What must I demonstrate, and is it documented?
NIS-2 minimum measures from § 30 of the German BSI Act, ISO 27001 Annex A, DORA requirements with status per control and documented evidence. On demand as PDF.
OdySecure, the security platform by Cybervize, answers the question "Where do we stand?" with source and metric and delivers the evidence you need for BSI, supervisory board, auditors and insurers. Including the duties for which management is personally accountable under NIS-2. In 30 minutes we clarify, free of charge, where you stand.
Book the risk checkFour answers every management board should have ready for the supervisory board, the insurer and the auditor. The platform delivers them on demand.
NIS-2 minimum measures from § 30 of the German BSI Act, ISO 27001 Annex A, DORA requirements with status per control and documented evidence. On demand as PDF.
Risk register with owner, treatment status and 12-month trend. You see immediately which risks need active management decisions.
Measure register with budget annotation, owner, due date. Before every supervisory board meeting you can say what you have committed for which risk reduction.
Audit trail with timestamp, owner, versioning. Re-audits, supplier requests and external audits become an on-demand exercise rather than an Excel battle.
Four reasons that recur in board conversations. None of them is a tech statement.
The platform codifies 25 years of ISMS leadership at PwC, Deloitte and KPMG. You get DAX-level methodology without the hourly rates and programme inertia of Big-Four engagements.
Module licence or vCISO bundle with a clear monthly price. Budgetable, no risk of open T&M mandates, no surprise invoice at quarter-end.
KPI dashboards and PDF reports in the language of corporate leadership. Maturity heatmaps, top-10 risks, compliance status for NIS-2, ISO 27001 and DORA, 12-month trend.
Led by an ISO 27001 Lead Auditor since 2006 and a BSI IT-Grundschutz auditor. Platform evidence is built for the audit situation: timestamp, owner and version on every entry.
Management boards most often start with the free 30-minute risk check, which provides the basis for the next decision.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn moreThe platform, permanent CISO function bookable as an add-on. For organisations without an in-house CISO.
Learn moreGap assessment, roadmap, implementation via the platform. From 4,500 euros.
Learn moreISMS, compliance and evidence from a single platform. Multi-entity, multi-country, multilingual.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
OdySecure codifies 25 years of ISMS leadership from the Big Four. Translated into a platform that delivers evidence to boards and supervisory boards on demand, instead of being filtered through IT language.
The IT service provider typically owns operations and technology. NIS-2, however, obliges management to handle governance, risk assessment, supplier management and documented reporting paths. These duties cannot be delegated away. That governance role runs on the platform, and you add the vCISO when you need one, without you having to become CISO yourself.
That is the core question of the free 30-minute risk check. We assess sector (Annexes 1 and 2 of the German BSI Act), headcount, revenue and balance sheet total and classify you indicatively. The legally binding evaluation, however, remains a matter for a law firm with an IT-security-law focus. We provide the expert basis for that legal conversation.
Maturity heatmap by site and standard, top-10 risks with mitigation status, measure tracking by owner and due date, compliance status for NIS-2, DORA, ISO 27001 and sector-specific requirements, 12-month trend charts. Format: PDF templates for supervisory-board meetings and interactive dashboard for ongoing oversight.
With the vCISO bundle you have a senior CISO on mandate in week one. With the 30-minute risk check you have an initial gap assessment immediately. Audit-ready NIS-2 readiness typically lands in 8 to 12 weeks, depending on size and number of sites.
The risk check is free. The vCISO bundle starts at 3,600 euros per month. The NIS-2 gap assessment runs at 4,500 euros fixed price, implementation from 18,000 euros. Corporate pricing for multi-site rollouts is project-based.
Free risk check with indicative classification, top-5 gaps, path recommendation and cost estimate. Ideally with you and your IT lead present.
Book the risk checkMany companies cannot answer where their critical data lives. What this means for NIS-2 compliance and how one structured workshop day creates clarity.
Many companies start their NIS-2 journey by searching for the right tool. But the foundation is often missing: a clear operating model with defined responsibilities and processes. Why getting the sequence right matters.
Many organizations push the information security policy to the back of the queue. Yet it is the operational anchor point for ISMS development and NIS-2 implementation and can be developed in just a few weeks.
Experienced C-level security leadership, 2 to 6 days a month, with the platform as the working tool.
Learn moreImmediate security expertise for transition phases and critical projects.
Learn moreComprehensive analysis of your IT security posture with actionable roadmap.
Learn more