ISO 22301 Experts in Germany
in minutes from over 15,000 CVs with the power of AI.Hire experts who build business continuity management systems, run gap assessments, prepare certification readiness, and improve incident response plans. Work with vetted, available specialists who can support German or remote teams with fast, precise matching.
Meet FRATCH Experts in Germany, who have recently used ISO 22301
Sandra Klinkenberg
Last position:
Webinar Leader - Blackout Prevention and Preparation at SANDRA KLINKENBERG • Management Consultant, self-employed independent business consultant
- Webinar on Blackout - Brownout - Power failure - how do I recognise it and what can I do?
M. S.
Last position:
Security consulting, audits & assessments
- Innovation/pilot project eHealth Germany
- SaaS company in the media sector, NRW
- Secure software development lifecycle, NRW
- BSI IT baseline protection assessments for multiple clinics
Tarek El Idrisi
Last position:
Associate GRC at Egerer Consulting
Carve-out project: Development of certification strategy, implementation and requirement plans across multiple standards — ISO/IEC 27001, ISO 9001, ISO 14001, ISO 22301, ISO/IEC 20000-1, BSI IT-Grundschutz, and BSI TR-RESISCAN
- Cross-standard inventory and risk assessment
- Coordination with cross-department stakeholders: ISB, executive management, certification bodies, legal and data protection
- Consulting in information security, GRC, and IT auditing
Federico Leefhelm
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW. Developed and implemented a holistic process view covering both technical and organizational aspects Ensured end-to-end control of all IAM-related technical services Established clear responsibilities and accountabilities within the IAM landscape Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security Introduced and monitored governance policies to ensure compliance and security Continuously improved IAM processes and systems through regular audits and evaluations Participated in external audits of the process as part of official ISO audits Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units Conceptually advanced the KPI system to measure process quality
Alexander Sänn
Last position:
Lead Audit Conformity & IT Security Catalog at DAX group energy provider in the renewable energy sector
- Supported the implementation of §8a requirements of the BSI Act for critical infrastructures.
- Systematically prepared and supported internal and external audits, resolving previous deviations (HA, NA, VP)
- Implemented the specific requirements of the IT security catalog
- Developed training, created run books, and conducted assessments to ensure operational effectiveness.
Serdar Colak
Last position:
Consultant at Freelance
- ISO 27001 implementation & audit readiness
- NIS2 & DORA compliance support
- Interim / fractional CISO services
- IT risk & controls (ITGC, SOX, COBIT, BAIT)
- M&A and IT due diligence for startups/ventures
- Business continuity management (BCM, ISO 22301)
- Cybersecurity framework development (NIST, ISO, BSI)
- GRC tool advisory (Archer, ServiceNow)
Kai Saathoff
Last position:
Senior Manager Regulatory Changes and Digitalization at Consulting Firm
- Responsible for business development, sales, partnerships, and marketing
- Project management and business analysis for regulatory and strategic projects
- Test management
- Expert in digitalization strategies
- Expert in new EU regulations and legislative changes
- Expert in client-related projects
- Implementations in asset management and in the banking sector
Robert Vattig
Last position:
Freelance Consultant Information Security and Business Continuity at Freelance business consulting
- Provide consulting services nationwide in both private and public sectors
- Advise on information security management systems, IT-Grundschutz, KRITIS compliance, TISAX, business continuity and crisis management
- Support the introduction of policies, risk management methods, asset registers and supplier management
- Conduct internal audits, training workshops and support audit preparations
David Bleyer
Last position:
Acting Partner at Bliestal Consulting UG
- Redesigning cablewise infrastructure with CAT 8.1 keystones, measuring the speed and quality of the new installation with Pockethernet, documentation at a local saddlery
- CAT 8.1 installation and building a data center, site linking, VPN and VLAN configuration for a local car dealership, implementation of IT-Security standards like virus protection (G Data) and firewalling (OPNSense)
- Relocation of a tax office with redesign of the IT infrastructure, virus protection (G Data) and backup solutions (QNAP)
