Consulting Services

Experts who take you from
diagnosis to compliance

Specialist consultancy in ISO/IEC 27001:2022, Cybersecurity Framework Law (21,663) and Personal Data Protection Law (21,719). Choose the service you need:

Not sure which applies to you? See it in 2 minutes

International
8 Regulations we implement
ISO standards and Chilean laws
40.000 UTM Maximum fine, Operators of Vital Importance
Law 21,663 ≈ $ 2.865.960.000
3 h For the early alert
to the ANCI
92 Days until Law 21,719
is fully in force
20.000 UTM Maximum fine
Law 21,719 ≈ $ 1.432.980.000
$71.649 UTM value today as at 31/08/2026
Choose your starting point

Which service do you need?

Click the service that best fits your current situation.

Gap Assessment

You do not know exactly what you are missing in order to comply. The gap assessment gives you a clear picture of gaps, priorities and the way forward — before investing in implementation.

2 – 4 weeks 4 phases 6 deliverables

Regulatory Implementation

You already know what you need and are ready to do it. We implement ISO 27001, Law 21,663 or Law 21,719 alongside your team, with complete documentation and audit preparation.

3 – 8 months 5 phases 3 regulations
Gap Assessment

A professional assessment of your compliance gaps

The gap assessment compares your current situation —documentation, controls, processes and governance— against the exact requirements of the regulation you need to comply with. The result is not a generic list: it is a a compliance matrix, requirement by requirement with maturity scoring by domain and a roadmap prioritised by risk.

For ISO 27001 we assess clauses 4–10 and the 93 Annex A controls. For Law 21,663, the duties that follow from your designation (Operator of Vital Importance or essential service). For Law 21,719, principles, lawful bases, rights and security obligations.

Price a gap assessment
2 to 4 weeks
Remote or hybrid delivery. Interviews by video conference and secure document review.
Triple coverage
We assess ISO 27001, Law 21,663 and Law 21,719 together so that a single diagnosis covers all three.

The 4 Phases of the Gap Assessment (click to expand)

F1
Discovery and Scope
Week 1
  • Kick-off meeting and definition of scope with the areas involved
  • Interviews with those responsible for IT, legal, HR and operations
  • Collection and review of existing documentation
  • Identification of critical processes, information assets and data flows
F2
Gap Evaluation
Weeks 1 – 2
  • Requirement-by-requirement review against the selected regulation
  • Verification of implemented controls and their level of evidence
  • Maturity scoring (0–5) by domain or compliance area
  • Classification of each gap by criticality: high, medium or low
  • Identification of quick wins: low effort, high impact
F3
Results Report
Week 3
  • Executive report for senior management: overall status, risks and penalties
  • Detailed technical report, requirement by requirement, with observations
  • Maturity heat map by domain (governance, risk, controls, privacy)
  • Document inventory: what exists, what needs updating and what is missing
F4
Roadmap and Presentation
Week 4
  • Gap closure plan prioritised by risk, effort and regulatory impact
  • Estimate of effort and resources per improvement initiative
  • Presentation of results to the board or management, with a Q&A session
  • Recommended route: ISO certification or direct legal compliance

Deliverables included

All in editable DOCX format, ready to present to the board, auditors or regulators.

Executive report for management
Detailed technical report by requirement
Compliance matrix (Excel/DOCX)
Maturity heat map by domain
Document inventory with the status of each item
Prioritised roadmap with estimated effort
Regulatory Implementation

Select the regulation you need to implement

End-to-end support alongside your team, with complete documentation and preparation for audit or inspection.

ISO/IEC 27001:2022 4 to 8 months

Implementation of a Certifiable ISMS

We design and implement your Information Security Management System (ISMS) in line with clauses 4–10 of ISO 27001:2022 and the 93 Annex A controls organised into 4 domains: organisational (37), people (8), physical (14) and technological (34). At the close, your organisation is ready to certify with an accredited body.

