Information security

ENS and ISO 27001 audits for organisations that need rigour, evidence and a clear roadmap.

Diagnosis, internal audit and compliance plan in language management can understand, with enough depth for technical leads and auditors.

Who it is for

Especially useful when security and compliance can no longer be handled informally.

Target organisations

  • Companies that work with public administrations or in regulated environments.
  • Companies that need to set up or maintain an ISMS.
  • Businesses that need a real picture of their risk to decide on investments.

What the audit delivers

  • Clear priorities for management.
  • Actionable findings for technical teams.
  • Better order in documentation and evidence.
  • A solid basis for compliance or certification.
Methodology

Diagnosis, fieldwork and compliance plan.

1Scope and context

Processes, assets, dependencies, requirements and business objective.

2Gap analysis

Comparison against ENS or ISO 27001 to pinpoint the real gaps.

3Fieldwork

Documentation review, interviews and technical validation of controls.

4Report and wrap-up

Clear deliverables, treatment plan and a final presentation session.

Deliverables

Documentation you can use to decide and act.

For management

  • Executive report with risks and priorities.
  • Summary of non-conformities and relevant gaps.
  • Action plan organised by impact and effort.

For the technical team

  • Findings broken down by control or measure.
  • Evidence and documentation still to be completed.
  • Map of technical and operational improvements.
Indicative plans

ENS / ISO 27001 pricing

VAT not included

Gap Analysis & Roadmap

€600 - €1,200one-off payment

  • Initial assessment and priorities.
  • Evidence checklist.
  • Initial strategic guidance.
Request a Gap Analysis

Annual support

€450/month12 months

  • Follow-up on the compliance plan.
  • Support on evidence and controls.
  • Ongoing readiness for external audits.
Request support
Frequently asked questions

Frequently asked questions

What is the difference between ENS and ISO 27001?

ENS is the Spanish framework applicable to the public sector and providers; ISO 27001 is a certifiable management system standard. They are often worked on in a complementary manner.

What deliverables does the company receive?

Executive report, findings, risk matrix, treatment plan and documentation useful for alignment or internal audit.

Can you support the follow-up phase?

Yes. Besides the audit, you can engage support for implementation, gap closure and evidence preparation.

Direct contact

If you need to prepare for ENS or ISO 27001 with order and good judgement, we can work on it together.

Tell me your organisation's starting point and I'll put together a proposal tailored to the project's maturity level, scope and demands.