We take you by the hand through the entire ISO 27001 or ENS certification process: diagnosis, plan, control implementation and external audit support. You can be certified in 6 months.
Choose the certification that matches the customer you target. If you work with public administrations, ENS is mandatory; for the private market or international expansion, ISO 27001 is the de facto standard.
International information security management standard. Essential to scale globally or work with large corporations.
Mandatory for technology vendors of the Spanish public sector. Three categories: Basic, Medium and High based on data criticality.
Too many consultancies leave you halfway through with a stack of documents. We commit to the result: the certification.
If you do not pass the external audit, we refund part of the fees. It has never happened, but the commitment matters.
Short, clear and applicable policies and procedures. Not "200-page manuals nobody reads".
Average 6 months for ISO 27001 from scratch, 4 months for ENS Medium. Plan with weekly milestones.
Auditors with CISA, ISO 27001 LA, CISSP, ENS. Not textbook theory — real experience across dozens of programmes.
Your certification lasts 3 years with annual audits. We help you keep it alive without extra effort.
Fixed quote, no surprises. We tell you exactly what it costs before starting and that is what you pay.
Phases completed, controls deployed, open findings and days to external audit. No surprises, no "we are almost there".
Diagnosis of your current situation against the standard's controls. We identify what you have, what is missing and the effort to close the gap.
Detailed roadmap with owners, deadlines, deliverables and follow-up meetings. Approved with management before kicking off.
Drafting of policies, procedures, technical instructions and records. Tailored to your operational reality, not internet copy-paste.
Technical and organisational rollout of required controls. We coordinate IT, HR and vendors. We generate the necessary evidence.
We simulate the external audit. We identify nonconformities and close them before they cost you.
We support you throughout the audit with the certifying body (Aenor, BSI, Bureau Veritas, etc.). Resolve on the spot and earn the certificate.
Let's talk about real timelines and see if we can make it. We have certified clients in less than 4 months when needed.
There are two costs: our fees (consulting) and the external certifying body fees. For a 50-employee SME, all-in (ISO 27001), it is usually around €12,000-22,000 in year one. We give you a fixed quote after the initial diagnosis.
On average 6 months for ISO 27001 from scratch, 4 months for ENS Medium. If you have some maturity in place, we can move faster.
No. We start from wherever you are. If you have something we use it; if not, we build it together. No judgement.
An accredited certifying body (independent from us). We recommend the ones that best fit your size and sector, but the choice is yours.
Yes. The certification lasts 3 years with annual surveillance audits (lighter ones). We offer an annual maintenance service to make renewal a formality.