Why certify?
ISO 27001 certification opens commercial doors (tenders, corporate clients) and structures the information security management system that article 8, letter a) of Law 21,663 requires of Operators of Vital Importance. The law does not name any technical standard, so certification does not replace legal compliance: it evidences it. And it is a solid base for Law 21,719.

Project phases (click to expand)

F1
Context and Planning
Clauses 4–5
  • Analysis of organisational context and interested parties (clause 4)
  • Definition of the formal ISMS scope
  • Information Security Policy approved by management
  • Roles, responsibilities and constitution of the security committee
F2
Risk Management and SoA
Clause 6 · ISO 27005
  • Risk assessment methodology in line with ISO 27005
  • Inventory and valuation of information assets
  • Risk identification, analysis and evaluation
  • Risk treatment plan and Statement of Applicability (SoA)
F3
Control Implementation
Clauses 7–8 · Annex A
  • Drafting and rollout of policies and procedures across the 4 Annex A domains
  • Supplier, access, asset and physical security management
  • Secure development controls and incident management
  • Training and awareness programme by role
F4
Performance Evaluation
Clause 9
  • Definition of ISMS key performance indicators
  • Execution of the ISMS internal audit programme
  • Management review with minutes and documented decisions
F5
Improvement and Certification
Clause 10
  • Management of non-conformities and corrective actions
  • Internal pre-audit in preparation for certification
  • Support through stages 1 and 2 of the certification audit

Deliverables

ISMS scope, policy and manual
Risk methodology and matrix (ISO 27005)
Statement of Applicability (SoA)
Complete set of policies, procedures and forms
Internal audit programme and reports
Evidence folder ready for the certification body
Law 21,663 3 to 6 months depending on designation

Cybersecurity Framework Law

Law 21,663 created the ANCI and established mandatory duties for Operators of Vital Importance and providers of essential services. Incident reporting with the strict deadlines of article 9: early alert within 3 hours, a second report within 72 hours —or within 24 if an Operator of Vital Importance sees the delivery of its essential service affected— and a final report within 15 days. Operators of Vital Importance must also submit a action plan within 7 calendar days. Fines of up to 20,000 UTM (40.000 UTM for Operators of Vital Importance in very serious infringements).

The clock starts at the incident
Three hours for the early alert leaves no room for improvisation. If the protocol, the roles and the channels are not defined and rehearsed before the incident, breaching is all but inevitable — and the fine, certain.

Project phases (click to expand)

F1
Designation and Scope
Weeks 1 – 2
  • Legal and technical analysis to determine designation as an Operator of Vital Importance or essential service
  • Mapping of the specific duties that apply to you under the Law and its regulations
  • Review of the registers required by the ANCI and their associated deadlines
F2
Cybersecurity Governance
Weeks 2 – 4
  • Formal appointment and empowerment of the cybersecurity officer
  • Constitution of the cybersecurity committee and definition of responsibilities
  • Cybersecurity policy approved by management
  • Alignment with an ISMS (compatible with ISO 27001)
F3
Risk and Continuity
Weeks 3 – 8
  • Continuous risk management over essential services
  • operational continuity and disaster recovery plans
  • Incident response plan aligned with the deadlines of article 9 (alert 3 h · report 72 h, or 24 h if an Operator of Vital Importance sees its service affected · action plan 7 d · final report 15 d)
F4
Document and Technical Implementation
Weeks 6 – 14
  • Production of the complete document set: policies, procedures and protocols
  • Rollout of controls and security measures proportionate to the risk
  • Secure communication protocols with the ANCI and the National CSIRT
F5
Operation, Drills and Improvement
Weeks 12 – 20
  • Incident drills with timed reporting (3 h · 72 h · action plan 7 d · final report 15 d)
  • Training by role: officer, IT team, management and operations
  • Periodic compliance review and preparation for ANCI inspections

