Audit and regulatory readiness
I audit the way certification bodies do, because I work with them as a lead auditor. Whether you need a gap analysis before certification, an internal audit before the certification visit, a NIS2 or DORA assessment, or documentation for the regulator — you get a report that holds up.
What you get
- ISO/IEC 27001 and ISO 22301: gap analysis, internal audit, statement of applicability, risk-treatment and continuity plans ready for the certification body
- NIS2 / Cybersecurity Act: assessment of organisational and technical measures, register of obligations and a plan to meet them
- DORA: ICT risk-management assessment, register of information, incident reporting and third-party arrangements mapped to the regulation
- Preparation of the documentation the regulation requires: policies, procedures, risk and obligation registers, continuity plans — ready for approval, not templates to fill in
- Prioritised list of findings with severity, evidence and a concrete remediation
- Executive summary for the board, customers and insurers — optionally loaded into Qzila
When to get in touch
- You are going for ISO/IEC 27001 or ISO 22301 certification, or recertification is coming up
- NIS2 applies to you and you need to know exactly what is missing and in what order to fix it
- You are a financial entity and DORA asks for ICT risk management, testing and vendor oversight that hold up
- A customer, partner or insurer wants an independent assessment of your security
How it works
- 01
Scoping
Standard or regulation, systems, audit boundary, certification or submission deadline
Duration: 1 h - 02
Audit
Document review, interviews, configuration checks and evidence that controls operate
Duration: 5–12 d - 03
Report & plan
Findings, gaps and a prioritised plan — walked through with your team
Duration: 2 d - 04
Certification support
Remediation verified; present at the certification audit or the regulator meeting
Duration: as needed
Other services
All services →AWS audit
A review of your AWS environment against the AWS Well-Architected Framework and security benchmarks: identity and access, network, encryption, logging, backups, resilience and cost — with a prioritised remediation plan.
Read more →Risk assessment
Information-security risk analysis, business-impact analysis (BIA) and vendor risk assessment under ISO/IEC 27005 and the requirements of NIS2 and DORA — with a register you can actually maintain.
Read more →Technical due diligence
An independent assessment of the technology, security, operations and team of a company you are buying, funding or depending on — in days, with a report for the investment committee.
Read more →Thirty minutes that save you months
Tell me what you are dealing with — an audit before certification, a letter from the regulator, a customer requirement, or just not knowing where you stand. Within two working days you get a concrete proposal with scope and price.
- You talk directly to the auditor who does the work
- Fixed scope and price before anything starts
- NDA on request, deliverables in Czech or English