Twelve Weeks to DAkkS-Accredited ISO 27001 Certification: How CIRCUS SE Met Its Deadline with SECJUR

About the company

‍

Circus SE (XETRA: CA1) is a publicly listed technology company headquartered in Munich that develops autonomous AI robotics for food supply. Its business model rests on two pillars: the patented CA-1 robot, which handles the entire production process from raw ingredient to serving, and its proprietary operating system CircusOS, which controls, monitors and optimizes that process. Founded by Nikolas Bullwinkel, the company now manufactures the CA-1 in series production and supplies customers in institutional catering as well as the defence sector.

Through Circus Defence, the company operates a dedicated business unit for autonomous supply systems for armed forces and government agencies. Circus SE has been officially approved as a supplier to US government agencies and the US Armed Forces, allowing it to take part in public procurement processes in the United States. In Europe, the company received an order from the Bundeswehr (German Armed Forces) in early 2026 and won the public tender for autonomous food supply for the Lithuanian Armed Forces on NATO's eastern flank. It also holds a framework agreement with the Ukrainian defence technology platform BRAVE1.

This places Circus SE in an environment where customers, public contracting authorities and the capital market prioritize security and the ability to prove it. It was precisely this combination (a publicly listed deep-tech company with dual-use technology and international procurement processes) that made certified information security a prerequisite for the next step.

‍

The Challenge

‍

Circus SE was working against a tight deadline: within twelve weeks, the company needed an information security management system certified to ISO 27001, with the certification issued by a DAkkS-accredited certification body. The accreditation was far more than a formality. In tenders and supplier assessments, the question is not only whether a certificate exists, but also who issued it. As Germany's national accreditation body, DAkkS oversees the certification bodies themselves, ensuring that every certificate is backed by a comparably rigorous audit standard. For procurement departments and public contracting authorities, this is exactly what allows them to trust the evidence presented.

On a technical level, the company already had a solid foundation. Any organization that manufactures networked systems in series and runs its own operating system necessarily relies on established security practices throughout development and operations. What still needed to be added was the formal structure on top. A certifiable ISMS requires a clearly defined scope, a documented and traceable risk assessment, a complete set of policies, a Statement of Applicability, and verifiable evidence of training and of the effectiveness of the measures in place. This documentation layer forms the basis of the audit and cannot be recreated at short notice, because it presupposes a process that has actually been implemented over a period of time.

One obvious option would have been to hire an in-house information security specialist. On closer examination, however, the company's decision-makers ruled this out: finding, negotiating with, hiring and onboarding a suitable candidate would have used up the entire twelve-week window on recruiting alone, before a single policy had been written. On top of that came the ongoing personnel costs for a role whose workload drops significantly after certification. Traditional consulting would have brought the expertise, but the implementation work would have remained entirely with the internal team, at a time when the internal team was responsible for series production, international expansion and building up the defence business.

Circus SE therefore looked for a solution that would lead the company to a certifiable ISMS, guide the in-house implementation with the same professional rigor as an external consultancy, and also support the subsequent surveillance audits and later recertification.

"SECJUR takes the heavy lifting in information security off our hands. We had only a few weeks until the certification audit and no one in the company to build an ISMS. Thanks to SECJUR, we still haven't had to fill a dedicated position, and we passed the audit without any issues."
Jan Sorgenfrei
Jan Sorgenfrei, Vice President of Engineering, Circus SE

The Solution

‍

Circus SE opted for SECJUR's Expert-Managed model. Under this model, a dedicated SECJUR expert took responsibility for building the management system: together with the company, the expert defined the scope, identified the assets, carried out the risk assessment, drafted the set of policies and the Statement of Applicability, and derived the risk treatment plan from them.

Implementing the technical and organizational measures set out in the plan was Circus SE's responsibility, since it directly affects the company's systems, processes and ways of working and can neither be owned nor replaced from the outside. The professional guidance, however, was provided by SECJUR: guiding which measures to implement, in what order and to what depth, what evidence is required, and whether the result meets the requirements of the standard. For Circus SE, this removed the part that consumes the most time without relevant experience: working out what exactly needs to be done and when it is good enough.

This model is made possible by the Digital Compliance Office, SECJUR's platform. In this project, it did not serve as a tool for the customer to work through on their own, but as the expert's working foundation. Requirements, policies, evidence, tasks and deadlines are all in one place and can be evaluated against the certification status at any time. This structure makes it possible to provide support at this depth at software pricing rather than the day rates of traditional consulting.

For Circus SE, this meant an effort of around 0.3 full-time equivalents (FTE) per week. Their contribution consisted mainly of interview sessions, approvals, implementing the assigned measures, and supplying evidence from IT and the relevant departments. In preparation for the certification audit, SECJUR conducted the internal audit, prepared the management review for the executive board, worked through the resulting findings together with the company, and supported both Stage 1 and Stage 2.

Management and the project team therefore went into the certification audit on a verified foundation. The internal audit had already confirmed the effectiveness of the documentation, open issues had been resolved in advance, and the outcome of the audit was correspondingly predictable.

‍Circus SE passed the certification audit and received its ISO 27001 certificate from a DAkkS-accredited certification body within the twelve-week deadline.

‍

The Impact

‍

The immediate effect was the ability to act in the market. With an accredited certificate, Circus SE can compete in procurement processes where this evidence is a formal entry requirement, both in the civilian business with corporate and infrastructure customers and in the defence sector. Evidence delivered twelve weeks later would have meant exclusion from certain tenders.

Economically, the advantage over building the function in-house came down to three points. Circus SE achieved certification without an additional full-time position, without a recruiting cycle and without an onboarding phase. For a publicly listed company, budget certainty also matters: the scope was fixed before the project began.

Just as important as the ISO 27001 certification itself is the ongoing operation that follows. An ISMS requires continuous maintenance, and experience shows that the greater effort lies not in the initial certification but in demonstrating effectiveness during the surveillance audit.

SECJUR continues to support exactly this maintenance. As a result, Circus SE does not handle audit findings as a separate internal project. The SECJUR expert assesses each finding, derives the necessary corrective action and root cause analysis, supports its implementation within the company, and documents the outcome in the Digital Compliance Office. Circus SE decides and implements; professional guidance and deadline tracking remain with SECJUR.

The same division of labour applies to the surveillance audits and recertification. Because policies, evidence, training records and risk assessments are kept up to date on an ongoing basis, the certification status is not a snapshot that has to be reconstructed every three years. Preparation for the next audit builds on the current state. The knowledge built up remains documented in the system and available independently of any individual.

Because the ISMS is designed to be modular, additional compliance frameworks such as NIS2, TISAX® or ISO 27017 can also be built on the existing foundation instead of setting up parallel structures. For a company that delivers AI systems into regulated and security-critical environments, this is a highly relevant competitive advantage.

Circus SE has therefore not only certified its information security but given it a lasting structure. Responsibility for the ISMS remains within the company, while the time-consuming professional guidance and the ongoing upkeep of the documentation lie with SECJUR.