top of page
Dein Abschnittstext (2)_edited_edited.png

See where your client's ISMS documentation breaks

before the audit takes place.

COSI DIAG checks existing documentation against all NIS2 and ISO 27001 requirements, including all 93 Annex A controls, and delivers an objective compliance score in minutes instead of days.

Image by Akif Waseem

AI-POWERED READINESS ASSESSMENT

for NIS2, ISO 27001, and Beyond

COSI DIAG software interface for ISO 27001 and ISMS assessment featuring document verification, checkpoints, compliance analysis, and results evaluation.
COSI DIAG verifies compliance with the following standards
ISO/IEC 27001 * NIS-2/ EU 2024/2690 * ISO/IEC 27002 * ISO 22301 * ISO/IEC 27017 * ISO/IEC 27018 * ISO/IEC 27701

Market pressure

Preliminary audits take days. AI squeezes margins.

Manual preliminary audits of an ISMS against standard requirements such as NIS2 or ISO 27001 consume at least three to five days per inquiry, with varying, person-dependent quality. At the same time, AI is driving down processing times in the market, leading clients to expect lower fees and faster turnaround times. For consultants, this means staying competitive through new tools and technologies. Ultimately, those who fail to keep up with the accelerated pace risk losing clients to faster competitors.

COSI DIAG shows ISO 27001 clause compliance across 128 evaluated clauses, featuring a comprehensive overview of fully, partially, and non-compliant requirements.

How COSI DIAG Works

Documents in. Findings out. In minutes.

1. Upload

You upload your client's existing ISMS documentation.

2. Conduct Full Review

A comprehensive ISO 27001 assessment covering all 93 Annex A controls

3. Receive Findings

Receive a compliance score and a gap report with evidence at the clause level

NO GUT FEELINGS.

THE SAME FINDING. EVERY TIME.

Radar chart representation for digital analysis of information security, ISMS maturity level, and compliance with COSI DIAG.

Instead of a subjective assessment dependent on the individual, you receive a reproducible score and a gap report. The same input yields the same result tomorrow. You present this objective finding to your client as verifiable proof.

Book an Initial Consultation
DATA SECURITY
Your client documents: Processed in full compliance with GDPR
Gemini_Generated_Image_ayejpwayejpwayej.jpg

COSI DIAG runs as a dedicated service hosted on a language model located within the EU. Customer data is strictly excluded from model training, processing is governed by a Data Processing Agreement (DPA), and each client operates within an isolated, client-centric workspace.

This ensures confidential documents are processed within a protected environment—without ever exposing them publicly.

For organizations requiring total data sovereignty, COSI DIAG can be deployed as a separate tier on-premises using an isolated language model, ensuring no document ever leaves your infrastructure.

EU-Hosting

Training Exclusion

for Customer Data

Data Processing

Agreement (DPA)

Encapsulated Project

Workspace per Client

Value and Price

The business value of COSI DIAG at a glance – and a transparent pricing model

Value of COSI DIAG for Consultants

The value of COSI DIAG lies not primarily in questionnaire catalogs, but in turning regulatory complexity into a repeatable consulting process.

  • Increased productivity: Less time spent on research and structuring, more time dedicated to consulting

  • Higher quality: Consistent, traceable, and objective results

  • Risk reduction: Lower risk of overlooking critical regulatory requirements

  • Scalability: A proven process designed to handle complex frameworks seamlessly

Price

COSI DIAG is offered as an annual license per consultant.

1950 € pro Jahr/ Consultant
  • Use of all available diagnostic modules: NIS2, ISO 27001, and more

  • Regular updates

  • Technical support

  • Use on up to 2 devices per consultant

FOR IT PROVIDERS AND CONSULTING PRACTICES

Consistent quality

across your entire consultant pool.

Where multiple consultants conduct audits, quality fluctuates. COSI DIAG delivers a consistent, reproducible benchmark across the entire pool, including maturity transparency modeled after the Capability Maturity Model (CMM). It offers a quantified maturity level for each process rather than a binary statement, communicated in a language that resonates all the way up to executive management. On-premises deployment and enterprise conditions are available as a separate tier.