Deliverables

Designation report and applicable duties
Cybersecurity policy and officer appointment record
Risk matrix for essential services
ANCI reporting protocol (3 h · 72 h · plan 7 d · report 15 d)
Tested operational continuity plan
Drill report and training programme
Law 21,719 3 to 6 months · in force: 1 Dec 2026

Personal Data Protection Law

Law 21,719 brings the Chilean privacy regime up to GDPR level: it creates the Data Protection Agency, recognises the rights of access, rectification, erasure, objection, portability and blocking and sets fines of up to 20,000 UTM for very serious infringements. For companies that are not small businesses and that reoffend, the fine can reach 2% or 4% of annual revenue from the business, depending on whether the infringement is serious or very serious. It applies to every organisation that processes data in Chile, whatever its size.

92 days to prepare
A serious implementation takes 3 to 6 months. Organisations starting late will arrive with no records of processing, no rights procedures, and exposed to the Agency's first inspections.

Project phases (click to expand)

F1
Data Mapping and Transparency
Weeks 1 – 3
  • Inventory of all personal data processing (internal flows and those with third parties)
  • Internal records of processing activities. Chilean law does not require it in the GDPR sense, but without it you cannot build what it does require
  • Building the the duty to inform under article 14 ter: the twelve items that have to be published and kept available to the public
  • Classification of sensitive data and high-risk processing
F2
Lawful Bases and Consent
Weeks 3 – 6
  • Review of each processing operation against the lawful bases of Law 21,719
  • Redesign of privacy notices and policies
  • Consent management in forms, on the website, in cookies and in campaigns
F3
Data Subject Rights
Weeks 5 – 9
  • Procedures and channels to handle requests for access, rectification, cancellation, objection, portability and blocking
  • Implementation within the legal deadlines, with records and traceability
F4
Security and Breach Notification
Weeks 8 – 12
  • Security measures proportionate to the risk of the processing
  • Breach notification protocol to the APDP «without undue delay» —the law does not set 72 hours, that deadline comes from the GDPR— and to the data subjects when there is sensitive data, data of children under 14 or economic data
  • Internal incident register and response times
F5
Governance and Prevention
Weeks 10 – 20
  • Decision on appointing data protection officer: article 50 allows it, it does not require it
  • Impact assessments (DPIA) for high-risk processing
  • Processing agreements and international transfer clauses
  • Infringement prevention model of article 49: it is voluntary, and its certification works as a mitigating factor. What is mandatory is the duty of prevention in article 48

Deliverables

Records of processing and the article 14 ter publication
Updated privacy policy and notices
Rights procedures with channels and deadlines (30 calendar days)
Breach notification protocol for the Data Protection Agency
Impact assessment methodology and templates (DPIA)
Voluntary prevention model under article 49
Not sure which one you need?

Answer 3 questions and we will recommend the service

Do you know exactly which documents, controls or processes you are missing in order to comply?

Think of the specific regulation you are interested in (ISO 27001, Law 21,663 or Law 21,719).

Yes, we have a clear list of what we need
No, we are unsure exactly what we are missing

Have you carried out any formal compliance audit or assessment before?

Whether internal, with an external consultant, or through Ziemtinel's free assessment.

Yes, we have the results of a recent assessment
No, we have never done a formal assessment

Do you have a formal deadline to certify, bid for a tender or be ready for an inspection?

For example, a process with a corporate client, an ANCI audit, or Law 21,719 coming into force.

Yes, we have a date or deadline set
No, we are planning without a fixed date yet
Why Ziemtinel

Consulting with a Technological Edge

300+ Base Documents

We do not start from scratch: our catalogue covers all three regulations with professional documentation that we adapt to your reality. That saves months of work.

Senior Consultants

Whoever works with you knows the Chilean regulatory landscape and has defended documentation before auditors. Regulatory judgement cannot be improvised.

Triple Coverage

ISO 27001, Law 21,663 and Law 21,719 share many requirements. We implement them together so that one effort satisfies all three.

Defensible Deliverables

Every document and piece of evidence we deliver can be defended before auditors, the ANCI and the Data Protection Agency. Real compliance, not paper compliance.

