Deutsch: această pagină nu e încă tradusă. Textul de mai jos e în English.
The difference between an audit that delivers value and one that just produces paper comes down to a distinction many skip: design effectiveness (is the control designed to meet the objective?) versus operating effectiveness (has it worked, consistently, over a period of time?). A control that looks good in a policy but no one applies is a non-conformity — and that is exactly where most programmes break at a real inspection. We test both.
How we work
The same discipline, regardless of framework:
- Scoping — which systems, data and entities fall within the assessment. In compliance, a poorly scoped engagement is the primary cause of failure
- Gap analysis — current state against requirements, in a clear register with owners and severity
- Control testing — design and operating effectiveness separately: interviews, configuration reviews, log and ticket samples, walkthroughs
- Evidence collection — not declarations, but artefacts that withstand inspection
- Report — findings, priorities and a roadmap your team can execute
What we cover
International frameworks — ISO/IEC 27001, PCI-DSS v4.0.1, NIS2, DORA, NIST CSF — plus the national authority requirements you operate under. For each, we verify what the framework actually requires, not a generic interpretation: from the information security management system (ISO 27001) to cardholder data environment scoping (PCI-DSS) or operational resilience and the third-party register (DORA).
Honesty about attestation
This is where credibility is lost most quickly, so we are explicit: we prepare, verify and conduct internal audits, but the certification decision for ISO 27001 belongs to an accredited body, and signing a PCI Report on Compliance belongs to a QSA. Our role is to bring you to the point where the certification auditor has nothing left to reject — and to keep the programme defensible between audits.