01
BSI IT-Grundschutz for the public sector chain
BSI IT-Grundschutz is binding for federal authorities and increasingly required from the suppliers of KRITIS operators. Secfix does not carry it. KaitoSec covers Basis-, Standard- and Kern-Absicherung with control mapping, gap analysis and cross-references to ISO 27001 and NIS2.
02
NIS2 next to continuity and the supply chain
NIS2 asks for incident handling, supply chain security and business continuity in one breath. KaitoSec links the related controls, incident processes, supplier risks and management approvals to the ISMS and the BCMS, so an Article 21 measure carries its evidence and its recovery plan in one place.
03
Deployment when a cloud is not allowed
Secfix runs in the cloud. For organisations under an IT security policy that keeps security data in house, that is where the evaluation ends. KaitoSec offers on-premise deployment in the Enterprise plan and agrees the hosting path as part of the scope.
04
Advisory with a named result and a handover
KaitoSec defines gap analysis, implementation support, mock audit and vCISO as separate services with a named result. The outcome, the person responsible and the next review stay visible in the workspace after the engagement ends.
05
The cycle after the certificate
KaitoSec runs internal audits, management reviews, improvement actions and preparation for the surveillance audit in the same workspace. Compare how each offer carries year two, when the project team has moved on.