Skip to main content
Cybersecurity / GRC

NIS-2 compliance platform for a BCM and information security consultancy

NIS-2 brings the German Mittelstand under a cybersecurity regime it has neither a security department nor an in-house consultant for. A German consultancy for business continuity and information security worked with us to turn its scoping check, measure catalogue and self-assessment from spreadsheets into a multi-tenant platform — the first consultation free in the browser, then the tool for implementation.

← Back to all case studies
61 measures
725 implementation steps in the catalogue
14 sectors
criteria by size, revenue, balance sheet and classification
AI assistant
grounded in the BSIG, IT-Grundschutz and ISO 27001
1 year
from concept to production, team of two to three

Starting point

NIS-2 brings roughly 29,000 German companies under a cybersecurity regime for the first time. Most of them are mid-sized businesses with no security department, and their management is now personally liable for approving and overseeing the measures (§ 38 BSIG). Three questions arrive at the same time and in the wrong order: are we even in scope? What do the ten measure areas mean for us concretely? And how do we prove it to an auditor?

The consultancy had been answering those questions in engagements, and the answers lived where consulting answers usually live: in spreadsheets. A decision tree for the scoping question, a measure catalogue with hundreds of implementation steps, a self-assessment questionnaire — all correct, all maintained by hand, and none of it usable by a company without a consultant in the room. They wanted a product that does the first consultation for free, in the browser, without a sign-up — and then turns into the tool the company implements NIS-2 with.

Solution

The public entry point is a guided check along § 28 BSIG: sector, company size, revenue and balance sheet establish whether the company is in scope and whether it counts as an important or a particularly important entity. Companies in scope continue into a GAP self-assessment of 23 questions, and every no becomes a task. Before registering, the visitor already sees the plan of measures that registration will create; registration then creates the tenant, the first admin and that plan in one step. The whole path takes about ten minutes and costs nothing.

The consultancy's spreadsheet catalogue was imported with a purpose-built parser and became reference data: 61 measures across the ten BSIG measure areas, 725 implementation steps and the criteria that decide which measure applies to which company — 14 sectors, size, revenue and balance-sheet bands and the NIS-2 classification. Administration screens let the consultancy maintain all of it without a developer. As the BSIG and the BSI guidance evolve, that is a content change, not a release.

Inside the platform each measure is a task with sub-tasks on a kanban board: priority, assignee, due date, status, a review step before done, and comments. Changes reach every open browser over WebSockets, notifications and a daily digest keep owners informed, and progress is measured per measure, per area and overall for reporting to management. Every change is written to an append-only history with the state before and after; deletion is only ever a flag.

The NIS-2 assistant is a retrieval-augmented chat: the BSIG, the BSI IT-Grundschutz compendium and ISO/IEC 27001 material are stored as vectors, and every answer is generated from the passages that match the question. It is opened from a task, so “how do we implement this?” is answered for this measure in this company. Conversations stay per task and per tenant and never cross a company boundary.

For the supply chain the platform models the requirement of Art. 21(3) directly: a supplier register, a structured assessment per supplier with a risk score, recorded treatment of high risks, a contractual checklist with evidence uploads and a review cycle with reminders. The supply chain measure cannot be closed while a critical supplier has no valid assessment. The audit report for the authority, the auditor and internal committees is rendered server-side as a PDF from live data — plan of measures, state of implementation, ownership and supplier register included.

  • Free scoping check along § 28 BSIG, no sign-up, about ten minutes
  • Measure catalogue with 61 measures and 725 implementation steps, maintained by the consultancy itself
  • Kanban board with a review step, real-time updates and an append-only history
  • AI assistant with retrieval over the BSIG, IT-Grundschutz and ISO/IEC 27001, opened from the task at hand
  • Supplier register and per-supplier assessment along Art. 21(3)
  • Audit report as a PDF from live data, for the authority, the auditor and internal committees
  • Tenant isolation at the service layer, roles over 29 permissions, two-factor authentication and around 120 automated test suites — deployed with Docker on cloud infrastructure in Germany

Results

The platform is in production and the consultancy's customers implement NIS-2 with it. The first consultation is now a URL: a company finds out whether it is in scope and receives its own plan of measures without a meeting, a sign-up or a fee — the beginning of the working relationship rather than a brochure. Catalogue, questionnaire and criteria remain data the consultancy maintains itself, so a change in the law is a content update and not a development ticket.

Three decisions carried the project: building the free part first and as a real public flow, treating the consultants' spreadsheet as the domain model, and grounding the assistant in the source rather than in a generic language model.

  • The first consultation as a free, public flow that ends in the company's own plan of measures
  • The consultancy owns its content: catalogue, questionnaire and criteria are maintained without a developer
  • Compliance as a project with ownership, deadlines and review on one board instead of email threads and spreadsheets
  • An assistant customers trust, because its answers come from the law and the standards
  • Audit-ready evidence on demand, including a per-supplier supply chain record

Let’s turn your service into a digital product.

In an introductory call, we look at your consulting service, the repeatable workflows behind it, and the tool that could emerge. Together, we clarify whether a scoping workshop is the right next step.

Book a call
Collaboration

What clients say about working with us

01 — 04

They're wonderfully honest and upfront and provide incredible customer service as well. They go above and beyond; when one of our customers went bankrupt, Browserbite EOOD helped us get through that. If anyone needs help with anything technology-based, I always put them in touch with Browserbite EOOD. They're very knowledgeable.

They've already provided the prototype, which we're able to show our customers. We're just doing beta testing with them and fine-tuning the app on our end.

Angelique Bradford
Co-Founder, New Beginnings Consultation

The client and we as consulting partner were very happy with the quality and the cooperation with Browserbite.

Really feels like working with a partner who cares about the projects as much as we do.

Robert Vossen
Partner, Consulting Agency

Overall, the app has received positive feedback. After Browserbite EOOD implemented the platform, our users found the processes very practical. Previously, we had to provide training for these processes, and the app made everything more intuitive. Our users are happy to have that tool, and we now have better productivity and quality.

They delivered everything on time and on point. We communicated using Google Meet, constant phone calls, and Slack messages. Additionally, we used Google tools to share documents.

Dennis Goldbach
CEO, DevGold

Within 3 months we executed a live proof of our concepts and reached valuable insights into our business model. We started into the next project phase fast and will further develop our product.

The communication and bilateral understanding were superb.

Dennis Dedaj
CEO, DGTL MKRS