Information Security

Consulting that ends up in your system — not in a folder.

We build your information security management system where your team already works: in your existing environment. Jira and Confluence are our strongest implementation path; Microsoft 365, SharePoint, existing GRC tools, or open registers are also possible. From the first assessment through certification to ongoing operations — from a single source, with an optional product behind it that reduces the heavy lifting.

⚠ NIS2 is live. Now comes the hard part.

The NIS2 Implementation Act has been in force since 6 December 2025; around 30,000 companies in 18 sectors are in scope. BSI registration is complete — the risk-management measures, the incident-reporting process, and evidence for supervisory review are still pending for most organisations.

NIS2 Readiness Workshopfrom €2,900 excl. VAT

Our approach

Others deliver a PDF. We deliver a running system.

The conventional path to ISO 27001 or NIS2 ends with a folder full of documents that start ageing the day they are handed over. We do it differently: every output of our work lives on in your working environment — as a risk register, as a measure with an owner and due date, as a versioned policy, as a report or as an importable artefact for your target system.

This is made possible by standardised registers, field-tested templates and — when you use Jira and Confluence — our own product. The time gained flows to where consulting really counts: your risks, your processes, your evidence.

The result: audit-ready in weeks, not months. And afterwards a system that keeps running.

All services

From first assessment to ongoing operations.

Three stages that build on each other. Each stage has fixed deliverables and can be commissioned independently.

Stage 1 · Assessment

First, know where you stand.

Fixed price, fixed deliverables, fixed duration. The fee is fully credited.

Each of these offerings has a fixed price, a fixed deliverable, and takes days rather than weeks. Commission an implementation project within six months and we credit the fee in full.

Stage 2 · Implementation

From plan to audit-ready ISMS.

Fixed phases, fixed deliverables — your ISMS is built inside your own target system.

ISMS Implementation — ISO 27001

From scope to audit-readiness — your ISMS is built inside your own Atlassian.

6–16 weeks·ab €14,900 excl. VAT
NIS2-UmsetzungsprojektOn request

Pflichten erfüllen ohne den Umweg über eine Zertifizierung — in 6–12 Wochen.

DORA-Informationsregister aufbauenOn request

Ein Register, das das ganze Jahr über stimmt — nicht nur im März. Mit xBRL-CSV-Export.

ISMS App Quick Start

You steer. We ensure a clean start — including migration and 30 days of hypercare.

1–3 weeks·ab €4,900 excl. VAT
Internes Audit & Audit-BegleitungOn request

Die Feststellungen wollen Sie von uns hören — nicht vom Zertifizierungsauditor.

Stage 3 · Ongoing Operations

An ISMS is not a project. It is an operational state.

Ongoing operations, regular reporting, a named contact for emergencies.

Why maplee

Four good reasons.

01

Product and consulting from a single source.

We don't just advise on a standard — we built the tool for it. You get a recommendation that doesn't depend on someone else to implement.

02

Your data stays in your system.

No unnecessary additional system, no export to an external platform, no lock-in to our consulting.

03

Multiple frameworks, one system.

ISO 27001, NIS2, and DORA all access the same assets, risks, and measures — you maintain them once.

04

Direct line.

You work with the people who build the product. Short paths, fast decisions, direct influence on the roadmap.

How it works

Four steps to your ISMS.

01

Introductory call

30 minutes, free of charge. We clarify your starting point, your deadline, and whether we are the right fit.

02

Assessment

A workshop or analysis at a fixed price. Afterwards you know what lies ahead — with numbers.

03

Implementation

We build your ISMS in your chosen target system. Fixed phases, fixed deliverables.

04

Operations

We stay on board as far as you want: from pure product use to a fully outsourced security officer.

FAQ

Common questions.

Yes. Our consulting services are product-independent. Our ISMS app is designed for Atlassian Cloud, but we can deliver registers, policies and measures in Microsoft 365, SharePoint, an existing GRC tool, or open formats.

Where do you stand today?

Thirty minutes, free of charge and without commitment. Afterwards you will know which first step is right for you — even if that turns out not to be maplee.

kontakt@maplee.de

+49 170 6501904