Cybersecurity › Compliance
Compliance

Complying with regulations is one thing.
The evidence shows something else.

We'll determine whether you're affected, identify any gaps, implement the necessary measures, and provide documentation that will stand up to scrutiny.

Certified NIS2 Consultants · NIS2, CRA, and ISO 27001

The Problem

The requirement is already in effect.
Many people just don't realize that it applies to them.

NIS2 is now law and applies not only to critical infrastructure. Starting in 2027, the Cyber Resilience Act will also apply to all manufacturers of products with digital components.


, Unaware That It Was Affected

It also affects medium-sized companies in the energy, healthcare, IT, transportation, food, and manufacturing sectors—as well as suppliers who aren't even active in any of those sectors themselves.

One catch
s don't provide protection

If you only meet the requirements on paper, you have a document but no security. This becomes apparent during an audit—or, at the very latest, after an incident.


's management is personally liable

Responsibility for implementation lies explicitly with management. This is not a theoretical risk, but is enshrined in law.

10 million euros

or 2% of global annual revenue: the range for fines imposed on significant entities.

NIS 2 Directive, Article 34

72 hours

Deadline for reporting the incident to the appropriate authority; an early warning is issued after just 24 hours.

NIS 2 Directive, Article 23

Not sure if this affects you?

Six questions, two minutes, instant results. The quick check tells you whether NIS2 applies to your company.

Start the NIS2 Quick Check
Services

From the impact assessment
to the completed audit.

We’re with you every step of the way: determining whether you’re affected, identifying gaps, implementing measures, and providing proof.

NIS2

Assess the impact, identify gaps, implement measures, and document them.

Cyber Resilience Act

For manufacturers and retailers of products with digital components.

ISO 27001

Establish an information security management system and prepare for certification.

Guidelines

Requirements, processes, and documentation, right through to reporting to the authorities.

You will receive
  • Clarity on whether and how you are affected
  • Complete report on all vulnerabilities
  • Action Plan with Steps and Deadlines
We'll take care of it
  • Technical and Organizational Implementation
  • Policies, Processes, and Training Materials
  • Coordination with the authorities, upon request
In the end, there is
  • Documentation that stands up to scrutiny
  • A verifiable status of implementation
  • Continuous Updates Instead of a Snapshot

In an emergency, what matters isn't
what you've done, but what you can prove.

That is why we create the documentation at the same time as implementation, rather than after the audit date.

Procedure

From the question “Does this apply to me?”
to providing proof.

Every step is verifiable and builds on the previous one. As a result, the end result is not a pile of paper, but a traceable chain.

Impact Assessment

We will determine whether and to what extent you are subject to NIS2 or the Cyber Resilience Act. Your industry, size, revenue, and business activities determine your classification.

1–2 hours

Gap Analysis

We assess your situation against all the requirements that apply to you. Every gap is identified, evaluated, and prioritized based on urgency.

1–2 weeks

Action Plan

Based on the analysis, a plan is developed that includes a sequence of steps, realistic deadlines, responsibilities, and an estimate of the effort required.

1 week

Implementation at both levels

On the organizational side, this includes guidelines, processes, and training; on the technical side, it involves measures implemented on the systems. We handle both aspects with the same team.

4–12 weeks

Documentation and Audit Preparation

All implemented measures are documented in a verifiable manner, including the emergency plan and reporting procedures. This ensures you are prepared for inspections by regulatory authorities, auditors, and customer audits.

ongoing
Why ITanic

The requirements are technical.
Legal advice alone is not sufficient.

Detection, response, maintenance status, and access are explicitly required. Anyone who only provides documents is only halfway there.

Certified NIS2 Consultants

Both managing directors hold the WKO incite certification. Philipp Trummer also serves as a lecturer in the field of cybersecurity.

Regulations and Technology Combined

Attack detection, maintenance status, emergency response: These are legal requirements, and we handle them ourselves rather than passing them on to your IT department.

Focused on Liability

The documentation is structured in such a way that it can withstand an inspection by regulatory authorities and a customer audit. That is exactly what matters when it comes to personal liability.

Austrian Context

Implementation is governed by national law. We are familiar with the relevant authorities, the deadlines, and the procedures—not just the text of the directive.

Frequently Asked Questions

What companies ask first.

How can I tell if my company is affected?

The key factors are sector and size. The sectors affected include energy, healthcare, water, IT, transportation, and finance; organizations with 50 or more employees or 10 million euros in revenue are considered “important entities,” while those with 250 or more employees or 50 million euros in revenue are considered “significant entities.” Suppliers may also be affected. We’ll clarify the specifics during our initial consultation.

What happens if we ignore the requirements?

Fines of up to ten million euros or two percent of global annual revenue may be imposed, and management may be held personally liable in cases of proven negligence. The regulatory authority may also order restrictions on operations.

How long will the implementation take?

That depends on the starting point. Companies with an established security culture often need three to six months; those starting from scratch should plan for six to twelve months. After the gap analysis, we’ll provide a realistic timeline.

Can we handle this with our own IT team?

The organizational side—including policies, processes, and training—yes. The technical side requires specialized knowledge, such as in attack detection, maintenance status, backups, and network isolation. We support both areas and take the load off your team where it makes sense.

What is the Cyber Resilience Act, and who does it affect?

An EU regulation that will apply starting in 2027 to manufacturers, distributors, and importers of products with digital components—that is, software, connected hardware, and devices. It requires security by design, the management of vulnerabilities, and documentation throughout the entire lifecycle.

How is it different from NIS2?

NIS2 applies to companies that provide certain services and requires operational security. The Cyber Resilience Act applies to products and requires security built into the product itself. A company may be subject to both.

Compliance is the framework.

It is filled with real-life risk management that actually takes place in everyday life.

Consulting & Risk Management

It's not a question of "if."
It's just a question of "when."

We assess your compliance status, identify any gaps, and guide you through the process until you have provided proof.

Free and with no obligationCertified NIS2 consultantsUnder Austrian law