Why this exists

The problem Atlas Wireless solves

Without Atlas Wireless

The office Wi-Fi uses WPA2-PSK with a shared password written on the wall. Guest and corporate devices share the same SSID. The BYOD laptop with adware is on the same network as the finance server. A rogue AP installed by an employee has been bridging traffic to a mobile hotspot for 6 months — nobody noticed.

With Atlas Wireless

WPA3-Enterprise with EAP-TLS means every user authenticates with a certificate — the shared PSK is gone. Corporate, IoT, and Guest SSIDs are separate VLANs with firewall rules. The MikroTik CAPsMAN controller manages every AP from one plane — switches and APs stay on a single vendor with no cloud-account dependency. RouterOS native WIDS watches for rogue APs and triggers an alert to Atlas Observe within minutes. Every connected device is visible centrally, and firmware is pushed from the controller.

Architecture

How it works

Atlas Wireless — MikroTik CAPsMAN controller managing APs with VLAN-per-SSID segmentation
Architecture overview — Atlas Wireless component relationships

Regulatory compliance

What Atlas Wireless satisfies

Regulation / ControlRequirementAudit evidence
NIS2 Art. 21(2)(d)VLAN-per-SSID prevents guest and IoT from accessing corporate resourcesCAPsMAN SSID to VLAN mapping export · inter-VLAN firewall log
BSI WLAN.1WPA3-Enterprise with EAP-TLS, WIDS rogue AP detection, centralised managementRouterOS WIDS log · WPA3 policy config export · SSID audit
BSI INF.1.2All APs managed, authorised, and monitored — no rogue devicesCAPsMAN AP inventory · provisioning log · firmware version report
GDPR Art. 32(1)(d)WIDS provides ongoing wireless security assessmentRouterOS WIDS alert history · rogue AP detection log
NIS2 Art. 21(2)(i)WPA3-Enterprise with 802.1X ensures only authenticated users access Wi-FiFreeRADIUS accounting log · EAP-TLS certificate audit
DORA Art. 9(4)(b)Multiple APs provide wireless HA with no single point of failureCAPsMAN uptime report · AP failover test log

Standalone installation

Install one component — no full integration required

Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.

CAPsMAN controller — standalone deploy

MikroTik CAPsMAN controller on RouterOS / CHR. Provision up to 10 MikroTik cAP ax / hAP ax³ APs. Corporate SSID (WPA3) + guest SSID. VLAN-per-SSID. RouterOS native WIDS enabled. Centralised firmware updates.

  • CAPsMAN controller (RouterOS / CHR)
  • Provision up to 10 cAP ax / hAP ax³ APs
  • Corporate + guest SSID
  • VLAN-per-SSID config
  • WIDS rogue AP detection
  • 5-day post-install support

€ 890

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

Guest Wi-Fi + captive portal

Isolated guest SSID on VLAN 30. MikroTik hotspot portal with custom branding. GDPR-compliant usage notice with consent. Bandwidth limits per device. Internet only — no internal resources.

  • Isolated guest VLAN 30
  • MikroTik hotspot portal
  • Custom branding
  • GDPR consent + logging
  • Bandwidth limits
  • 5-day post-install support

€ 590

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

Wi-Fi site survey

On-site RF survey up to 500m² (single floor). Signal heatmap. Dead zone identification. AP placement recommendation. Channel plan. Expected throughput estimates.

  • RF survey up to 500m²
  • Signal heatmap
  • Dead zone identification
  • AP placement plan
  • Channel plan
  • Expected throughput estimates

€ 790

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote
Note: Standalone components do not include cross-product integration. Full Atlas Wireless integration — connecting it into your existing environment — starts with an audit engagement.

Full integration

Foundation · Plus · Enterprise

Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.

Foundation

5–50 users · 1 site · 1 month on-site

1 month on-site

from € 9,600

Net, excl. VAT · fixed price scoped by audit

  • CAPsMAN controller (RouterOS)
  • WPA3 corporate SSID
  • Guest SSID + captive portal
  • VLAN-per-SSID
  • WIDS rogue AP detection
  • Up to 10 cAP ax / hAP ax³ APs
Request audit to start
Enterprise

500+ users · multi-site · 6 months on-site

6 months on-site

from € 54,000

Net, excl. VAT · fixed price scoped by audit

  • Redundant CAPsMAN controllers
  • Full WIDS + rogue containment
  • BYOD onboarding portal
  • SIEM alert integration
  • Location analytics optional
  • ISO 27001 wireless evidence
Request audit to start

Start with an audit

All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.

Request audit engagement