IT Audit in Germany

How to prepare for your first IT audit in Germany

Facing your first IT audit in Germany? Learn how to prepare for customer audits, ISO 27001 certification, and GDPR reviews step by step, even without an IT team.

200+ companies already trust deeploi

Direct Answer

An IT audit in Germany typically means one of three things: a customer security questionnaire, an ISO 27001 certification audit, or a regulatory review from a supervisory authority or the BSI. Preparation comes down to documentation, a clean access and device inventory, and evidence your controls actually work, not just gaps discovered too late.

Key Takeaways

  • IT audits in Germany typically fall into three categories: customer security questionnaires, ISO 27001 certification audits, and regulatory reviews from supervisory authorities, and each requires a different preparation strategy.

  • Core preparation steps include building audit-proof documentation (Record of Processing Activities, IT policies, network diagrams), verifying access rights and device inventories, and gathering evidence for encryption, offboarding, and patch management.

  • The biggest mistakes companies without a dedicated IT team make are relying on scattered spreadsheets instead of centralized records, discovering orphaned accounts during the audit itself, and underestimating how long evidence gathering takes.

  • NIS2 is already law in Germany since December 6, 2025, with no transition period for security measures, and many SMBs don't realize they're in scope, either directly or through supply-chain requirements from regulated customers.

If you're an HR manager, office manager, or founder at a German SMB, chances are nobody warned you that IT audit preparation would land on your desk. Maybe a new enterprise customer sent over a security questionnaire. Maybe your board decided it's time to pursue ISO 27001. Or maybe a letter arrived from your local data protection authority announcing a GDPR review. Whatever triggered it, the question is the same: where do you even start?

This guide walks you through the practical steps, in plain language, so you can face your first IT audit with confidence. We'll cover the main audit types you'll encounter, the documentation and evidence you need, and the pitfalls that catch companies without dedicated IT staff. If you already use a platform like deeploi for IT compliance, some of this groundwork may already be in place. If not, you'll know exactly what to build.

What type of IT audit are you actually preparing for?

Not all IT audits are the same. The evidence an auditor expects, the timeline you're working with, and the consequences of failure vary significantly depending on who is asking and why. Before you start pulling together documents, figure out which category you're dealing with.

Customer security questionnaires and vendor audits

This is the most common first encounter for SMBs. An enterprise customer, or a prospect you really want to close, sends a security questionnaire asking how you handle data protection, access control, encryption, and incident response. These questionnaires have grown longer and more detailed in recent years, largely because of NIS2 supply-chain requirements.

Even if your company falls below the NIS2 threshold, regulated customers are now required to verify the security posture of their suppliers. That means you're being audited by proxy. The typical questionnaire covers device management policies, employee offboarding procedures, encryption standards, and whether you maintain audit logs. If you can't answer these questions convincingly, the deal stalls or dies.

ISO 27001 certification audits

A certification audit is a formal, multi-stage process conducted by an accredited auditor. It evaluates whether your Information Security Management System (ISMS, the structured framework of policies, controls, and processes you use to protect information) meets the ISO 27001 standard. Unlike a customer questionnaire, a certification audit examines the depth and consistency of your controls over time, not just a snapshot.

You'll typically go through a Stage 1 audit (documentation review) and a Stage 2 audit (on-site evidence gathering and interviews). The timeline from decision to certification usually runs six to twelve months for an SMB, depending on how much groundwork already exists. If you're early in this process, our guide on preparing your IT setup for ISO 27001 covers the foundational steps.

Regulatory reviews: GDPR and NIS2

A regulatory review is initiated by a supervisory authority, such as your state data protection authority (Landesdatenschutzbehörde) for GDPR or the BSI (Bundesamt für Sicherheit in der Informationstechnik) for NIS2. These reviews can be triggered by a complaint, a data breach notification, or a random sector-wide check.

Germany reported 27,829 GDPR data breach notifications between January 2024 and January 2025, placing it among Europe's top three countries for breach volume. (DLA Piper) Each notification is a potential trigger for a deeper review.

On the NIS2 side, the NIS2UmsuCG (Germany's NIS2 implementation law) has been in force since December 6, 2025 with no grace period for the security measures themselves. The BSI registration deadline was originally March 6, 2026, but has been extended to July 31, 2026 for companies that haven't registered yet. A common misconception involves the "Konzernklausel" (group clause): companies often assess NIS2 applicability in isolation when they should be evaluating it on a consolidated group basis. Subsidiaries of larger groups can be in scope even if they individually fall below the thresholds. NIS2 applies to any medium or large enterprise operating in 18 designated sectors, generally meaning 50 or more employees or annual turnover exceeding EUR 10 million. (SANS Institute)

Which compliance requirements apply to your IT systems?

Before diving into preparation, you need to know which rules actually apply to your company. Here's a quick orientation for SMBs in Germany.

