Strategic Cybersecurity Governance Advisor and virtual CISO based in Hamburg, Germany, working at the intersection of EU regulatory compliance and connected-product security.
Axel Hoehnke is a Strategic Cybersecurity Governance Advisor and virtual CISO based in Hamburg, Germany, working at the intersection of EU regulatory compliance and connected-product security. Through Axel Hoehnke Consulting, he helps manufacturers, IoT vendors, healthcare organizations, and digital service providers turn EU frameworks — the Cyber Resilience Act (Regulation (EU) 2024/2847), NIS2, ISO/IEC 27001, and ISO/IEC 42001 — into compliance programs that are right-sized for the actual risk, not generic checklists built for the largest possible audit.
His practice has particular depth in healthcare IoT and wearable medical devices, where the CRA's security-by-design, vulnerability-handling, and minimum-support-period obligations intersect with MDR, GDPR, and ISO 13485. To bring patient-safety impact into that work directly, he developed STRIDE-H, a healthcare-specific extension of STRIDE threat modeling that folds patient-safety consequences into vulnerability scoring and coordinated-disclosure design.
Axel's methodology is deliberately evolutionary rather than parallel: where a client already has an ISO 27001 ISMS in place, he builds CRA product-security requirements onto that foundation instead of standing up a second compliance system alongside it — a distinction that matters most for SMEs navigating CE marking under the Regulation with limited compliance headcount. Engagements follow a five-step method — Interpret, Collect Evidence, Measure Reality, Validate Insights, Communicate Clearly — that treats regulatory text as something to be translated into organization-specific requirements and tested against actual evidence, not assumed.
He also participates directly in the standardization work behind the CRA, contributing through the DIN mirror committee NA 043-04-13 GA, which feeds into CEN/CLC/JTC 13/WG 9. His personal focus within the EN 40000-1-X series — the horizontal CRA product-security standard, currently still in draft — is Part 1-3, Vulnerability Handling, with particular attention to its interface with medical-device security.
Credentials: BSI Trusted Expert, ISO/IEC 42001 Lead Auditor, ISO/IEC 27001 Lead Auditor, Vanta MSP Partner.
Evidence-based methodology — scoped before it starts, finished when it's done.
A rapid-deployment programme for SMEs — foundation-level compliance from day one.
Two live engagements — one Stage 2 certification sprint, one internal audit. Real findings, real outcomes.
Verified expertise in global and EU regulatory frameworks.
Fixed-scope engagements with clear deliverables and transparent pricing. No retainer required to start.
Build Your Proposal