Cybersecurity compliance: from obligation to strategic asset

NIS2, DORA, ENS, ISO 27001. Cybersecurity regulations keep multiplying and tightening. We help you understand what applies to you, what's missing and how to get there without turning it into a never-ending project.

The problem with compliance today

Companies face a regulatory map that overlaps and contradicts itself: the NIS2 Directive covers critical sectors, DORA applies to the financial sector, the ENS applies to public entities and their suppliers, and ISO 27001 is increasingly demanded by enterprise clients as a contractual requirement. Each regulation has its own deadlines, specific controls and penalty regime. Without a guide who knows them well, the risk is investing huge effort and getting nowhere. We support compliance projects for companies across Spain — Valencia, Alicante, Seville, Barcelona and beyond — remotely, with on-site presence when the audit requires it.

Regulations we cover

  • NIS2 — European directive on the security of network and information systems
  • DORA — Digital Operational Resilience Act for the financial sector
  • ENS — Spanish National Security Framework for public administration
  • ISO 27001 — International standard for information security management
  • GDPR — Technical aspects of data protection and security measures
  • PCI-DSS — Security in card payment processing

How we approach compliance

  1. Applicability analysis: We determine exactly which regulations apply to you, at what level and under what deadlines.
  2. Gap analysis: We compare your current state against the required controls. The result is a clear map of what you have and what's missing.
  3. Remediation plan: Action plan prioritized by risk and impact, with measurable milestones and concrete deliverables.
  4. Technical implementation: We support your IT team with implementation: access management, encryption, logging, backups, vulnerability management.
  5. Documentation and evidence: We draft the necessary policies, procedures and records: ISMS, incident procedure, business continuity plan.
  6. Audit readiness: We simulate the external audit, fix deviations and prepare your team to answer with confidence.

What's included

  • Gap analysis report with prioritized findings
  • Remediation plan with timeline and owners
  • Complete documentation package (policies and procedures)
  • Support implementing technical controls
  • Team training and awareness
  • Support during the external audit

Who needs this service?

  • Companies in sectors regulated by NIS2: energy, healthcare, transport, ICT, water, finance
  • Financial and insurance entities subject to DORA
  • Public administrations and their technology suppliers (ENS)
  • Companies asked for ISO 27001 by enterprise clients
  • SaaS and tech companies seeking certification to open up the enterprise market

Frequently asked questions

Can you help us with several regulations at once?

Yes, and it makes sense to do so. Many controls in ISO 27001, NIS2 and DORA overlap. Handling them in an integrated way avoids duplication and reduces overall effort.

Do you also run the certification audit?

We're not a certification body (that requires ENAC accreditation), but we work with the main certifying entities and support you throughout the process.

How long does a compliance project take?

It depends on the regulation and your starting point. A gap analysis takes 2-4 weeks. A full ISO 27001 project from scratch takes between 6 and 12 months for an SME.

Is the ENS mandatory for private companies?

The ENS is mandatory for public administrations and private companies that provide ICT services to the administration or process publicly owned data.