Request a Practice Discussion
COSI DIAG compliance matrix for ISO 27001 showing document and requirement coverage, partially fulfilled ISMS requirements, and mapped evidence.

WHERE WE STAND

Trust is built on results.

The best endorsement comes from companies that work with our solution every day.

Here, we highlight selected clients, testimonials, and concrete use cases.

Would you like to see for yourself? We would be pleased to demonstrate COSI DIAG live using your own documents.

Cross-industry

references

Testimonials &

Success Stories

Live demo

with your data

Top questions from auditors.
  • COSI DIAG is an AI-powered software for analyzing the maturity of Information Security Management Systems (ISMS). The solution analyzes your existing ISMS documentation, identifies vulnerabilities, inconsistencies, and potential for improvement, and supports companies in preparing for ISO 27001 audits, NIS2 requirements, as well as internal and external compliance assessments.

  • No. COSI DIAG does not replace internal audits or external certification audits. The software serves as an objective analysis and diagnostic tool that enables companies to determine their current ISMS maturity level and identify potential non-conformities prior to an audit. This reduces audit risks and significantly improves audit preparation.

  • COSI DIAG analyzes existing ISMS documentation, such as policies, processes, concepts, and other supporting evidence. Complete documentation is not strictly required – even incomplete records provide valuable insights into the current level of maturity and potential areas for improvement.

  • Traditional compliance checks and gap analyses are often just brief snapshots, heavily biased by individual auditors or consultants. COSI-DIAG automates this process, analyzing your ISMS documentation in a completely reproducible way. It flags gaps, inconsistencies, and issues, scores your management system's maturity, and delivers a prioritized management report. The result? A reliable, real-time view of your information security status whenever you need it.

  • Yes. COSI DIAG can be operated fully on-premises – optionally including a local Large Language Model (LLM). As a result, sensitive ISMS documentation, security policies, and compliance records remain entirely within your own IT infrastructure. This also meets stringent requirements for data privacy, information security, and regulatory compliance.

  • COSI-DIAG validates compliance with the following standards: ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO 22301:2019, ISO/IEC 27017:2015, ISO/IEC 27018:2025, ISO/IEC 27701:2025, and NIS2 (EU 2024/2690).

  • COSI-DIAG is built for any organization operating an ISMS or managing strict information security compliance. It is highly optimized for:

    • Critical Industries: KRITIS (Critical Infrastructure), Healthcare, Energy, Utilities, and Public Administration.

    • Commercial Sectors: Manufacturing, Industrial Production, Finance, Insurance, and IT Service Providers.

    • Compliance Goals: Companies actively preparing for ISO 27001 certification or the NIS2 directive.

    By delivering automated maturity insights, it provides Information Security Officers (ISOs), CISOs, compliance managers, and executive leadership with the visibility needed to catch gaps early and streamline audit preparation.

Choose the right licensing model

Whether for occasional assessments or continuous audit preparation, COSI DIAG offers the right package for your needs.

Gemini_Generated_Image_52y79z52y79z52y7.jpg
Starter Package

For occasional assessment runs:

  • 5 complete assessment runs

  • Structured evaluation and recommendations

  • One-time payment

  • No ongoing costs

Pro Abo

Developed for organizations and consultants who regularly conduct structured compliance assessments and want full access to the complete capabilities of COSI DIAG at all times.

  • Unlimited assessment runs

  • Structured evaluation and recommendations

  • Affordably priced subscription with complete feature access

COSI DIAG Pro software for ISO 27001, NIS2, and ISMS audits featuring a dashboard for structured compliance and maturity level analysis.

Schedule a 30-minute initial consultation

with Ing. Klaus Thurnhofer now.

Schedule an appointment
Schedule an initial consultation—in just 2 clicks
  • We analyze your current situation

  • You receive initial concrete recommendations

  • You decide how to proceed at your own pace

bottom of page