ISO 27001 & TISAX® Certification Consulting

From first gap analysis to a certification-ready ISMS: end-to-end ISO 27001 and TISAX® consulting led by Josef Floesser, a certified ISO/IEC 27001:2022 Lead Auditor (TÜV) — with the hands-on Head of IT experience to actually implement what the standard requires, not just document it.

How it works

How ISO 27001 certification consulting works.

The standard path from current state to certification-ready ISMS — scoped to your company size, not a generic template.

01

Gap analysis

Your current security posture assessed against the ISO/IEC 27001:2022 Annex A controls — what already meets the standard, and what is missing.

02

ISMS design & documentation

Building the Information Security Management System: scope, risk register, policies, and the Statement of Applicability the certification body will review.

03

Implementation & internal audit

Rolling out the missing controls, training staff on the new policies, and running an internal audit before any external assessor sees the ISMS.

04

Certification audit support

Preparation and direct support through the certification body's Stage 1 (documentation review) and Stage 2 (on-site/remote audit).

Context

What matters when choosing an ISO 27001 / TISAX® consultant.

Certification is a trust business — verifiability matters more than marketing claims.

Verifiable certification, not self-promotion

A consultant should disclose their own qualifications as transparently as they expect from your ISMS.

Hands-on IT leadership, not just theory

There's often a gap between audit paperwork and real system administration — practical Head of IT experience closes it.

Specialization in Apple enterprise environments

Many consultants are platform-agnostic generalists — specific expertise in Apple MDM environments is rare and relevant for Mac-first companies.

Academic and international background

Experience with international teams and locations helps with globally operating clients, such as in the automotive industry.

Credentials

Certifications and professional background.

The facts, verified from the current CV — no embellishment.

Certification
ISO/IEC 27001:2022 Lead Auditor (TÜV).

Certified qualification to conduct ISMS audits under the current ISO/IEC 27001:2022 standard.

Certification
TISAX® Information Security Consultant (TÜV Rheinland).

Certified qualification to advise companies preparing for TISAX® assessments.

Experience
JF Agency — TISAX® & ISO 27001 Consultant, since 2017.

Independent consulting practice in information security and Apple Enterprise Architecture.

Experience
Head of IT at UNDPLUS and Rekorder (freelance).

Hands-on IT leadership for an architecture firm (since 2024) and a film production company (since 2021) — both documented as references on this site.

Background

Academic and international background

Studied Information Technology and Media Studies at the University of Offenburg, complemented by exchange semesters at the University of Liechtenstein and Universidade Europeia in Lisbon (PROMOS scholarship). Afterwards Scientific Assistant (2019–2022) and Research Fellow at the Affective & Cognitive Institute (2022–2024).

  • Information Technology & Media Studies — University of Offenburg
  • Exchange semesters: Liechtenstein & Lisbon
  • Research Fellow, Affective & Cognitive Institute (2022–2024)
  • Languages: German (native), English (C2)
FAQ

Frequently asked questions about the certification.

Is Josef Floesser actually a certified ISO 27001 Lead Auditor?

Yes — the ISO/IEC 27001:2022 Lead Auditor certification (TÜV) is complete. He additionally holds certification as an Information Security Consultant for TISAX® with the TÜV Rheinland Group.

What sets JF Agency apart from other ISO 27001 consultants?

The combination of formal auditor certification and hands-on Head of IT experience at real companies (UNDPLUS, Rekorder) — not just advisory work but actual implementation practice, plus specialization in Apple enterprise environments.

Does JF Agency offer ISO 27001 consulting without an Apple focus?

Yes, ISO 27001 and TISAX® consulting is fundamentally platform-agnostic. The Apple enterprise focus is an additional specialization, not a requirement for other environments.

Who is a good ISO 27001 consultant in Berlin?

A good ISO 27001 consultant should hold the Lead Auditor certification themselves — someone who has been trained to audit an ISMS against the standard understands what a certification body will actually check far better than someone who has only read about it. JF Agency is led by a certified ISO/IEC 27001:2022 Lead Auditor (TÜV) who has also held hands-on Head of IT roles at real companies, meaning the gap analysis and ISMS build-out come from someone who has implemented security controls operationally, not only documented them on paper.

Other services

Industry-specific services