How it works today in many mid-sized companies
Information security in a mid-sized company rarely starts as a project. It starts with a demand from outside: a major customer asks for ISO 27001 evidence in a supplier questionnaire, the insurer asks about ransomware measures, and since the NIS2 Directive was transposed, management has been checking whether the company itself is in scope. Anyone supplying the automotive industry also has a TISAX request on the table.
The task usually lands with the head of IT or with someone appointed information security officer without anyone taking other work off their plate. They start with what is at hand: "ISO27001_Annex_A.xlsx" with 93 controls and a column for implementation status, next to it "TISAX_Self_Assessment.xlsx" from the industry association's catalog, and a folder "NIS2" with fact sheets and a note on reporting deadlines.
Three frameworks, three files – even though the requirements overlap to a large extent. An access rule, a backup policy or a training record meets requirements in all three but is maintained three times, with three different states. Evidence sits as screenshots in folders, and only the person who filed it knows which of them is still valid.
When software is to be bought, the search starts with questions like "Which ISMS software suits ISO 27001?" or "Software for implementing NIS2 in a mid-sized company?". The answers are vendor lists in which every product names standards, risk management and dashboards. Whether a tool runs several frameworks on a shared foundation or creates a separate checklist per standard is rarely stated.
The moment it becomes obvious
By the first certification or assessment at the latest, things get tight. The auditor asks for the statement of applicability as it stood on the reference date and for the evidence of a specific measure. The customer wants to know how a security incident would be reported and who decides. And in a real incident, a 24-hour early-warning deadline is running while someone searches the "NIS2" folder for the right template.
Then it becomes clear: the spreadsheets cover individual requirements but not the connections – between requirement and measure, between measure and evidence, between asset and risk. That is exactly what every audit asks about.
The analysis
Five questions for choosing ISMS software
They separate software that carries an audit from software that merely moves the spreadsheet into a web interface.
View measures and policiesSeveral frameworks, one measure
A measure should be able to meet several requirements without being copied. Otherwise every change is maintained three times, and within a year the versions contradict each other.
Evidence with an expiry date
A certificate expires, a policy is revised. If the software does not recognize outdated evidence, the gap only surfaces in the audit – and then under time pressure.
Reporting deadlines in an incident
NIS2 requires an early warning within 24 hours, a notification within 72 hours and a final report after one month. Without templates and deadline status, every incident turns into a search for the right form.
Usable without a specialist department
In SMEs, business units contribute who are not ISMS experts. If they see only their own requirements and tasks, they deliver; if they see the whole catalog, they do not.
States you can prove
An audit checks a reference date. If the statement of applicability cannot be filed as a dated version, the state at the time is reconstructed from memory and file dates.
The target process in six steps
An ISMS in software holds up when requirements, measures, evidence and assets are connected. The following steps lead there.
1. Define scope and frameworks. Clarify which sites and companies are included and which frameworks apply: ISO/IEC 27001 as the foundation, NIS2 if the company is in scope, TISAX for customers in the automotive industry. In preeco | information security, ready-to-use requirement catalogs are activated per organization, for example for ISO/IEC 27001 or BSI IT-Grundschutz.
2. Record assets. Systems, applications and sites form the inventory that risks and measures refer to. Responsibilities, hosting, encryption and NIS2 relevance are documented on the asset; the protection requirement is determined through a damage scenario matrix and inherited down the asset tree according to the maximum principle. Requirements can be assigned to individual assets and assessed for many assets at once.
3. Assess requirements. Each requirement gets an implementation status, a maturity level and a responsible person. Requirements that do not apply are excluded with a justification; this produces the statement of applicability, which can be filed as an immutable version with date and author.
4. Maintain measures once. A measure is linked to every requirement it meets, each link with its own degree of implementation, owner and deadline. The cockpit shows as a key figure how many applicable requirements have at least one measure. Deliberately accepted residual risks are recorded as documented exceptions instead of silently leaving a requirement open.
5. Request evidence instead of collecting it. Evidence is attached to the requirement or requested from other people, including external ones. It counts only once the responsible person confirms it, and expiring evidence automatically triggers a review.
6. Steer operations. The cockpit shows the degree of fulfillment per category as a heatmap and how it develops over time. Business units get a personal work list with exactly their requirements, tasks and deadlines. Follow-ups prompt the regular review of individual requirements, and every change to an assessment appears in the activity log.
