Aducis makes access rights audit-proof for the regulated mid-market — from initial assessment to ongoing operations.
Tool-neutral. Practice from the most heavily regulated environment there is.
They fail because no one can prove who has access to what, and why. Since NIS2 and DORA, regulators and management expect exactly that evidence — and are personally liable for it.
Aducis is not a tool rollout and not billable hours. It is the professional and technical control layer for identity and access governance — tool-neutral, with hands-on experience from the most heavily regulated environment there is (banking/DORA). The result: role and entitlement models, processes and evidence that hold up in an audit.
The fastest route to defensible evidence: Aducis reviews your access rights against the requirements of NIS2 and DORA and delivers exactly what regulators and your board want to see.
Result: audit-proof evidence and a prioritized gap list.
Not sure where you stand? Take the free 3-minute self-check →
Fixed packages instead of open-ended hours — each with a defined scope, outcome and timeframe. Prices shown openly as starting values.
Maturity, gaps and orientation: where does your entitlement management stand — and what is missing to become audit-proof?
Result: status report with maturity rating and prioritized gap list.
Joiner, mover and leaver processes cleanly modeled — from request to evidence, repeatable and auditable.
Result: documented, audit-proof JML processes.
Is your IAM tool audit-proof — or merely technical? An assessment of configuration, processes and evidence capability of your entitlement/IAM tool (e.g. tenfold or Microsoft Entra ID Governance).
Result: operational-readiness report with recommendations.
Ongoing professional stewardship: recertification, concept maintenance and evidence stay audit-proof — without a full-time hire.
Result: continuous governance with a dedicated contact.
All prices are starting values. Your actual quote depends on size, system landscape and regulatory scope — after a short intro call you receive an individual fixed-price offer.
No package fits exactly? Request a tailored offer.
Regulated SMEs and mid-market companies with roughly 50 to 2,500 employees in scope of NIS2 — primarily across four sectors:
Banks and financial institutions under DORA — the most heavily regulated environment Aducis brings its practice from.
NIS2 and DORA apply across the EU; Aducis supports German companies with operations in the region just as it does South-East European companies doing business in Germany.
Aducis is built on practice from the most heavily regulated environment there is — identity and access governance in banking under DORA. What holds up to an audit there holds up anywhere. Aducis brings that rigor to the regulated mid-market: tool-neutral, with technical depth in Active Directory, Microsoft Entra ID and common IAM tools — as the basis for sound assessment and steering, not as a product pitch.
Make maturity and gaps visible.
Define roles, rules and processes.
Steer the rollout, manage service providers.
Keep the evidence, keep governance alive.
Projects in banking and critical-infrastructure environments are strictly confidential. I am glad to discuss concrete references and project examples in a personal conversation — with fitting contacts on request.
A short, no-obligation conversation shows whether — and where — action is needed.