Back to Case Studies
Materna Cyber SecurityCyber Security & Compliance

NIS2 & ISO 27001 Compliance Readiness

Built an audit-ready Information Security Management System and regulatory compliance program, turning NIS2 and DORA obligations into concrete, evidence-backed controls for critical infrastructure clients.

The Challenge

Materna's clients in energy, healthcare, and public sector infrastructure faced a wave of incoming regulation — NIS2, DORA, and national KRITIS requirements — with no unified way to demonstrate compliance. Security policies existed on paper but were disconnected from daily operations, and every audit meant weeks of manual evidence-gathering across disparate systems.

Architecture Setup

Our Architectural Solution

RINVID helped design and stand up an ISO/IEC 27001-aligned Information Security Management System (ISMS), mapping each regulatory obligation to a concrete control, owner, and piece of evidence. We treated compliance as an operating model, not a one-time certification project — building the governance structure so it could absorb new regulation without a rebuild each time.

The Execution

We ran risk and gap assessments against BSI IT-Grundschutz and ISO 27001 baselines, then worked with Materna's teams to translate findings into a Business Continuity Management plan (BSI 200-4 / ISO 22301) and a secure software development policy embedding security requirements directly into the SDLC. We also helped define governance for emerging AI usage, so new tools could be adopted without opening an unmanaged risk surface.

Architecture & Tech Stack

ISO/IEC 27001BSI IT-GrundschutzNIS2 / DORAISO 22301 / BSI 200-4Secure SDLC Policy

Key Metrics & Results

  • Passed external ISO 27001 surveillance audit with zero major non-conformities.
  • Cut evidence-gathering time for compliance audits by more than half.
  • Established a reusable control framework that scales to new regulation without starting over.

Facing a similar technical challenge?

Speak with our Architects