Consulting · ISO/IEC 27001:2022
Implementation and certification ISO 27001
We design your information security management system, put it into practice and support you all the way to certification.
The standard
What ISO 27001 is and when you need it
ISO/IEC 27001 is the international standard that defines how an organization should manage information security. It doesn't require any specific technology: it requires a management system (ISMS) that identifies your risks, applies proportionate measures and proves that they work.
Certification is issued by an independent, accredited body after auditing you. It is how you prove to clients, partners and public authorities that you protect the information they entrust to you.
It is not legally required, but more and more contracts and tenders demand it. If you work for the Spanish public sector, what they will ask for is the ENS.
Do you need it?
Tick everything that applies to your organization.
One foundation for several standards
What you implement for ISO 27001 also works for the rest
It shares many of the same security measures. Mandatory if you work with the Spanish Public Administration.
ENS certification → NIS2The risk management measures required by the directive fit an ISMS that is already in place.
NIS2 compliance → DORAThe ICT risk management framework for the financial sector follows the same logic of risks and controls.
DORA compliance → ISO 9001Same high-level structure: you can have a single integrated quality and security system.
ISO 9001 certification →Frequently asked questions
What people ask us before getting started
No. It is issued by an accredited, independent certification body. Whoever helps you implement the standard cannot certify you, precisely to guarantee impartiality. We prepare you and support you throughout the audit.
It is not legally required, but many clients and tenders demand it. If you supply the public sector in Spain, the mandatory standard is the National Security Framework (ENS).
No. The transition period to the 2022 version ended on October 31, 2025, and certificates based on the 2013 version are no longer valid. If you haven't migrated yet, you should do so as soon as possible.
The certificate is valid for three years. During that time there is an annual surveillance audit, and in the third year a recertification audit.
Yes. The scope is defined at the start and can be limited to a service, a department or a site, as long as it is clearly defined.
Shall we talk about your certification?
Tell us where you stand and we'll explain how to get certified.