- Planning, conception and implementation of an inhouse data center, BSI-compliant for commercial laundry (including Proxmox-based virtualization of existing infrastructures, QNAP, G Data, OPNSense, APC)
- Implementation and conception of security solutions in the SME sector
- Collaboration on the IT-security concept for the Bremen network of authorities (in the dLAN network)
- Creation of IT-security concept VOIS (modules MESO, KFZ/iKFZ) including audit preparation for KBA
- Expansion of the IT-security concept for the online service for electronic residence registration (eWA) to include use as an eFA (one-for-all) service (nationwide)
- Expansion of the IT-security concept to include modules wos & wvp
- Concept development for the implementation of DIN SPEC 27076 at MSEs and SMEs
- Creation and evaluation of emergency concepts
- Creation and evaluation of response actions and BCM plans
- Assessment of existing business continuity management (ISO 22301)
- Development of BCM strategy options
- Conducting awareness training
Dmitrii Shatov
Last position:
IT Risk & Compliance | DORA | IT Regulatory & Operational Resilience Senior Consultant at Jefferies GmbH
Leading Jefferies’ DORA-driven operational resilience programme by strengthening ICT risk governance, control design, and regulatory readiness across key technology and outsourcing domains. Partnering with senior stakeholders to translate regulatory requirements into pragmatic governance, reporting, and assurance processes suitable for a global investment banking environment.
- Developed the Enterprise Register of Information (DORA Art. 28.3) to align with regulatory requirements.
- Defined and embedded ICT Risk Appetite and tolerance levels aligned to the Global Operational Risk Framework, strengthening decision-making and risk acceptance governance.
- Drove audit readiness by reviewing and re-drafting 50+ IT & Information Security policies, improving clarity, ownership, and control alignment.
- Oversaw the Operational Resilience Testing Programme (including penetration testing) and tracked remediation to closure, strengthening control assurance and reducing open findings.
- Aligned 10+ intra-group agreements with DORA regulatory standards.
- Enhanced executive-level decision-making with an enterprise ICT Risk Dashboard featuring KPIs/KRIs.
Jens Brennscheidt
Last position:
Senior Cyber Security Consultant at Brennscheidt IT Consulting
ISMS consulting
Interim management
Conducting security analyses & audits
BCM consulting
Executive management
Valeri Milke
Last position:
Associate Partner - Information Security Consulting at Insentis GmbH
- Improvement of the Information Security Management System (ISMS) based on ISO 27001, NIS2, DORA, B3S, TISAX and BSI IT Baseline Protection
- Conducting comprehensive gap analyses to identify gaps and derive action plans according to the above standards and regulations; management and KPIs
- Data Loss Prevention strategy and implementation using MS Purview
- Vulnerability and patch management, security monitoring
- Risk analysis and threat modeling using the STRIDE methodology
- Development of vendor risk assessments, implementation of risk classifications, conducting supplier assessments and implementing technical monitoring solutions (e.g. Security ScoreCard)
- Securing cloud environments (AWS and Azure); expertise in CSPM/CNAPP (Wiz), cloud migration, secure CI/CD pipelines, container security and best practices in AWS, Azure and Office 365
- Application security: penetration testing, DevSecOps, OWASP, pre-commit hooks, key and secret management, IDE plugins, static source code analysis, dependency checks, container scanning, vulnerability management, CIS benchmarks and compliance
- Security assessment and hardening according to CIS benchmarks and cloud conformity in AWS, Office 365 and Azure
Luca Pacor
Last position:
ERP Program Manager at Fiserv
The client is undergoing a comprehensive transformation. All SAP ECC landscapes worldwide are being migrated to SAP S/4HANA, with the goal of introducing a global standard template.
The program also includes the migration and modernization initiative "RISE with SAP", which may involve migrating selected country installations to the SAP Private Cloud.
On the stakeholder side, the program's reporting line extends up to the company's board and the implementation partner's board.
Fiserv Germany's ERP landscape currently includes several non-standard SAP tools and applications that extend the ECC environment's functionality and often integrate with downstream systems. As part of the move to SAP S/4HANA, it is essential to assess the core functionality, integration points, and future viability of these applications to determine their alignment with the target architecture.
