The next audit begins
with today's measures

Organise responsibilities, risks and evidence in an operable information security management system.

Documents alone are not enough if responsibilities and measures remain unclear in everyday work. Companies need a traceable link between requirements, implementation and evidence.

IQstruct Engineering supports internal audits, supplier audits and the technical and organisational preparation of external assessments. The offer includes tracking of measures, document maintenance and external roles as ISMS team, IT security officer or quality management officer. Requirements are considered together with the existing system landscape.

Start now at no cost

In a free first conversation we place which rule sets apply to you and which records are already in hand.

See the person in charge

Scope of services

Connect risks and measures

Asset and supplier information supports prioritisation.

Prepare evidence in a structured way

Audit report, findings, action plan and evidence overview are prepared to suit the order.

Keep supporting security management

External officer roles can support the ongoing work.

Connecting requirements, implementation and evidence

IQstruct Engineering supports internal audits, supplier audits and the technical and organisational preparation of external assessments.

We accompany TISAX, ISO 27001, NIS2, the Cyber Resilience Act, the EU AI Act, the EU Data Act as well as requirements from the ecodesign regulation and for the digital product passport. We review documents, classify requirements technically and organisationally and give implementation guidance; open legal questions are clarified by qualified legal advisers. For plants and automation systems, we additionally offer the provision of evidence under IEC 62443.

Tracking of measures, document maintenance and internal audits remain relevant after an audit as well. For this, IQstruct Engineering provides lasting support as an external ISMS team or as IT security or quality management officer, coordinated with your existing responsibilities.

Person working at a monitor and a notebook with source code

Information security

The next audit begins with today's measures

Responsibilities, risks and evidence are organised in an operable information security management system.

Approach in the project

  1. A consultant reviews products, processes and the applicable requirements on the screenAi

    1

    Determine requirements

    The company's products and organisational requirements are reviewed.

  2. An employee sets tasks, owners and deadlines in an action plan on the screenAi

    2

    Plan measures

    Responsibilities, tasks and dates are set out in an overview of measures.

  3. Two people check measures and evidence using binders and documentsAi

    3

    Prove implementation

    Internal measures and project completion are checked against the documents.

  4. An employee adds new requirements to the action plan on the screenAi

    4

    Accompany changes

    New requirements are incorporated into the action plan and the company's processes.

Getting started for small companies

CyberRisikoCheck

The CyberRisikoCheck based on DIN SPEC 27076 offers a structured start to the survey of IT security.

Internal audits

Internal audits show where measures and evidence are still missing.

External officers

IQstruct Engineering takes on the role of ISMS or IT security officer.

Information security

Protecting confidential project data reliably

In the automotive industry, TISAX creates a common basis for handling confidential information.

Manufacturers and suppliers exchange design data, software and further sensitive project information. TISAX makes it possible to assess information security against common criteria and to share the results with business partners. As an engineering service provider in this supply chain, IQstruct Engineering likewise commits to protecting the information entrusted to it and holds a TISAX label. Clear access rights, governed data exchange and traceable responsibilities are therefore part of the cooperation in a project as well.

Frequently asked questions

We are glad to answer your detailed questions in a personal conversation.

Does audit preparation guarantee certification?

The final assessment is made by the responsible independent certification body. We prepare documents and evidence structures for it.

Does IQstruct Engineering provide legal advice?

IQstruct Engineering classifies requirements technically and organisationally. Binding legal assessments are made by external experts.

What do you receive after an audit?

Audit report, documented findings, risk assessment, prioritised action plan and evidence overview.

First conversation

Arrange a free first conversation

Describe your task. We agree a date and discuss the possible project scope.

  1. Notebook on a desk with an open calendar and a selected appointmentAi

    1

    You request an appointment

  2. Joint planning of a segmented IT and OT infrastructure on a network diagramAi

    2

    We discuss your requirements

  3. Discussion of a security analysis with a network diagram and a list of measuresAi

    3

    You receive a quotation for the agreed scope

Philipp Niemann-Stryczek
Philipp Niemann-StryczekManaging DirectorLeads the company on the commercial side and answers questions on IT/OT security, asset administration shells, compliance and research projects.
Free first conversation

Describe your task in the contact form. We come back with a proposed date.

Arrange a first conversation

Not quite what you need?

Discover further suitable services.

Product compliance

Make components, licence terms and updates traceable.

AI governance and obligations

Classify requirements technically and organisationally before individual tools turn into operational processes.

IT operations and managed services

Combine monitoring, updates and support in one agreed operating model.