AI-BASED READINESS AUDIT FOR NIS2, ISO 27001, AND BEYOND
Catch the gaps in your client’s ISMS documentation before the auditors do.
COSI DIAG audits your documentation against all NIS2 and ISO 27001 requirements—including all 93 Annex A controls—delivering an objective compliance score in minutes, not days. See the FAQ section on this page for all supported standards.
Accelerate your workflow without sacrificing depth.

MARKET PRESSURE
Pre-audits take days.
AI drives down margins.
Where multiple consultants audit, quality fluctuates. COSI delivers the same reproducible benchmark across the entire pool. This includes maturity transparency based on the Capability Maturity Model (CMM)—offering a quantified maturity level for each process instead of a binary statement, delivered in a language that resonates all the way up to the executive board. On-premises deployment and enterprise terms are available as a separate tier.
HOW COSI DIAG WORKS
Drop documents. Get findings.
In minutes
01
Hochladen
Simply upload
your client's available
ISMS documentation.

02
Complete assessment
A complete
ISO 27001 assessment
across all 93 Annex A controls.
03
View results
Get a clear compliance score
and a gap report featuring specific evidence
mapped right down to the clause level.
118 Checks in 91 Seconds
In our first chat, we'll give you
a live demo using one of your actual files.
REPRODUCIBLE AND OBJECTIVE
No guesswork.
The exact same result, every time.
Instead of a person-dependent assessment, you receive a reproducible score and a gap report. The same input will yield the exact same result tomorrow. You can present this objective finding to your client as verifiable proof.

DATA SECURITY
100% GDPR-compliant handling of your client records.
COSI-DIAG runs as a dedicated service on an EU-hosted language model. Customer data is completely excluded from AI training, data processing is strictly governed by a DPA, and every client operates within an isolated, tenant-centric workspace. This allows you to process confidential files in a highly secure environment—completely hidden from the public web.
Need absolute data sovereignty? COSI can be deployed on-premises with your own local language model, ensuring no document ever leaves your corporate network.
EU-Hosting
Zero training on your data
Data Processing Agreement
Isolated
Tenant Workspaces
PRICE AND VALUE
Measure the value
before you check the price!
Saving three to five days of pre-assessment per request gives you the added value per inquiry, based on your own daily rate. This is a realistic calculation model using your numbers, not a guaranteed financial return.
YOUR NUMBERS
Days saved per inquiry
€/ day
/ Year
Calculated annual value €96,000
ADDED VALUE PER REQUEST
4.800 €
4 days x €1,200 daily rate
Price
€1,000 / month per user
COSI-DIAG as a SaaS Operation
€95-a-month tools are just "coaches" locked into a set implementation package to comment on paperwork. COSI is different: an independent auditor for your actual documentation. It’s a completely different league, regardless of the coach's lower price tag.
FOR IT SERVICE PROVIDERS AND PRACTICES
Standardized quality
across your entire consultant network.
More consultants mean fluctuating review quality. COSI brings a single, reproducible standard to your entire pool—complete with maturity transparency based on the Capability Maturity Model (CMM). Get a quantified maturity level per process instead of a simple pass/fail, using metrics that speak directly to the C-suite. On-premise deployment and enterprise terms are handled as a separate tier.

OUR CURRENT STATUS
Results build trust.
The strongest validation of our work is found in the companies that rely on our solution daily. Here, we present selected clients, case studies, and practical applications.
If you would like to experience it firsthand, we welcome the opportunity to demonstrate COSI DIAG live using a sample of your own documentation.
Cross-sector references
Customer Voices &
Success Stories
Custom
Live Demo
Top questions from auditors.
COSI-DIAG is an AI-powered software for ISMS maturity analysis. It scans your existing information security documentation to pinpoint gaps, inconsistencies, and room for improvement—helping your business streamline preparation for ISO 27001 audits, NIS2 requirements, and internal or external compliance checks.
No. COSI-DIAG does not replace internal or external certification audits. Instead, it acts as an objective diagnostic tool to measure your current ISMS maturity level and catch potential compliance gaps before auditors do—reducing your audit risk and heavily accelerating preparation.
COSI-DIAG analyzes your existing ISMS documentation—like policies, processes, blueprints, and supporting evidence. You don't need a complete set of files to start; even incomplete documentation delivers actionable insights into your current maturity level and shows you exactly where to improve.
Traditional compliance checks and gap analyses are often just brief snapshots, heavily biased by individual auditors or consultants. COSI-DIAG automates this process, analyzing your ISMS documentation in a completely reproducible way. It flags gaps, inconsistencies, and issues, scores your management system's maturity, and delivers a prioritized management report. The result? A reliable, real-time view of your information security status whenever you need it.
Yes. COSI-DIAG can be deployed entirely on-premise—complete with a local Large Language Model (LLM) if desired. This keeps your sensitive ISMS files, security policies, and compliance documents safely within your own IT infrastructure, easily satisfying the highest data privacy, security, and regulatory requirements.
COSI-DIAG validates compliance with the following standards: ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO 22301:2019, ISO/IEC 27017:2015, ISO/IEC 27018:2025, ISO/IEC 27701:2025, and NIS2 (EU 2024/2690).
COSI-DIAG is built for any organization operating an ISMS or managing strict information security compliance. It is highly optimized for:
-
Critical Industries: KRITIS (Critical Infrastructure), Healthcare, Energy, Utilities, and Public Administration.
-
Commercial Sectors: Manufacturing, Industrial Production, Finance, Insurance, and IT Service Providers.
-
Compliance Goals: Companies actively preparing for ISO 27001 certification or the NIS2 directive.
By delivering automated maturity insights, it provides Information Security Officers (ISOs), CISOs, compliance managers, and executive leadership with the visibility needed to catch gaps early and streamline audit preparation.
-
THE NEXT STEP: DISCOVERY CALL
See it live on your own document
in just 15 minutes.
Bring your biggest challenge.
We’ll show you exactly how to solve it.
100% Free
Your first call
is completely free and non-binding.
~30 Minutes
Short, efficient,
and strictly focused
on your specific questions.
Sleek & Modern
The meeting takes place conveniently via Microsoft Teams.
Your Contact
You will speak directly
with the Managing Director
of milvius.systems.
CONTACT US
Let’s talk
Have questions about COSI DIAG or need help preparing for your next audit?
Drop us a line—we’d love to hear from you!
Talk directly to Ing. Klaus Thurnhofer,
the creator of COSI-DIAG.
Straight to the expert—no sales pitch.
Send an email
For brief questions or general information. We will get back to you shortly.
