Information Security
We build your information security management system where your team already works: in your existing environment. Jira and Confluence are our strongest implementation path; Microsoft 365, SharePoint, existing GRC tools, or open registers are also possible. From the first assessment through certification to ongoing operations — from a single source, with an optional product behind it that reduces the heavy lifting.
⚠ NIS2 is live. Now comes the hard part.
The NIS2 Implementation Act has been in force since 6 December 2025; around 30,000 companies in 18 sectors are in scope. BSI registration is complete — the risk-management measures, the incident-reporting process, and evidence for supervisory review are still pending for most organisations.
Our approach
The conventional path to ISO 27001 or NIS2 ends with a folder full of documents that start ageing the day they are handed over. We do it differently: every output of our work lives on in your working environment — as a risk register, as a measure with an owner and due date, as a versioned policy, as a report or as an importable artefact for your target system.
This is made possible by standardised registers, field-tested templates and — when you use Jira and Confluence — our own product. The time gained flows to where consulting really counts: your risks, your processes, your evidence.
The result: audit-ready in weeks, not months. And afterwards a system that keeps running.
All services
Three stages that build on each other. Each stage has fixed deliverables and can be commissioned independently.
Fixed price, fixed deliverables, fixed duration. The fee is fully credited.
Each of these offerings has a fixed price, a fixed deliverable, and takes days rather than weeks. Commission an implementation project within six months and we credit the fee in full.
Clarity on applicability, obligations, and priorities in 1–2 days.
Your current state against ISO/IEC 27001:2022 and all 93 controls — with a realistic roadmap.
Bewertung entlang der fünf DORA-Säulen mit Schwerpunkt Informationsregister und Fahrplan bis zum Meldefenster.
Do you really need a second system? Target architecture, migration plan, and 3-year cost comparison.
KI wird längst genutzt — meist ungeregelt. In einem Tag zu Inventar, Risikoeinstufung, Nutzungsrichtlinie und ISMS-Anbindung.
Fixed phases, fixed deliverables — your ISMS is built inside your own target system.
From scope to audit-readiness — your ISMS is built inside your own Atlassian.
Pflichten erfüllen ohne den Umweg über eine Zertifizierung — in 6–12 Wochen.
Ein Register, das das ganze Jahr über stimmt — nicht nur im März. Mit xBRL-CSV-Export.
You steer. We ensure a clean start — including migration and 30 days of hypercare.
Die Feststellungen wollen Sie von uns hören — nicht vom Zertifizierungsauditor.
Ongoing operations, regular reporting, a named contact for emergencies.
You have the obligation, but rarely the position. We take on the security officer role or support your internal CISO.
Standard-Support für alle Lizenzkunden inklusive. Premium mit benanntem Ansprechpartner und schnellerer Reaktion.
Management training is mandatory under NIS2 — and must be documented.
Why maplee
We don't just advise on a standard — we built the tool for it. You get a recommendation that doesn't depend on someone else to implement.
No unnecessary additional system, no export to an external platform, no lock-in to our consulting.
ISO 27001, NIS2, and DORA all access the same assets, risks, and measures — you maintain them once.
You work with the people who build the product. Short paths, fast decisions, direct influence on the roadmap.
How it works
30 minutes, free of charge. We clarify your starting point, your deadline, and whether we are the right fit.
A workshop or analysis at a fixed price. Afterwards you know what lies ahead — with numbers.
We build your ISMS in your chosen target system. Fixed phases, fixed deliverables.
We stay on board as far as you want: from pure product use to a fully outsourced security officer.
FAQ
Thirty minutes, free of charge and without commitment. Afterwards you will know which first step is right for you — even if that turns out not to be maplee.
kontakt@maplee.de
+49 170 6501904