ISO/IEC 27001 · NIS2 · DORA · ISO 22301

Audit and regulatory readiness

I audit the way certification bodies do, because I work with them as a lead auditor. Whether you need a gap analysis before certification, an internal audit before the certification visit, a NIS2 or DORA assessment, or documentation for the regulator — you get a report that holds up.

What you get

  • ISO/IEC 27001 and ISO 22301: gap analysis, internal audit, statement of applicability, risk-treatment and continuity plans ready for the certification body
  • NIS2 / Cybersecurity Act: assessment of organisational and technical measures, register of obligations and a plan to meet them
  • DORA: ICT risk-management assessment, register of information, incident reporting and third-party arrangements mapped to the regulation
  • Preparation of the documentation the regulation requires: policies, procedures, risk and obligation registers, continuity plans — ready for approval, not templates to fill in
  • Prioritised list of findings with severity, evidence and a concrete remediation
  • Executive summary for the board, customers and insurers — optionally loaded into Qzila

When to get in touch

  • You are going for ISO/IEC 27001 or ISO 22301 certification, or recertification is coming up
  • NIS2 applies to you and you need to know exactly what is missing and in what order to fix it
  • You are a financial entity and DORA asks for ICT risk management, testing and vendor oversight that hold up
  • A customer, partner or insurer wants an independent assessment of your security

How it works

  1. 01

    Scoping

    Standard or regulation, systems, audit boundary, certification or submission deadline

    Duration: 1 h
  2. 02

    Audit

    Document review, interviews, configuration checks and evidence that controls operate

    Duration: 5–12 d
  3. 03

    Report & plan

    Findings, gaps and a prioritised plan — walked through with your team

    Duration: 2 d
  4. 04

    Certification support

    Remediation verified; present at the certification audit or the regulator meeting

    Duration: as needed
Contact

Thirty minutes that save you months

Tell me what you are dealing with — an audit before certification, a letter from the regulator, a customer requirement, or just not knowing where you stand. Within two working days you get a concrete proposal with scope and price.

  • You talk directly to the auditor who does the work
  • Fixed scope and price before anything starts
  • NDA on request, deliverables in Czech or English