.

Agree audit procedure and responsibilities

We discuss the appropriate type of audit, the documents required and the cooperation with the certification body.

Agree on an audit or IS audit
The points of a pair of dividers resting on coloured sticky notes above a map
Type of audit and certification body chosen to match your goal.

Audit and certification decision

The audit and the certification decision are separate. The scope of the audit and responsibilities are agreed according to the evidence required.

Questions about ISO 27001 audits, IT-Grundschutz and IS audit

What is the difference between an IS audit and a certification?

An IS audit assesses the security level according to the BSI guideline for IS audits, without requiring certification. There are different levels; an IS short audit is often an option. A certification, by contrast, follows the procedure of the responsible certification body.

Does secuvera carry out audits to ISO 27001 and on the basis of IT-Grundschutz?

Yes. Our team includes ISO 27001 Lead Auditors as well as certified auditors for ISO 27001 on the basis of IT-Grundschutz. Which audit framework applies depends on the evidence required and the certification procedure.

Can we also request a recertification?

Yes. For planning, the existing certificate, scope, previous findings and the intended date are important. We coordinate the audit and the cooperation with the responsible certification body.

Who issues the ISO 27001 certificate?

The responsible certification body decides on certification. secuvera provides the agreed audit services. The audit result and the certification decision are separate steps.

Can secuvera first advise us and then certify us?

Not for the same organisation. Under the certification scheme, consulting or coaching and the certification audit cannot be combined. If we have advised you, another body carries out the audit – and vice versa.

Articles on this topic (in German)

All 37 articles on the topic (in German)

How can we support you with certification and IS audit?