The focus of the role is to provide expert advice and assessment to define the scope, strategy, and roadmap for migrating Fiserv Germany's SAP ECC system to SAP S/4HANA.
SAP's recommended best practices are followed, and a structured approach is used to ensure a smooth transition with minimal disruption while maximizing business value.
This assessment forms the basis for a successful SAP S/4HANA transformation, ensuring alignment with industry best practices, regulatory compliance, and future scalability.
Migration strategy definition – evaluating available transition approaches based on business objectives, technical feasibility, and SAP best practices.
Technical readiness assessment – conducting a system analysis to assess compatibility, custom code impact, data volume management, integration points, and infrastructure readiness for SAP S/4HANA.
Business process impact analysis – reviewing the latest business process documentation to define the scope and effort needed to implement required functions in SAP S/4HANA and identify process optimization opportunities.
Roadmap for non-SAP systems and applications – evaluating third-party and legacy applications for SAP S/4HANA integration and recommending consolidation, migration, or replacement strategies.
Deployment & implementation planning – defining a phased rollout approach, including project timelines, risk mitigation strategies, and key milestones aligned with business priorities.
The transformation is carried out in phases: the discovery phase leads to the explore phase, which then leads to the design phase and finally to the implementation phase.
Program management
Change management
Requirements management
Transition management
Stakeholder management
Risk management
Comprehensive coordination
Harald Kirsch
Last position:
Lecturer - Business Informatics & Business Administration at Fachhochschule des Mittelstands (FHM)
As part of my work, I focus on three key areas that are essential for the innovation and future viability of business and society: business start-ups, digitalization and automation, and career planning and personal development.
One focus is on the challenges and opportunities of starting a business—especially academic start-ups as drivers of regional and national innovation. I teach skills for the entire start-up process: from idea creation and building viable business models to managing and scaling a company.
The topic of digitalization and automation covers technical, economic, and social dimensions. It includes basics of digitalization, automation technologies, IIoT and smart manufacturing, software and IT infrastructures, and application areas in various industries. I also analyze human-machine interaction, economic impacts, and future trends that have a lasting effect on companies.
In the area of career planning and personal development, I support future specialists and managers in developing their personal strengths, recognizing their entrepreneurial and intrapreneurial potential, and designing an individual market and career strategy. Topics such as personal branding, personal marketing, and strategic career planning are key to fostering long-term professional direction and proactive action.
Bernd Schmidl
Last position:
Head of IT Business Applications & Partnerships at Software AG
- Strategic overall management of the global IT application landscape and further development of the roadmap for core applications (Salesforce, SAP, Workday, OpenAir, Jira)
- Realignment of the IT architecture towards cloud-native (IaaS/SaaS) and establishment of an agile DevOps culture and process automation
- Leading the IT application workstream for the successful separation of four business units (carve-outs)
- Acting as a strategic business partner for C-level functions (COO, CRO, CHRO) to ensure IT-business alignment
- Representing IT interests to employee representative bodies and ensuring compliance
- Reduced maintenance effort by 66% by designing and rolling out a new customer portal
- Implemented a fully automated CPQ self-service to accelerate sales processes
- Successfully went live with critical business platforms to support the target operating model (e.g., Dayforce for HR/payroll, Coupa for P2P, Zuora for billing)
- Replaced legacy custom software with scalable SaaS standard solutions (legacy modernization)
Discover over 15,000 top freelancers
Statistics of experts using ISO 22301
Aggregated from the professional profiles of matched freelancers.
Experience
21 years
Position duration
2.9 years
Positions per freelancer
15
Top business areas
Information Technology, Project Management, Quality Assurance
Top industries
Information Technology, Professional Services, Banking and Finance
Certification focus areas
Information Technology, Audit, Quality Assurance
Bachelor's degree or higher
90%
Master's degree or higher
48%
Doctorate
10%
Certifications per freelancer
8
Most common languages
German, English, French
Speak two or more languages
93%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using ISO 22301
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Business continuity ISO 22301 defines how a business continuity management system works. It helps companies keep critical services running, even when operations are disrupted by outages, supplier issues, cyber incidents, or site problems. Strong specialists turn the standard into clear controls, owners, and recovery steps.
