Certificates and audit reports apply only to the named provider, period and scope. We document which evidence applies to the infrastructure in use.
Information Security
For the selected infrastructure provider, we review and document available ISO 27001 certificates, including their scope and validity.
Cloud Security
The BSI Cloud Computing Compliance Criteria Catalogue (C5) defines minimum requirements for secure cloud computing - relevant for public administration and regulated industries.
Operational Controls
Where a provider supplies a SOC 2 Type II report, we review its period and scope for the service in use.
Technical and organisational measures designed to support privacy requirements at infrastructure level.
German and European locations are available. Location, subprocessors and any required third-country transfers are documented before the contract starts.
Encryption in transit and at rest is defined per system. Protocols, key management and rotation are recorded in the operating documentation.
Roles, multi-factor authentication and logging of administrative access are configured within the supported and agreed scope.
Where WZ-IT acts as a processor, we provide a DPA with a description of the technical and organisational measures.
Compliance is not created in a binder, but in day-to-day operations. If you want to present evidence in an audit, you have to produce it beforehand - these six points are what ongoing operations deliver to your compliance.
As soon as we operate systems containing personal data, we act as a processor within the meaning of Art. 28 GDPR. The DPA governs processing on instructions, confidentiality and sub-processing - with us it is part of every operations contract, not a paid extra.
Technical and organizational measures are only worth as much as their implementation. Our TOMs describe actual operations - encryption, access control, backup processes - and are updated whenever your infrastructure changes.
Every installed update is documented: which system, which package, when, by whom. These reports answer every auditor's standard question - how do you ensure your systems are up to date? - with data instead of declarations of intent.
All systems we operate run in German data centers. For your data protection documentation this means: no third-country transfers, no standard contractual clauses and no transfer impact assessments at the infrastructure level.
The GDPR requires that data is not stored longer than necessary. In operations this means: defined backup retention, documented deletion at contract end and traceable handling of deletion requests - including with regard to backups.
Who has access to which systems - and why still? We manage SSH keys centrally, work with personal accounts instead of shared root passwords and revoke access in a documented way when employees leave or providers change.
From ongoing documentation to audit preparation - we deliver the evidence you need.
Reports on patching, backups, monitoring and incidents at the agreed interval and level of detail.
We support technical preparation for ISO 27001, BSI C5 and privacy assessments with evidence from our agreed service scope.
Technical and organizational measures (TOMs), network diagrams, access matrices and incident response plans.
Regular vulnerability scans and penetration test coordination with documented tracking of all findings.
The EU directive NIS2 (EU 2022/2555) obliges essential and important entities to implement cybersecurity risk management. In Germany, the NIS2 implementation act (NIS2UmsuCG) transposes the directive - it has been in force since December 2025. It affects companies from 18 sectors, generally from 50 employees or 10 million euros in annual revenue, and certain entities regardless of size.
Whether and how your company falls under NIS2 should be clarified with your legal counsel - we deliver the operational implementation and the evidence for it.
These services and articles complement the compliance topic.
Our infrastructure is designed for the requirements of regulated industries.
Client data, legal communication systems, professional obligations
Patient data, hospital regulations, telematics infrastructure
Financial regulatory requirements, DORA, critical infrastructure
BSI C5, public IT procurement, digital government compliance
Solvency II, insurance regulations, data protection requirements
SLA & Service Levels
Four tiers with clearly defined response times.
Monitoring Only
24/7 monitoring from €79.90; alerts go to your team.
Managed Zabbix
Platform operations from €79.90; alerts go to your team.
CVE Monitoring
Vulnerability scanning and patch management.
Server Management from €149.90
Your servers, our operations - patching, monitoring, and response.
Contract & Maintenance Model
How scope, maintenance cadence, and responsibilities are defined.
Legacy Operations
Operation and modernization of legacy systems.
A data-centre certification alone does not make a processing activity GDPR compliant. We document the selected location, provider, subprocessors and available certification evidence. Overall assessment depends on the application, configuration, data flows and the controller's organisational measures.
Yes, where WZ-IT acts as a processor under Article 28 GDPR. The DPA describes processing on instructions, subprocessors and technical and organisational measures; project-specific deviations are recorded before the contract starts.
Yes. We provide the technical and organisational measures, network diagrams, access matrices and patch, backup and incident evidence available within the agreed service scope. These documents do not replace the customer's ISMS or a certification.
We configure roles, multi-factor authentication, administrative access paths and logging within the supported and agreed scope. The operating documentation states which access events are recorded. Further details can be found on our monitoring page.
Yes. If your customers or their auditors request evidence about the infrastructure - for example via supplier questionnaires or security assessments - we deliver the relevant documents: TOMs, patch reports, backup evidence and data residency confirmation. On request we participate directly in audit meetings or calls.
Yes. Patch, monitoring and incident reports are documented with timestamps and system references and are exportable (PDF, CSV). They are suitable as evidence of operational measures in your GDPR documentation, in your organization's ISO 27001 audits and towards customer auditors. The reports do not replace your own ISMS, but they provide the operational evidence for it.
We support operational implementation with documented patch and vulnerability management, monitoring with defined escalation, backup concepts, agreed recovery evidence and access control. Whether and which NIS2 obligations apply to your organisation should be clarified with your legal counsel.
Tell us briefly what it is about - we will get back to you within one business day.
Customer feedback on monitoring, updates, maintenance, support and stable production systems.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
