Skip to content
SECURITYSQUAD

Cyber Risk Check: know where you stand, for a fixed price

Fast. Understandable. BSI-aligned.

CyberRisikoCheck
Cyber Risk Check

Carried out remotely, at a fixed price

The official entry point into structured information security, following DIN SPEC 27076.

The check runs entirely remotely. For you it is one to two hours of conversation; the evaluation and the report come from us.

Festpreis

€199

(net)

Fully credited if you commission further services.

Book the check (opens in a new window)
DIN SPEC 27076

What the Cyber Risk Check delivers

The Cyber Risk Check to DIN SPEC 27076 is a standardised procedure initiated by Germany's BSI, aimed specifically at small and mid-sized organisations and at anyone not yet running an information security management system. In a structured remote interview we work through your key areas together and assess them against a uniform, verifiable scheme – without technical jargon and without extensive preparation on your side.

What comes out at the end is not an unwieldy scan report but an objective position assessment: a prioritised report that ranks every recommendation by urgency and explains it in plain language. You immediately know which measures have the greatest effect – and you hold a sound basis for further steps such as ISO 27001, IT-Grundschutz or NIS2 implementation.

Scope

27 requirements across six topic areas

DIN SPEC 27076 prescribes what is asked: 27 requirements across six topic areas, with a defined score for each answer. That is why the result is comparable – it does not depend on who carries out the check. The data is collected through a web application the BSI provides free of charge to qualified providers.

For every requirement that is not met, the report contains an action recommendation, ordered by urgency. And one point many people miss: the report indicates which government funding measures at federal, state and municipal level are available for those recommendations. For small organisations that is often the difference between a good idea and a feasible one.

Process

How the check runs

Four steps, not a project.

1

Book a slot

Pick a time online. No preparation needed on your side.

2

Remote interview

One to two hours on video. We ask, you answer – we translate the jargon.

3

Evaluation

We score against the DIN SPEC scheme and rank the gaps by urgency.

4

Report

Prioritised measures with funding pointers, plus a walkthrough of the results.

Preparation

What to bring

Very little – and that is deliberate. It helps if someone in the meeting can answer these questions:

  • Who looks after IT – in-house, external, or both?
  • Which systems and applications is the business unable to work without?
  • How are backups made, and when was a restore last tested?
  • Who may access what, and how is access granted and withdrawn?

You do not need to write any of this down beforehand. If a question stays unanswered, that is itself a result.

Results

Your results and what you gain

What is on the table at the end.

A score to the BSI scheme

A comparable figure to DIN SPEC 27076 – not a subjective opinion.

A clear position assessment

You see where you stand and can evidence it internally and to third parties.

Prioritised measures

A recommendation for every gap, ordered by urgency – with funding pointers.

A basis for NIS2 and ISO

The report is the starting point for an ISMS, ISO 27001 or NIS2 implementation.

Boundaries

What the check is not

So that you expect the right thing – and we do not sell you the wrong one:

Not a technical scan and not a penetration test. The check is a structured conversation, not an examination of your systems from outside. If that is what you need, look at vulnerability management.

Not a certification. The report is a position assessment, not a certificate and not audit evidence. For a certificate the route runs through ISO 27001.

Not implementation. The check says what needs doing. The doing is a separate step – we are glad to support it, but it is not inside the fixed price.

Vulnerability Management
Is it a fit?

Who the check is meant for

The BSI developed DIN SPEC 27076 for small and micro enterprises with fewer than 50 employees. That is where it fits best: enough structure to be meaningful, little enough effort not to become a project.

Particularly useful for:

Small companies
Municipalities and associations
Organisations without an ISMS

If you are considerably larger or already run an ISMS, the check is too coarse. Then the route runs straight through a gap analysis towards ISO 27001 – tell us, and we will save you the €199.

Asked often

Frequently asked questions about the Cyber Risk Check

How long does the whole check take?

For you it is a one- to two-hour interview on video. We produce the evaluation and report afterwards; together with the walkthrough of the results you are looking at around three hours in total. No preparation effort falls on you.

What does it cost, and are there hidden costs?

€199 net at a fixed price, regardless of how the result turns out. If you commission further services afterwards, we credit the amount in full. Further costs only arise if you commission implementation – a separate decision after the report.

Who should attend the session?

Ideally someone with an overview of the organisation – management or administrative leadership – and someone who knows the IT. That can be your external provider. Two or three people are enough; a larger group only slows the session down.

What happens to our answers?

Data is collected in the BSI's web application, which is provided to qualified providers for carrying out the check. You receive the report; it is not passed on. Details of the processing are in our privacy policy.

Do we need this if we already have an IT provider?

Usually yes, for a simple reason: the check does not assess your provider's work but the state of your organisation – including matters such as responsibilities, contingency planning and training, which are rarely in the contract. Many providers attend the session themselves.

Book your check now

€199 net, remote, no preparation – and fully credited if you go on to work with us.

Book online directly (opens in a new window)