NIS2 and TISAX in the same system
An ISMS under ISO/IEC 27001 covers many organizational requirements of the NIS2 Directive but does not replace its own obligations. preeco | information security includes nine report templates, among them early warning, notification and final report to the BSI under Section 32 BSIG, and shows the deadline status for each report. A NIS2 training course for management serves as evidence of the training obligation for management bodies. For TISAX, the VdA ISA audit catalog is available as an optional extension; audit objects are linked to the existing assets, and progress is shown graphically. This way, all three frameworks build on the same assets, measures and evidence instead of each creating its own documentation.
Before and after at a glance
| Criterion | Before | After |
|---|---|---|
| Frameworks | Three files with separate states | Requirement catalogs per organization |
| Measures | Copied per framework | Maintained once, linked to several requirements |
| Evidence | Screenshots in a folder | Requested, confirmed, reviewed on expiry |
| Applicability | A column in a spreadsheet | Statement of applicability as a dated version |
| Incidents | Fact sheet and a search for templates | Report templates with deadline status |
| Collaboration | Questionnaires by email | Personal work lists for business units |
| Overview | Counting ticks | Heatmap, degree of fulfillment and trend in the cockpit |
| Evidence over time | File dates | Activity log and revisions |
In practice
How this looks in preeco | information security
The three building blocks that carry an ISMS in a mid-sized company.
Requirement catalogs and measures
Ready-to-use catalogs, assessment with implementation status and maturity level, the statement of applicability as an immutable version, and measures that meet several requirements at once.
Risk analyses
Freely definable events, damage assessment and risk levels, linked to assets and documents, with export as PDF or DOCX including a graphical view of the risks.
Incident management
Security incidents with severity and reporting obligation assessment, nine report templates for the BSI and the supervisory authority, a clear deadline status and lessons learned.
What the switch means in practice
The existing work is not lost. Assessments, measure descriptions and evidence from the spreadsheets are transferred into a structure in which every measure knows which requirements it carries. What becomes visible are duplicates and gaps: the same policy in three versions, a requirement without a measure. Anyone licensing data protection and information security together switches between both work environments with a toggle.
Software replaces neither the certification body nor the assessment. It makes sure the state can be proven whenever someone asks.
The time frame depends mostly on the preparatory content work. A cloud environment is ready within 48 hours on business days; onboarding covers setting up the organizational structure, user groups and permissions, plus online training for administrators and users. Clarify beforehand who owns which category of requirements.
Three mistakes that make the switch harder than it needs to be
Running each framework as its own project. Tackling ISO 27001, NIS2 and TISAX separately builds three sets of documentation. Start with a shared foundation of assets and measures.
Collecting evidence at the end. Evidence gathered just before the audit is often outdated. Request it where it is created and have it confirmed. Evidence with an expiry date then reminds you itself that it needs renewing, long before the auditor asks.
Confronting business units with the whole catalog. Whoever sees hundreds of requirements works on none. Personal work lists with a few clearly assigned items work better.
How to tell it is time
A spreadsheet is not a mistake for a first inventory. It becomes a risk when at least one of these applies:
- More than one framework requires evidence from you.
- The same measure appears in several files with different states.
- You cannot say which evidence expires next quarter.
- The state of the statement of applicability on an earlier reference date cannot be proven.
- In a security incident, nobody would know right away which report is due by when.
FAQ
Frequently asked questions about ISMS software for SMEs
Software with a ready-to-use ISO/IEC 27001 catalog, a statement of applicability that can be filed as a dated version, measures that meet several requirements, and evidence that is reviewed on expiry. preeco | information security is operated in ISO 27001-certified data centers in Germany.
It covers the NIS2-specific obligations that go beyond an ISMS: preeco | information security includes report templates for early warning, notification and final report to the BSI with deadline status, marks NIS2 relevance per asset and includes a NIS2 training course for management. Whether a company falls under NIS2 is for the company to assess.
TISAX assessments are based on the VDA information security catalog. In preeco | information security, this catalog is available as the optional VdA ISA audit catalog; audit objects are linked to existing assets, and progress is shown graphically and exported as PDF or DOCX.
No, certification is granted by an accredited certification body after an audit. Software prepares for it by bringing requirements, measures, evidence and the statement of applicability together in a provable way.
Through clearly assigned tasks instead of the whole catalog. preeco | information security has a dedicated user permission for this: a user group sees only the requirements assigned to it, with their tasks, evidence and deadlines. Evidence can also be requested from external people by file or link.
Sort out your frameworks together
Bring your spreadsheets. In 30 minutes we show how ISO 27001, NIS2 and TISAX build on a shared foundation in preeco | information security.