Cyber Risk Check: know where you stand, for a fixed price
Fast. Understandable. BSI-aligned.

Carried out remotely, at a fixed price
The official entry point into structured information security, following DIN SPEC 27076.
The check runs entirely remotely. For you it is one to two hours of conversation; the evaluation and the report come from us.
Festpreis
€199
(net)
Fully credited if you commission further services.
Book the check (opens in a new window)What the Cyber Risk Check delivers
The Cyber Risk Check to DIN SPEC 27076 is a standardised procedure initiated by Germany's BSI, aimed specifically at small and mid-sized organisations and at anyone not yet running an information security management system. In a structured remote interview we work through your key areas together and assess them against a uniform, verifiable scheme – without technical jargon and without extensive preparation on your side.
What comes out at the end is not an unwieldy scan report but an objective position assessment: a prioritised report that ranks every recommendation by urgency and explains it in plain language. You immediately know which measures have the greatest effect – and you hold a sound basis for further steps such as ISO 27001, IT-Grundschutz or NIS2 implementation.
27 requirements across six topic areas
DIN SPEC 27076 prescribes what is asked: 27 requirements across six topic areas, with a defined score for each answer. That is why the result is comparable – it does not depend on who carries out the check. The data is collected through a web application the BSI provides free of charge to qualified providers.
For every requirement that is not met, the report contains an action recommendation, ordered by urgency. And one point many people miss: the report indicates which government funding measures at federal, state and municipal level are available for those recommendations. For small organisations that is often the difference between a good idea and a feasible one.
How the check runs
Four steps, not a project.
Book a slot
Pick a time online. No preparation needed on your side.
Remote interview
One to two hours on video. We ask, you answer – we translate the jargon.
Evaluation
We score against the DIN SPEC scheme and rank the gaps by urgency.
Report
Prioritised measures with funding pointers, plus a walkthrough of the results.
What to bring
Very little – and that is deliberate. It helps if someone in the meeting can answer these questions:
- Who looks after IT – in-house, external, or both?
- Which systems and applications is the business unable to work without?
- How are backups made, and when was a restore last tested?
- Who may access what, and how is access granted and withdrawn?
You do not need to write any of this down beforehand. If a question stays unanswered, that is itself a result.
Your results and what you gain
What is on the table at the end.
A score to the BSI scheme
A comparable figure to DIN SPEC 27076 – not a subjective opinion.
A clear position assessment
You see where you stand and can evidence it internally and to third parties.
Prioritised measures
A recommendation for every gap, ordered by urgency – with funding pointers.
A basis for NIS2 and ISO
The report is the starting point for an ISMS, ISO 27001 or NIS2 implementation.
What the check is not
So that you expect the right thing – and we do not sell you the wrong one:
Not a technical scan and not a penetration test. The check is a structured conversation, not an examination of your systems from outside. If that is what you need, look at vulnerability management.
Not a certification. The report is a position assessment, not a certificate and not audit evidence. For a certificate the route runs through ISO 27001.
Not implementation. The check says what needs doing. The doing is a separate step – we are glad to support it, but it is not inside the fixed price.
Who the check is meant for
The BSI developed DIN SPEC 27076 for small and micro enterprises with fewer than 50 employees. That is where it fits best: enough structure to be meaningful, little enough effort not to become a project.
Particularly useful for:
If you are considerably larger or already run an ISMS, the check is too coarse. Then the route runs straight through a gap analysis towards ISO 27001 – tell us, and we will save you the €199.
Frequently asked questions about the Cyber Risk Check
How long does the whole check take?
For you it is a one- to two-hour interview on video. We produce the evaluation and report afterwards; together with the walkthrough of the results you are looking at around three hours in total. No preparation effort falls on you.
What does it cost, and are there hidden costs?
€199 net at a fixed price, regardless of how the result turns out. If you commission further services afterwards, we credit the amount in full. Further costs only arise if you commission implementation – a separate decision after the report.
Who should attend the session?
Ideally someone with an overview of the organisation – management or administrative leadership – and someone who knows the IT. That can be your external provider. Two or three people are enough; a larger group only slows the session down.
What happens to our answers?
Data is collected in the BSI's web application, which is provided to qualified providers for carrying out the check. You receive the report; it is not passed on. Details of the processing are in our privacy policy.
Do we need this if we already have an IT provider?
Usually yes, for a simple reason: the check does not assess your provider's work but the state of your organisation – including matters such as responsibilities, contingency planning and training, which are rarely in the contract. Many providers attend the session themselves.
Book your check now
€199 net, remote, no preparation – and fully credited if you go on to work with us.
Book online directly (opens in a new window)