Audits and regulatory readiness that hold up in front of the certification body.
ISO/IEC 27001, NIS2 and DORA audits, preparation of the policies, procedures and registers the regulation requires, risk assessments, AWS audits and technical due diligence. Led by an auditor who has also been building and running the kind of systems he audits since 2004.
- ISO/IEC 27001
- ISO 22301
- ISO 9001
- NIS2
- DORA
- GDPR
- OWASP
- AWS Well-Architected
From gap analysis to signed-off documentation
Fixed scope and price: the audit, a remediation plan, documentation ready for approval and a follow-up audit. In Czech or English, to certification-body standards.
Audit and regulatory readiness
Gap analysis, internal audit and certification readiness for ISO/IEC 27001 and ISO 22301, audits under NIS2 and the Czech Cybersecurity Act, DORA compliance assessment — including preparation of the documentation the regulation requires.
Read more →AWS audit
A review of your AWS environment against the AWS Well-Architected Framework and security benchmarks: identity and access, network, encryption, logging, backups, resilience and cost — with a prioritised remediation plan.
Read more →Risk assessment
Information-security risk analysis, business-impact analysis (BIA) and vendor risk assessment under ISO/IEC 27005 and the requirements of NIS2 and DORA — with a register you can actually maintain.
Read more →Technical due diligence
An independent assessment of the technology, security, operations and team of a company you are buying, funding or depending on — in days, with a report for the investment committee.
Read more →The Asign platform and Qzila tools: compliance as a process, not a one-off report
Asign is the GRC platform for managing cybersecurity and compliance with NIS2, DORA and ISO 27001; qzila is a home for compliance, security and productivity tools that watch what changes every day — email security, TLS, DNS, uptime, lookalike domains, data breaches or link safety. ZOOM CREW sells them on the Czech market, implements them and fills them with the results of its own audits.
Why a small expert team rather than a big firm
An auditor, not a salesperson
Every engagement is led by the auditor who does the work: scoping, testing, the report and its defence in front of the certification body or regulator.
Twenty years on both sides
Since 2004 I have run a software and security company with engineers in three countries. I know what systems look like from the inside, not just from a questionnaire.
Certification-body standards
I run ISO/IEC 27001, 9001 and 22301 audits in cooperation with TÜV SÜD and write findings the way a certification body expects them.
Technology and law under one roof
Security audit and GDPR are handled together: an auditor and a lawyer acting as data protection officer, so technical measures and documentation hold together.
Thirty minutes that save you months
Tell me what you are dealing with — an audit before certification, a letter from the regulator, a customer requirement, or just not knowing where you stand. Within two working days you get a concrete proposal with scope and price.
- You talk directly to the auditor who does the work
- Fixed scope and price before anything starts
- NDA on request, deliverables in Czech or English