What experts deliver
- Business continuity scope and policy setup
- Business impact analysis and risk review
- Recovery objectives and response plans
- Internal audit and certification preparation
- Improvement plans after exercises or incidents
Common projects Companies bring in freelance specialists for ISO 22301 from the first gap assessment through certification support and ongoing maintenance. In Germany, this often involves coordination with compliance, operations, IT, and security teams, especially where local and international sites must follow the same continuity model.
Ecosystem and skills A strong specialist understands the standard, audit evidence, crisis coordination, and document control. They also work well with related areas such as ISO 27001, risk management, incident handling, supplier resilience, and disaster recovery planning. Clear writing matters because plans only work when teams can use them under pressure.
When to hire
- You need a fresh gap analysis against ISO 22301
- Certification work is stalled or unclear
- Existing plans are outdated or untested
- New services, sites, or vendors changed the risk picture
- You need interim support for continuity tasks
Strong delivery The best experts do more than write documents. They test scenarios, challenge weak assumptions, and make sure the plan fits real operations. Good ISO 22301 work is practical, traceable, and ready for audit without adding unnecessary complexity.
Frequently asked questions
What clients ask us most about ISO 22301 — answered in short.
ISO 22301 covers business continuity management. It helps an organization prepare for disruption, protect critical activities, and define how recovery should work across people, process, technology, and suppliers. The focus is on keeping essential services available when normal operations are interrupted.
ISO 22301 is about continuity, while ISO 27001 focuses on information security. The two standards often work together, but they solve different problems: one keeps services running, the other protects information assets. Many projects need both because continuity and security overlap during incidents.
A ISO 22301 specialist is often brought in when a gap assessment shows missing controls, when certification work needs structure, or when plans need a full refresh. They are also useful after incidents, reorganizations, supplier changes, or new service launches. In Germany, this support is often needed across distributed teams and sites.
A strong ISO 22301 freelancer has worked on business impact analysis, recovery planning, exercise design, and audit preparation. They should be comfortable turning the standard into usable procedures and evidence. Experience with operational continuity, governance, and documentation quality matters more than theory alone.
A BCMS specialist usually also knows risk management, incident response, disaster recovery, internal audit, and supplier management. Familiarity with ISO 27001 helps, especially where continuity and security controls overlap. Good communication skills are important because the work depends on coordination across departments.
Yes, much of the ISO 22301 work can be done remotely because it relies on workshops, document review, and coordination. On-site time can still help when a specialist needs to observe operations, test recovery steps, or meet local stakeholders. For German organizations, a mix of remote and on-site work is common.
Look for clear examples of gap assessments, continuity plans, exercise results, and audit support from the ISO 22301 work they have done. Strong candidates explain trade-offs in plain language and show how their recommendations fit the business. Ask how they make plans testable, owned, and easy to maintain.
A business continuity management system is the structured way an organization prepares for disruption and keeps improving its response. Under ISO 22301, it includes scope, policy, risk and impact analysis, plans, exercises, and review cycles. The best specialists make the system workable, not just compliant.
The average hourly rate of freelancers in Germany who have used ISO 22301 in their recent projects is 125 €, which corresponds to a daily rate of about 1,004 € based on an 8-hour working day.
Of the freelancers in Germany who have used ISO 22301 in their recent projects, 90% hold at least a Bachelor's degree, 48% hold at least a Master's degree, and 10% hold a doctorate.
On average, freelancers in Germany who have used ISO 22301 in their recent projects have 21 years of professional experience, with a single engagement typically lasting around 2.9 years.
The most common languages among freelancers in Germany who have used ISO 22301 in their recent projects are German (100%), English (93%), and French (28%).
The most common industries among freelancers in Germany who have used ISO 22301 in their recent projects are Information Technology (86%), Professional Services (76%), and Banking and Finance (55%).
The most common business areas among freelancers in Germany who have used ISO 22301 in their recent projects are Information Technology (100%), Project Management (86%), and Quality Assurance (83%).
Main locations of FRATCH Experts, who have recently used ISO 22301
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