GDPR applies to every company processing personal data of EU residents. It's not optional, and its documentation requirements (Record of Processing Activities, technical and organizational measures, data breach reporting) form the baseline for any audit. Our GDPR IT compliance checklist covers the practical IT controls you need.

NIS2 is mandatory for companies in 18 regulated sectors that meet the size thresholds. Roughly 80% of affected organizations reportedly don't realize they're regulated, often because they haven't assessed themselves at the group level. The European Commission has proposed targeted amendments to ease compliance for 28,700 companies, including 6,200 micro and small-sized enterprises, but the core obligations remain. (European Commission)

ISO 27001 is voluntary but increasingly expected by enterprise customers as a trust signal. If a customer questionnaire asks whether you're ISO 27001-certified, a "no" often triggers a longer, more detailed audit of your actual controls.

BSI IT-Grundschutz is the German national standard for information security, required for public-sector suppliers and critical infrastructure operators. Most SMBs won't need full BSI IT-Grundschutz compliance, but its catalogs are a useful reference for building your own security baseline. Having a clear IT security policy helps you map your controls to whichever framework applies.

How to prepare step by step

Build your documentation foundation

Documentation is where most first-time audit failures happen. Auditors don't expect perfection in your infrastructure. They expect you to know what you have, why you have it, and how you protect it, and to prove it on paper.

Start with these three documents:

  1. Record of Processing Activities (Verzeichnis von Verarbeitungstätigkeiten): Required under GDPR Article 30. It lists every process where your company handles personal data: what data, why, who has access, where it's stored, and how long you keep it. If you don't have one, this is your first priority.

  2. IT policies: At minimum, you need an acceptable use policy, a password policy, and an incident response procedure. These don't have to be long, but they must exist and be communicated to employees. An AI usage policy is also increasingly expected.

  3. Network and system diagrams: A visual overview of your IT environment: which cloud services you use, how devices connect, where data flows. This doesn't need to be a professional network map. A clear diagram that shows your actual setup is enough.

"Audit-proof" (revisionssicher) means your documentation is timestamped, version-controlled, and stored in a way that prevents undetected changes. A shared Google Drive folder can work if it has proper access controls and version history. A collection of email attachments cannot. For more on structuring this properly, see our guide on IT documentation for small businesses.

Verify access rights and device inventory

Auditors consistently check two things: who has access to what, and whether you know which devices are connected to your systems. Orphaned accounts (credentials belonging to former employees that were never deactivated) are one of the most common audit findings, and one of the easiest to prevent.

To prepare, pull a complete list of all user accounts across your SaaS tools, email, and cloud services. Cross-reference it against your current employee list. Deactivate anything that doesn't belong. Then build or update your device inventory: every laptop, phone, and tablet that accesses company data should be listed, with its owner, operating system version, and encryption status.

This is where companies without a dedicated IT team struggle most. When onboarding and offboarding happen informally, accounts accumulate. The global average cost of a data breach reached a record USD 4.88 million in 2024, a 10% increase from the prior year. (IBM) Orphaned accounts and unmanaged devices are exactly the kind of gap that turns a minor control weakness into a breach.

Gather evidence for encryption, offboarding, and patch management

Beyond documentation and access reviews, auditors want to see proof that specific technical controls are actually working. The three areas they focus on most are:

  • Encryption: Can you demonstrate that laptops use full-disk encryption (FileVault on macOS, BitLocker on Windows)? Can you show that data in transit is encrypted via TLS? Screenshots, MDM (mobile device management, software that lets you enforce security settings remotely) reports, or configuration exports serve as evidence.

  • Offboarding: When an employee leaves, is there a documented process for revoking access, recovering devices, and wiping company data? Auditors will ask for evidence from your last three to five departures. If you don't have a consistent process, start building one now.

  • Patch management: Are operating systems and critical software up to date? Auditors look for evidence that patches are applied within a reasonable window (typically 30 days for critical vulnerabilities). An automated update policy through MDM or endpoint management is the simplest way to prove this.

If you're an SMB without an IT team, producing this evidence manually is time-consuming but not impossible. The key is to start collecting it now, not the week before the audit. Companies in the SME security space that treat evidence collection as an ongoing process rather than a one-time project fare significantly better.

How do you reduce compliance risks with automation and audit logs?

Spreadsheets work until they don't. When an auditor asks you to prove that a specific account was deactivated on the day an employee left, a spreadsheet with a date in a cell isn't convincing. What's convincing is an automated log showing the deactivation event, timestamped, with the user who triggered it.

Automated audit logs solve three problems at once: they create evidence continuously without manual effort, they're tamper-resistant (unlike manually edited documents), and they reduce the preparation time before an audit from weeks to hours. For SMBs that manage IT across multiple SaaS tools without centralized visibility, the risk of gaps is real. 88% of SMB breaches in 2025 involved ransomware, compared to just 39% for large organizations. (Verizon) That disparity exists partly because smaller companies lack the logging and monitoring infrastructure that would catch suspicious activity early.

