_edited_edited.png)
See where your client's ISMS documentation breaks
before the audit takes place.
COSI DIAG checks existing documentation against all NIS2 and ISO 27001 requirements, including all 93 Annex A controls, and delivers an objective compliance score in minutes instead of days.

AI-POWERED READINESS ASSESSMENT
for NIS2, ISO 27001, and Beyond

COSI DIAG verifies compliance with the following standards
ISO/IEC 27001 * NIS-2/ EU 2024/2690 * ISO/IEC 27002 * ISO 22301 * ISO/IEC 27017 * ISO/IEC 27018 * ISO/IEC 27701
Market pressure
Preliminary audits take days. AI squeezes margins.
Manual preliminary audits of an ISMS against standard requirements such as NIS2 or ISO 27001 consume at least three to five days per inquiry, with varying, person-dependent quality. At the same time, AI is driving down processing times in the market, leading clients to expect lower fees and faster turnaround times. For consultants, this means staying competitive through new tools and technologies. Ultimately, those who fail to keep up with the accelerated pace risk losing clients to faster competitors.

NO GUT FEELINGS.
THE SAME FINDING. EVERY TIME.
.png)
Instead of a subjective assessment dependent on the individual, you receive a reproducible score and a gap report. The same input yields the same result tomorrow. You present this objective finding to your client as verifiable proof.
DATA SECURITY
Your client documents: Processed in full compliance with GDPR

COSI DIAG runs as a dedicated service hosted on a language model located within the EU. Customer data is strictly excluded from model training, processing is governed by a Data Processing Agreement (DPA), and each client operates within an isolated, client-centric workspace.
This ensures confidential documents are processed within a protected environment—without ever exposing them publicly.
For organizations requiring total data sovereignty, COSI DIAG can be deployed as a separate tier on-premises using an isolated language model, ensuring no document ever leaves your infrastructure.
EU-Hosting
Training Exclusion
for Customer Data
Data Processing
Agreement (DPA)
Encapsulated Project
Workspace per Client
Value and Price
The business value of COSI DIAG at a glance – and a transparent pricing model
Value of COSI DIAG for Consultants
The value of COSI DIAG lies not primarily in questionnaire catalogs, but in turning regulatory complexity into a repeatable consulting process.
-
Increased productivity: Less time spent on research and structuring, more time dedicated to consulting
-
Higher quality: Consistent, traceable, and objective results
-
Risk reduction: Lower risk of overlooking critical regulatory requirements
-
Scalability: A proven process designed to handle complex frameworks seamlessly
1950 € pro Jahr/ Consultant
-
Use of all available diagnostic modules: NIS2, ISO 27001, and more
-
Regular updates
-
Technical support
-
Use on up to 2 devices per consultant
FOR IT PROVIDERS AND CONSULTING PRACTICES
Consistent quality
across your entire consultant pool.
Where multiple consultants conduct audits, quality fluctuates. COSI DIAG delivers a consistent, reproducible benchmark across the entire pool, including maturity transparency modeled after the Capability Maturity Model (CMM). It offers a quantified maturity level for each process rather than a binary statement, communicated in a language that resonates all the way up to executive management. On-premises deployment and enterprise conditions are available as a separate tier.
.png)
WHERE WE STAND
Trust is built on results.
The best endorsement comes from companies that work with our solution every day.
Here, we highlight selected clients, testimonials, and concrete use cases.
Would you like to see for yourself? We would be pleased to demonstrate COSI DIAG live using your own documents.
Cross-industry
references
Testimonials &
Success Stories
Live demo
with your data
Top questions from auditors.
COSI DIAG is an AI-powered software for analyzing the maturity of Information Security Management Systems (ISMS). The solution analyzes your existing ISMS documentation, identifies vulnerabilities, inconsistencies, and potential for improvement, and supports companies in preparing for ISO 27001 audits, NIS2 requirements, as well as internal and external compliance assessments.
No. COSI DIAG does not replace internal audits or external certification audits. The software serves as an objective analysis and diagnostic tool that enables companies to determine their current ISMS maturity level and identify potential non-conformities prior to an audit. This reduces audit risks and significantly improves audit preparation.
COSI DIAG analyzes existing ISMS documentation, such as policies, processes, concepts, and other supporting evidence. Complete documentation is not strictly required – even incomplete records provide valuable insights into the current level of maturity and potential areas for improvement.
Traditional compliance checks and gap analyses are often just brief snapshots, heavily biased by individual auditors or consultants. COSI-DIAG automates this process, analyzing your ISMS documentation in a completely reproducible way. It flags gaps, inconsistencies, and issues, scores your management system's maturity, and delivers a prioritized management report. The result? A reliable, real-time view of your information security status whenever you need it.
Yes. COSI DIAG can be operated fully on-premises – optionally including a local Large Language Model (LLM). As a result, sensitive ISMS documentation, security policies, and compliance records remain entirely within your own IT infrastructure. This also meets stringent requirements for data privacy, information security, and regulatory compliance.
COSI-DIAG validates compliance with the following standards: ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO 22301:2019, ISO/IEC 27017:2015, ISO/IEC 27018:2025, ISO/IEC 27701:2025, and NIS2 (EU 2024/2690).
COSI-DIAG is built for any organization operating an ISMS or managing strict information security compliance. It is highly optimized for:
-
Critical Industries: KRITIS (Critical Infrastructure), Healthcare, Energy, Utilities, and Public Administration.
-
Commercial Sectors: Manufacturing, Industrial Production, Finance, Insurance, and IT Service Providers.
-
Compliance Goals: Companies actively preparing for ISO 27001 certification or the NIS2 directive.
By delivering automated maturity insights, it provides Information Security Officers (ISOs), CISOs, compliance managers, and executive leadership with the visibility needed to catch gaps early and streamline audit preparation.
-
Choose the right licensing model
Whether for occasional assessments or continuous audit preparation, COSI DIAG offers the right package for your needs.

Starter Package
For occasional assessment runs:
-
5 complete assessment runs
-
Structured evaluation and recommendations
-
One-time payment
-
No ongoing costs
Pro Abo
Developed for organizations and consultants who regularly conduct structured compliance assessments and want full access to the complete capabilities of COSI DIAG at all times.
-
Unlimited assessment runs
-
Structured evaluation and recommendations
-
Affordably priced subscription with complete feature access

Schedule a 30-minute initial consultation
with Ing. Klaus Thurnhofer now.
Schedule an initial consultation—in just 2 clicks
-
We analyze your current situation
-
You receive initial concrete recommendations
-
You decide how to proceed at your own pace