An audit alone answers this
- Whether you comply or not.
- What you're missing.
- What risks you have.
- What you should fix.
From diagnosis to full ISMS implementation: risk analysis, documentation, controls, evidence and basic development included, with support all the way to the audit. More than 20 years designing and implementing security and control systems.
An audit tells you where you stand. If you stop there, you have a report full of gaps and you still have to fix them. Here the work doesn't end with the diagnosis: I help you implement the ISMS, prepare the documentation, get the controls running, create evidence and adjust systems when needed, so you enter ENS or ISO 27001 with a real foundation that fits your organization.
I run data protection, the ISMS and the audits for healthcare companies, and that has been key for them to start working with the public sector. More than 20 years designing and deploying security and control systems, with a single point of contact bringing together security, GDPR and AI Act, so you never have to deal with three different providers.
Processes, assets and dependencies, plus categorization of the systems under Anexo I of the ENS to set the real level.
A comparison against ENS or ISO 27001 to pinpoint the real gaps, with nothing inflated.
Risks, statement of applicability, policies, procedures, controls and evidence, with the necessary basic development included.
A check that everything works and leaves a trail, with the internal audit the standard requires.
Preparation and support up to the external audit or certification, plus maintenance to keep the ISMS alive.
VAT not included
Initial diagnosis
Timeframe of 1 to 2 weeks. Credited against the implementation if you go ahead.
To be truly ready
Payment in monthly installments throughout the project.
To keep it alive
Includes an official DPD if you don't have one.
Both. The audit tells you whether you comply, but the usual approach is to hire the full ISMS implementation: documentation, controls, evidence and basic development so that you truly comply and can pass the external audit or certification.
The gap analysis ranges from €900 per standard to €1,200 for the combined option. The full implementation ranges from €3,800 to €5,800 for ENS, from €4,800 to €6,800 for ISO 27001 and from €7,200 to €9,500 for the combined option, all plus VAT and payable in monthly instalments. The final figure is set after the diagnosis. If you then hire the implementation, the gap fee is credited against its price.
The gap takes one to two weeks. A single standard usually runs between three and five months, and the combined ISO and ENS option between four and seven months, depending on which controls need changes and your availability.
Not always. For ENS Basic, self-assessment is usually enough, and some clients have started working with the public sector on the basis of audits carried out by an official Data Protection Officer. The formal seal is only required for ENS Medium or High and for the ISO 27001 certificate, and it is issued by an accredited body, usually from €1,500 to €4,000.
The basic systems or software development needed for the implementation is included: adjustments, automations and small integrations to get the controls working. Hardware and complex systems are excluded and are reviewed before starting.
Yes. The implementation cost can be spread over monthly instalments throughout the whole period, so you do not have to take on the expense all at once.
For many companies the sensible level is ENS Medium, but the actual level comes from categorising the systems according to Anexo I of the ENS. We confirm it during the gap, without inflating the level.
If you do not yet have a Data Protection Officer, the maintenance includes me acting as your official DPD, with the appointment notified to the Spanish Data Protection Agency.
Tell me your starting point and I will prepare a fixed proposal with scope, level and price. The first assessment is free.