Information security

ENS and ISO 27001: I don't just audit you, I implement the whole ISMS and get you compliant.

From diagnosis to full ISMS implementation: risk analysis, documentation, controls, evidence and basic development included, with support all the way to the audit. More than 20 years designing and implementing security and control systems.

Audit versus implementation

It's not just an audit. It's getting you ready to comply.

An audit tells you where you stand. If you stop there, you have a report full of gaps and you still have to fix them. Here the work doesn't end with the diagnosis: I help you implement the ISMS, prepare the documentation, get the controls running, create evidence and adjust systems when needed, so you enter ENS or ISO 27001 with a real foundation that fits your organization.

An audit alone answers this

  • Whether you comply or not.
  • What you're missing.
  • What risks you have.
  • What you should fix.

Full implementation solves this

  • Documentation ready.
  • Controls up and running.
  • Evidence ready to go.
  • Internal audit included.
  • Basic development included when needed.
  • Support all the way to the external audit or certification.
Who it is for

Built for those who want to enter the public sector or meet the demands of exacting clients.

Target organizations

  • Companies that want to work with public administration or in regulated environments.
  • Healthcare, finance or technology companies that handle sensitive data.
  • Businesses already being asked for ENS or ISO 27001 by a client or a tender.

What you get

  • Real compliance, not just a report.
  • Documentation and evidence an auditor can review.
  • A defensible foundation for winning tenders and contracts.
  • A single point of contact for security, GDPR and AI Act.
Why me

The same path I have already walked with healthcare companies.

I run data protection, the ISMS and the audits for healthcare companies, and that has been key for them to start working with the public sector. More than 20 years designing and deploying security and control systems, with a single point of contact bringing together security, GDPR and AI Act, so you never have to deal with three different providers.

Methodology

From diagnosis to a working setup, step by step.

1Scope and categorization

Processes, assets and dependencies, plus categorization of the systems under Anexo I of the ENS to set the real level.

2Gap analysis

A comparison against ENS or ISO 27001 to pinpoint the real gaps, with nothing inflated.

3ISMS deployment

Risks, statement of applicability, policies, procedures, controls and evidence, with the necessary basic development included.

4Internal audit and evidence

A check that everything works and leaves a trail, with the internal audit the standard requires.

5Support all the way to the end

Preparation and support up to the external audit or certification, plus maintenance to keep the ISMS alive.

Deliverables

Documentation and controls you can use, decide on and audit.

From the implemented ISMS

  • Risk analysis and statement of applicability (SoA).
  • Policies, procedures and evidence log.
  • Treatment plan and controls up and running.

For management and audit

  • Executive report with risks and priorities.
  • Internal audit and improvement map.
  • A solid base ready for the external audit or certification.
Indicative prices

ENS / ISO 27001 rates: from diagnosis to implementation

VAT not included

Gap analysis

Initial diagnosis

  • ISO 27001€900
  • ENS€900
  • ISO + ENS€1,200

Timeframe of 1 to 2 weeks. Credited against the implementation if you go ahead.

  • Clear categorization and priorities.
  • Evidence checklist.
  • Roadmap to close the gaps.
Request a gap analysis

Annual maintenance

To keep it alive

  • ISO 27001€150 - €450/month
  • ENS€150 - €450/month
  • ISO + ENS€250 - €750/month

Includes an official DPD if you don't have one.

  • Plan tracking and evidence review.
  • Support when things change.
  • Preparation for surveillance audits.
Request maintenance

Before you start, this is worth knowing

  • The gap analysis fee is credited against the implementation price if you decide to go ahead.
  • The seal from an accredited body costs €1,500 to €4,000 depending on scope, and you only pay for it if you need it.
  • You don't always need a seal to get started. For ENS Basic, self-assessment is usually enough, and the formal seal is only required for ENS Medium or High or for the ISO 27001 certificate.
  • Any basic systems or software development needed for the implementation is included.
  • Hardware and complex systems are out of scope and we review them together before starting.
  • Typical timelines: gap analysis 1 to 2 weeks, a single standard 3 to 5 months, and the combined option 4 to 7 months.
Frequently asked questions

Frequently asked questions

Do you only do the audit or the implementation as well?

Both. The audit tells you whether you comply, but the usual approach is to hire the full ISMS implementation: documentation, controls, evidence and basic development so that you truly comply and can pass the external audit or certification.

How much does it cost to implement ENS or ISO 27001?

The gap analysis ranges from €900 per standard to €1,200 for the combined option. The full implementation ranges from €3,800 to €5,800 for ENS, from €4,800 to €6,800 for ISO 27001 and from €7,200 to €9,500 for the combined option, all plus VAT and payable in monthly instalments. The final figure is set after the diagnosis. If you then hire the implementation, the gap fee is credited against its price.

How long does an ENS or ISO 27001 implementation take?

The gap takes one to two weeks. A single standard usually runs between three and five months, and the combined ISO and ENS option between four and seven months, depending on which controls need changes and your availability.

Do I need the seal of a certification body to win public sector contracts?

Not always. For ENS Basic, self-assessment is usually enough, and some clients have started working with the public sector on the basis of audits carried out by an official Data Protection Officer. The formal seal is only required for ENS Medium or High and for the ISO 27001 certificate, and it is issued by an accredited body, usually from €1,500 to €4,000.

Is the technical development included?

The basic systems or software development needed for the implementation is included: adjustments, automations and small integrations to get the controls working. Hardware and complex systems are excluded and are reviewed before starting.

Can I pay for the implementation in instalments?

Yes. The implementation cost can be spread over monthly instalments throughout the whole period, so you do not have to take on the expense all at once.

Which ENS level applies to me?

For many companies the sensible level is ENS Medium, but the actual level comes from categorising the systems according to Anexo I of the ENS. We confirm it during the gap, without inflating the level.

Does the maintenance include the Data Protection Officer?

If you do not yet have a Data Protection Officer, the maintenance includes me acting as your official DPD, with the appointment notified to the Spanish Data Protection Agency.

Direct contact

If you want to get into ENS or ISO 27001, I leave it implemented and up and running for you.

Tell me your starting point and I will prepare a fixed proposal with scope, level and price. The first assessment is free.

WhatsApp