We clear the regulatory jungle for SaaS.
Eighteen obligations across four domains feel like a thicket. They are just an uncleared path. awedit scans your real product, shows you exactly what applies, and gets you ready. Where the law names an examiner, we walk you to the gate. Where you sign your own declaration, we arm you to hold up under supervision.
WE CLEAR THE PATH · WE READY YOU · WE HAND OVER · Orientation, not evidence.
Free, instant orientation on which obligations apply to your product.
Experts weigh every finding against your real artifacts, accelerated by AI that reads your artifacts, not your checklists.
A handover-ready report. To an examiner where the law names one, to your own signature where you self-declare.
We clear the path. We ready you. We hand over.
You do not meet one regulation. You meet all of them at once, without a map.
No SaaS team experiences C5, or the BFSG, or NIS2 on its own. You experience the whole stack at the same time, in different languages, with different endings, on different deadlines. That is the exact definition of a jungle.
Overlapping laws, unclear scope, moving deadlines. Weeks lost deciding what even applies.
Checklists that never read your actual product. Effort spent on obligations you do not have.
Readiness no one downstream can use as-is. Rework at the most expensive point.
The same four steps, whichever regime you are in.
One foundation, staggered waves. Led by audit experts, accelerated by highly specialized AI tooling. Nothing ships just because a model says so.
Self-Check
Free, instant. See which obligations apply and roughly where you stand. Orientation, not evidence.
Scanner + Analysis
Our experts review your real artifacts, accelerated by specialized AI tooling. Nothing ships just because the model says so.
Actionable Report
A prioritized, ranked gap list in the format the next step expects.
Remediation + Handover
We help close the gaps. Where the law names an examiner, we walk you to the gate. Where you sign your own declaration, we arm you so it holds up under supervision.
WE CLEAR THE PATH · WE READY YOU · WE HAND OVER
Four paths are open. More are being cut.
Every scanner rides the same readiness engine. Same method, same discipline, different regime.
awedit C5
BSI C5 readiness for cloud and health SaaS. The gate is the C5 Testat by a Wirtschaftsprüfer. Everything up to it is ours.
Open C5awedit BFSG
Accessibility readiness under the BFSG / European Accessibility Act, live since 28.06.2025. No reserved examiner: you sign your own declaration and face market surveillance.
Open BFSGawedit NIS2
Cybersecurity duties under NIS2, German law since 06.12.2025. Roughly 29,500 entities in scope. No reserved examiner today: you self-declare and must survive BSI supervision.
Open NIS2awedit KRITIS
Readiness for operators of critical facilities: one threshold, two laws. The gate is the §39 evidence by the examining body, every three years. We prepare and escort to the handover.
Open KRITISSoftware as a Medical Device, notified-body gate.
High-risk healthcare subset, phased obligations through 2026-2027.
One base, sequenced waves. awedit is not a C5 company. It is regulated readiness as a repeatable machine.
One scan, five check areas. Free.
We fetch your public pages and show what they hand out today.
The portal is coming.
Your whole readiness, in one sovereign room.
The regimes do not arrive one at a time. Neither do we treat them that way.
A large hospital today carries C5 (§393 SGB V), NIS2 as a besonders wichtige Einrichtung, §31 attack detection, the §39 evidence, and the physical duties of the KRITIS umbrella act. All at once. One scanner foundation means one provider, one evidence base, and each audit uses the work of the last.
- Same evidence, used more than once: what your C5 scan collects feeds your NIS2 file.
- One contact across all lanes, instead of four consultancies with four truths.
- Where examiner paths overlap (ISO/DAkkS, WP), we design the handover so you do not have to explain twice.
One provider. Two signatures. Neither of them ours.
We are experts in IT certification and regulated audits, supercharged with highly specialized AI tooling. For you that means expert quality in weeks instead of quarters, and every finding in your report passed a human who puts their name on it.
- You know in minutes which duties actually apply. Not after weeks of pre-study.
- You get findings with a name behind them, not raw machine output to interpret on your own.
- Your report gets adopted by the next step instead of rewritten. The most expensive second run disappears.
- You go to the examiner when you are ready. Not to find out whether you are.
- Call a result “certified”, “compliant” or “audit-proof”. No tool earns you the certificate, the attestation or the declaration.
- Claim a tool alone reaches readiness or compliance.
- Sign it off for you. Where the law names an examiner, that act is theirs. Where you self-declare, the signature stays yours.
The name gives it away: there is a we inside awedit. The audit you already spotted.
One entry point, four steps up.
The ladder mirrors the model. Every rung buys you something concrete; start where you stand.
Free, instant. Buys you clarity: which duties apply, how urgent, where the first gaps are.
Buys you the map: an expert-reviewed scan of your real product, a prioritized report the next step adopts as-is.
Buys you the shortest path: we close the gaps with you until handover or signature holds.
Buys you steadiness: readiness is not a state, it is a rhythm. Catalogs move (C5:2026, new KritisV), evidence recurs (§39 every three years). We keep you audit-ready while the law keeps moving.
Find your path in three minutes.
The Self-Check is free and instant. It tells you which obligations apply to your product and where the first gaps are. Orientation, not evidence.
Orientation, not evidence.
We clear the path.
We ready you.
We hand over.