What you can engage

Services by Regulation

We work with organisations in Chile and across Latin America: the ISO standards are the same in every country. Each scope can be engaged as an assessment, as a full implementation, or as both together, with the detailed scope and deliverables set out in the proposal.

Law 21,719

Personal Data

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

Law 21,663

Cybersecurity Framework

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

ISO/IEC 27001:2022

Information Security

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

All three regulations

One single project, not 3 por separado

  • Gap assessment Gap assessment
    −21%
  • Regulatory implementation Gap closure and evidence
    −20%
  • Gap assessment + implementation Both services, together
    −15%

How the value is determined

Proposals are quoted in UF, plus VAT. The value of each project comes from four factors:

  • Scope: which standards are included, and how many processes, systems and suppliers fall inside the management system.
  • Size and sites: people to interview, number of locations, and whether the scope spans more than one country.
  • Maturity: how much already exists —policies, records, controls in operation— and how much has to be built from scratch.
  • Timeline: the certification or compliance date you need, and the effort it takes to sustain it.
Find out what yours costs, today

Build your scope in the quote builder and get the proposal with figures in UF within 24 business hours. No meeting first, and no details needed until the end.

Build my quote

Full programme: ISO 27001 with Law 21,663 built in

The management system the standard certifies is the same one that article 8(a) of Law 21,663 requires of an Operator of Vital Importance. The five phases, the four deadlines of article 9, and which legal duty each stage covers.

See the programme
1.154
organisations already designated
as Operators of Vital Importance by the ANCI
Request a formal proposal
Specialist programmes

Specialist Consultancy Programmes

They all share the same management system structure, so the context, the roles, document control and the internal audit are built once and serve all of them. Each programme is contracted separately, but implementing them as one integrated management system avoids duplicating what is already done.

Privacy Governance

ISO 27701

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

AI Governance

ISO 42001

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

Quality Management

ISO 9001

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

Business Continuity

ISO 22301

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

IT Service Management

ISO 20000-1

  • Gap assessment Gap assessment
  • Regulatory implementation Gap closure and evidence
  • Gap assessment + implementation Both services, together
    −15%

ISO 27701 + ISO 42001, integrated

One single project, not 2 por separado

  • Gap assessment Gap assessment
    −20%
  • Regulatory implementation Gap closure and evidence
    −20%
  • Gap assessment + implementation Both services, together
    −15%

How the value is determined

Proposals are quoted in UF, plus VAT. The value of each project comes from four factors:

  • Scope: which standards are included, and how many processes, systems and suppliers fall inside the management system.
  • Size and sites: people to interview, number of locations, and whether the scope spans more than one country.
  • Maturity: how much already exists —policies, records, controls in operation— and how much has to be built from scratch.
  • Timeline: the certification or compliance date you need, and the effort it takes to sustain it.
Find out what yours costs, today

Build your scope in the quote builder and get the proposal with figures in UF within 24 business hours. No meeting first, and no details needed until the end.

Build my quote
Request a proposal

Tell Us About Your Compliance Challenge

Build your quote in two minutes: choose the regulations and the service you need, indicate the size of your organisation and see the reference figure on screen. A senior consultant contacts you within 24 business hours with the formal proposal.

1. Build your quote

Regulations, service and the size of your organisation. The reference figure appears instantly, with no waiting for a reply.

2. Diagnostic meeting

A 30-minute video call, at no cost, to understand your context and your urgency.

3. Formal proposal

You receive scope, phases, deliverables, timelines and figures. No hidden commitments.

It takes two minutes and commits you to nothing.
Would you rather write to us directly? contacto@ziemtinel.cl

Confidentiality
Your information is used only to prepare your proposal, in accordance with Law 21,719. We sign an NDA if your organisation requires one.
Basket 0 products

Your basket is empty

Add regulatory documentation packs or plans
Complete purchase
Contact and payment details
1Contact
2Summary
3Payment
Add to basket?