Download a requirements specification – ISO 27001, NIS2 and BSI C5
How to activate a standard such as ISO/IEC 27001, NIS2 or BSI C5 as a requirements specification in your team: select the standard, assign a title, set the association – all requirements are then ready for assessment and feed into the ISMS cockpit.
A requirements specification is the foundation of your ISMS: it adopts the complete set of requirements of a standard into your team as assessable entries. This article shows how to download a standard such as ISO/IEC 27001, NIS2 or BSI C5 and release it for the right organisations.
Prerequisites
- Your team has a licence for Information Security (ISMS).
- You have permission to download requirements specifications.
Step by step
- Open “Requirements specifications” and click “Download the requirements specification”. The “Download the requirements specification” window opens.
- Under “General”, select the desired standard in the “Standard” field. Available options include
BSI C5,BSI IT baseline protection,DORA,ISO/IEC 27001,NIS2andTISAX. - Optionally assign a “Title”. If the field remains empty, the standard together with its version is used as the title.
- Under “Association”, define the “Organisations” for which the catalogue is to apply. Select individual organisations or activate “All organisations”.
- Click “Download the requirements specification”.
Activate “All organisations” only deliberately. The application explicitly indicates that this setting grants access for all organisations and may result in users receiving access to requirements for which they would otherwise not be authorised.
What happens next
- The complete set of requirements of the selected standard is adopted into your team as assessable entries – for ISO/IEC 27001:2022, this is 93 requirements.
- The catalogue appears with the status “Active” in the requirements specifications overview.
- The requirements and the degree of fulfilment of the catalogue become visible in the “ISMS cockpit”.
Practical tip: for an annual reassessment, simply download the same standard again and assign a descriptive title, for example ISO/IEC 27001:2022 – Rating 2026. You can then archive the previous year's version in the detail view.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.