top of page

COSI-DIAG by 

milvius.systems_transparent.png

AI-BASED READINESS AUDIT FOR NIS2, ISO 27001, AND BEYOND

Catch the gaps in your client’s ISMS documentation before the auditors do.

COSI DIAG audits your documentation against all NIS2 and ISO 27001 requirements—including all 93 Annex A controls—delivering an objective compliance score in minutes, not days. See the FAQ section on this page for all supported standards.

Accelerate your workflow without sacrificing depth.

Clause.png

MARKET PRESSURE

Pre-audits take days.

AI drives down margins.

Where multiple consultants audit, quality fluctuates. COSI delivers the same reproducible benchmark across the entire pool. This includes maturity transparency based on the Capability Maturity Model (CMM)—offering a quantified maturity level for each process instead of a binary statement, delivered in a language that resonates all the way up to the executive board. On-premises deployment and enterprise terms are available as a separate tier.

HOW COSI DIAG WORKS

Drop documents. Get findings.

In minutes

01

Hochladen

Simply upload

your client's available

ISMS documentation.

 

shield.png

02

Complete assessment

A complete

ISO 27001 assessment

across all 93 Annex A controls.

03

View results

Get a clear compliance score

and a gap report featuring specific evidence

mapped right down to the clause level.

118 Checks in 91 Seconds

In our first chat, we'll give you

a live demo using one of your actual files.

REPRODUCIBLE AND OBJECTIVE

No guesswork.

The exact same result, every time.

Instead of a person-dependent assessment, you receive a reproducible score and a gap report. The same input will yield the exact same result tomorrow. You can present this objective finding to your client as verifiable proof.

Gauge.png

DATA SECURITY

100% GDPR-compliant handling of your client records.

COSI-DIAG runs as a dedicated service on an EU-hosted language model. Customer data is completely excluded from AI training, data processing is strictly governed by a DPA, and every client operates within an isolated, tenant-centric workspace. This allows you to process confidential files in a highly secure environment—completely hidden from the public web.

 

Need absolute data sovereignty? COSI can be deployed on-premises with your own local language model, ensuring no document ever leaves your corporate network.

EU-Hosting

Zero training on your data

Data Processing Agreement

Isolated

Tenant Workspaces

PRICE AND VALUE

 

Measure the value
before you check the price!

Saving three to five days of pre-assessment per request gives you the added value per inquiry, based on your own daily rate. This is a realistic calculation model using your numbers, not a guaranteed financial return.

YOUR NUMBERS

Days saved per inquiry

€/ day

/ Year

Calculated annual value €96,000

ADDED VALUE PER REQUEST

4.800 €

4 days x €1,200 daily rate

Price

€1,000 / month per user

COSI-DIAG as a SaaS Operation

€95-a-month tools are just "coaches" locked into a set implementation package to comment on paperwork. COSI is different: an independent auditor for your actual documentation. It’s a completely different league, regardless of the coach's lower price tag.

FOR IT SERVICE PROVIDERS AND PRACTICES

Standardized quality

across your entire consultant network.

More consultants mean fluctuating review quality. COSI brings a single, reproducible standard to your entire pool—complete with maturity transparency based on the Capability Maturity Model (CMM). Get a quantified maturity level per process instead of a simple pass/fail, using metrics that speak directly to the C-suite. On-premise deployment and enterprise terms are handled as a separate tier.

Clause.png

OUR CURRENT STATUS

 

Results build trust.

 

The strongest validation of our work is found in the companies that rely on our solution daily. Here, we present selected clients, case studies, and practical applications.

If you would like to experience it firsthand, we welcome the opportunity to demonstrate COSI DIAG live using a sample of your own documentation.

Cross-sector references

Customer Voices &

Success Stories

Custom

Live Demo

Top questions from auditors.
  • COSI-DIAG is an AI-powered software for ISMS maturity analysis. It scans your existing information security documentation to pinpoint gaps, inconsistencies, and room for improvement—helping your business streamline preparation for ISO 27001 audits, NIS2 requirements, and internal or external compliance checks.

  • No. COSI-DIAG does not replace internal or external certification audits. Instead, it acts as an objective diagnostic tool to measure your current ISMS maturity level and catch potential compliance gaps before auditors do—reducing your audit risk and heavily accelerating preparation.

  • COSI-DIAG analyzes your existing ISMS documentation—like policies, processes, blueprints, and supporting evidence. You don't need a complete set of files to start; even incomplete documentation delivers actionable insights into your current maturity level and shows you exactly where to improve.

  • Traditional compliance checks and gap analyses are often just brief snapshots, heavily biased by individual auditors or consultants. COSI-DIAG automates this process, analyzing your ISMS documentation in a completely reproducible way. It flags gaps, inconsistencies, and issues, scores your management system's maturity, and delivers a prioritized management report. The result? A reliable, real-time view of your information security status whenever you need it.

  • Yes. COSI-DIAG can be deployed entirely on-premise—complete with a local Large Language Model (LLM) if desired. This keeps your sensitive ISMS files, security policies, and compliance documents safely within your own IT infrastructure, easily satisfying the highest data privacy, security, and regulatory requirements.

  • COSI-DIAG validates compliance with the following standards: ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO 22301:2019, ISO/IEC 27017:2015, ISO/IEC 27018:2025, ISO/IEC 27701:2025, and NIS2 (EU 2024/2690).

  • COSI-DIAG is built for any organization operating an ISMS or managing strict information security compliance. It is highly optimized for:

    • Critical Industries: KRITIS (Critical Infrastructure), Healthcare, Energy, Utilities, and Public Administration.

    • Commercial Sectors: Manufacturing, Industrial Production, Finance, Insurance, and IT Service Providers.

    • Compliance Goals: Companies actively preparing for ISO 27001 certification or the NIS2 directive.

    By delivering automated maturity insights, it provides Information Security Officers (ISOs), CISOs, compliance managers, and executive leadership with the visibility needed to catch gaps early and streamline audit preparation.

THE NEXT STEP: DISCOVERY CALL

See it live on your own document

in just 15 minutes.

Bring your biggest challenge.

We’ll show you exactly how to solve it.

100% Free

Your first call

is completely free and non-binding.

~30 Minutes

Short, efficient,

and strictly focused

on your specific questions.

Sleek & Modern

The meeting takes place conveniently via Microsoft Teams.

Your Contact

You will speak directly

with the Managing Director

of milvius.systems.

CONTACT US

Let’s talk

Have questions about COSI DIAG or need help preparing for your next audit?

Drop us a line—we’d love to hear from you!

Talk directly to Ing. Klaus Thurnhofer,

the creator of COSI-DIAG.

Straight to the expert—no sales pitch.

Send an email

For brief questions or general information. We will get back to you shortly.

Persönliches Erstgespräch vereinbaren

Unternehmensgröße
Norm
bottom of page