Centralized device management platforms that generate audit trails automatically are increasingly common in this space, with tools such as deeploi bringing device management, access logging, and compliance documentation together in a single platform. When customers ask about your vendor's security posture, a supplier holding ISO 27001 certification itself (as deeploi does) becomes a useful reference point. The broader point, regardless of which tool you choose, is that manual compliance tracking becomes a liability once you have more than a handful of employees and devices. Third-party and supply-chain risk doubled to account for 30% of all breaches in 2025. (Verizon) Your customers' auditors are increasingly looking at your controls, not just your promises.

Key takeaways

  • Identify which audit type you're facing (customer questionnaire, certification, or regulatory review) before you start preparing, because the evidence requirements and timelines are different for each.

  • Build your Record of Processing Activities and IT policies this week; these two documents are the most common gaps auditors find, and they take days, not months, to create.

  • Run an access-rights review and device inventory now, then schedule it quarterly; orphaned accounts are the single most preventable audit finding.

  • Move from spreadsheets to automated audit logs before your next audit; the time savings during preparation alone justify the switch.

  • Check NIS2 applicability at the group level, not just for your individual entity, because the group clause catches companies that assume they're too small to be affected.

Frequently asked questions

How do I document IT processes in an audit-proof way?

"Audit-proof" (revisionssicher) means your records are complete, timestamped, version-controlled, and protected against undetected modification. In practice, this means using systems with built-in version history and access controls rather than emailing Word documents back and forth. Cloud-based documentation platforms, IT management tools with automatic logging, or even a well-structured wiki with change tracking can meet this standard. The minimum requirement is that an auditor can verify when a document was created, when it was last changed, and by whom.

How long does it take to prepare for a first IT audit?

It depends on the audit type and your starting point. For a customer security questionnaire, two to four weeks is realistic if you already have basic documentation in place. For ISO 27001 certification, plan for six to twelve months from decision to Stage 2 audit. A GDPR regulatory review can arrive with as little as two weeks' notice, which is why maintaining ongoing documentation matters more than cramming. Companies that treat compliance as a continuous process rather than a project consistently report smoother audits.

Do I need compliance management software to pass an audit?

Not necessarily, especially for your first audit. Many SMBs pass customer questionnaires with well-organized cloud documents, a clean device inventory, and clear policies. However, manual processes have clear limits. Once you're managing more than about 20 employees and devices, the effort to keep spreadsheets accurate and audit-ready becomes unsustainable. Compliance software or an IT management platform that generates audit trails automatically saves significant time and reduces the risk of gaps that auditors would flag.

Does NIS2 apply to my company if we're under 50 employees?

Generally, NIS2 does not apply directly to companies with fewer than 50 employees and under EUR 10 million in annual turnover. However, there are two important exceptions. First, the group clause (Konzernklausel): if your company is a subsidiary of a larger group that exceeds the thresholds, you may be in scope even if your entity alone is small. Second, supply-chain pressure: even if NIS2 doesn't apply to you directly, your NIS2-regulated customers are required to verify your security measures as part of their own compliance. In practice, this means many sub-threshold companies still need to demonstrate controls.

What happens if we fail an IT audit?

Consequences depend on the audit type. Failing a customer security questionnaire usually means losing the deal or being placed on a remediation plan with a deadline. Failing an ISO 27001 certification audit means you don't receive the certificate; you can re-attempt after addressing the findings, but this adds months and cost. Failing a GDPR regulatory review can result in corrective orders, formal warnings, or fines. European supervisory authorities issued EUR 1.2 billion in GDPR fines in the twelve months ending January 2025, bringing total fines since 2018 to EUR 5.88 billion. Under NIS2, fines for substantive violations by "besonders wichtige Einrichtungen" (essential entities) can reach EUR 10 million or 2% of global annual revenue, and even failing to register can result in penalties up to EUR 500,000.

Conclusion

Preparation beats perfection. The goal of your first IT audit isn't to present a flawless infrastructure. It's to demonstrate that you understand your IT environment, have documented your controls, and can show evidence that those controls are working. Auditors are far more forgiving of an honest gap with a remediation plan than of a company that clearly hasn't thought about security at all.

Start with the documentation and access review steps outlined above. Get your Record of Processing Activities in order. Run an account cleanup. Write down your IT policies, even if they're simple. These steps cost time but not money, and they address the findings that trip up most first-time audit candidates. If you're growing fast and managing IT alongside your actual job, consider whether a centralized IT management platform could take the ongoing evidence collection off your plate entirely.

Founded
Customer Size
Headquarters
Industry
KEY RESULTS
CUSTOMER STORIES
This field is required
This field is required
This field is required
Choose
This field is required
This field is required
Thank you for your interest!

We’ll get back to you shortly.

Oops! Something went wrong while submitting the form.

Download the professional onboarding checklist for free

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Get the checklist