ISO/IEC 27001:2022
Information Security
-
Gap assessment Gap assessment
-
Regulatory implementation Gap closure and evidence
-
Gap assessment + implementation Both services, together−15%
We implement certifiable management systems built on ISO/IEC standards for organisations across Latin America, the United States and Europe. An ISO/IEC 27001 implemented in Lima, Mexico City or Madrid is precisely the same standard, with the same clauses and the same controls.
This catalogue covers international standards, and nothing else. It does not include any country's legislation — neither ours nor yours. You and your counsel know your local regulation, and we are not going to pretend otherwise from another continent.
What we do build is the management system that regulation later rests on. It is the part that does not change from one country to the next: context analysis, scope, asset inventory, risk assessment, controls and their evidence, internal audit and management review. A regulator asking you for appropriate technical and organisational measures finds its answer there, whatever the rule demanding it happens to be called.
That separation is a rule of the accreditation standards themselves, so be wary of anyone offering both: a consultant who also certifies would be auditing their own work. We leave the system standing, train your internal auditors and are there on audit day; the certificate is issued by whoever is entitled to issue it.
Perú · Colombia · Ecuador · México · Argentina · Bolivia · Brasil · Uruguay · Paraguay · Panamá · Costa Rica · Estados Unidos · España
Where from
Santiago, Chile, remotely. Chilean hours overlap the full working day across the Americas and reach into the European afternoon, so meetings land inside both parties' business hours without anyone getting up at dawn.
Your country not on the list? Write to us anyway. The list is where we have already worked, not a border.
Presented the way any asset is presented inside a management system: with its identifier, its reference standard, who verifies that it exists and who is going to ask you for it. Click a row to see what it covers.
The information security management system. Clauses 4 to 10 and the 93 Annex A controls, grouped into four themes: organisational, people, physical and technological. This is the standard corporate clients and tenders ask for when they want proof that their supplier manages risk.
Two-stage initial audit, annual surveillance and recertification in year three.
Extends the security system to the processing of personal data: controller and processor roles, records of processing activities, impact assessments, data subject rights and supplier agreements. It ships with an explicit mapping to the European General Data Protection Regulation.
Built on top of SG-01, not instead of it.
The first certifiable AI management standard. Inventory of AI systems, impact assessment, model lifecycle control, training data governance and human oversight. It answers the question every audit committee is asking today: who answers for what the model decides.
Shares the records of processing and the impact assessment with SG-02.
The most widely demanded management system standard in the world, in tenders and in contracts with large buyers. Process approach and risk-based thinking: the company understood as connected processes, each with an owner, its indicators and what can go wrong in it.
The usual way in: whoever holds it implements the others far faster.
What happens when something goes down, and how long you can afford it to last. Business impact analysis, recovery time objectives, continuity strategies, response plans and — the part almost nobody does — the exercise proving the plan works before you need it.
It is also what SG-01 expects to find behind its continuity controls.
The service management system: catalogue and service levels, incident and problem management, change and release, capacity and availability. For managed service providers whose clients require them to demonstrate how they operate, not merely to promise it.
Aligns with ITIL, which is a body of good practice and not an auditable standard.
All six share the same high-level structure: if you already have one in place, the context, the roles, document control and internal audit are reused rather than duplicated. That is why the second system always costs less than the first.
The same inventory, for what cannot be certified. There is no such thing as a «NIST certificate» or a «GDPR certificate», however often they are sold, which is why none of them appears below as a programme you can engage on its own. The last column is what we do instead: map them onto the management system already in place, because a control implemented once answers several at a time.
Version 2.0, released in 2024, added Govern to the five original functions: govern, identify, protect, detect, respond and recover. It maps cleanly onto Annex A of ISO/IEC 27001, so it lets you report in the language a board or a US client expects without standing up a second system.
Not certifiable: no body audits against it.
The US federal government's catalogue of security and privacy controls, and the foundation FedRAMP is built on. Relevant if you sell to a federal agency, or to a contractor passing its requirements down to you by contract.
Used to extend the Statement of Applicability, not to replace it.
It reaches anyone offering goods or services to people in the European Union, even without an establishment there. Records of processing activities, impact assessments, breach notification within 72 hours and a data protection officer where required. ISO/IEC 27701 was written to leave all of that in place and evidenced.
It is law, not a technical standard: you comply with it, you do not certify against it. Your counsel has the last word.
Not a certification: a report issued by a CPA firm, Type I on the design of the controls or Type II on how they operated over a period. Almost every SaaS buyer in the United States asks for it.
We prepare the evidence; the report is signed by the auditor, never by the consultant.
Eighteen controls ordered by real-world priority and split across three implementation groups, from the most basic to the most demanding. It is the most concrete item on this list: where ISO 27001 says what must be covered, CIS says where to start on Monday.
Most useful in the first quarter, when gaps need closing and time is short.
Neither certified nor audited against: it is the guidance the method comes from — how risk is identified, analysed and treated. It is what makes the ISO/IEC 27001 risk assessment something more than a colour-coded spreadsheet, and the same methodology then serves the other systems.
It runs across the whole inventory: all six systems require risk assessment.
A system certified last year and left unattended since will not pass its surveillance audit. These two roles are what keeps it alive: the same function as an in-house post, with agreed monthly hours and without a full-time executive salary.
The security leadership function as a service, for organisations that need it but cannot justify a full-time post. It keeps the system alive between audits: risk review, follow-up on the treatment plan, security committee, management review, and the technical counterpart when a client sends its supplier questionnaire or when there is an incident.
It does not transfer ownership of the risk: that stays with the board, and no standard allows it to be delegated.
The data protection function, for those required to appoint one or who simply need someone to answer for it. It maintains the records of processing activities, leads impact assessments, handles data subject rights, reviews processor agreements and acts as the contact point for the relevant supervisory authority.
The formal appointment is made by your organisation before your authority; we take on the function and the work.
Both roles together come in 10% cheaper than separately: the context, the asset inventory and the risk assessment are done once and serve both. Engagements run for 3, 6, 12 or 24 months, billed monthly.
Management system consulting is interviews, documents and evidence. Almost none of that improves by sharing a room, and the little that does is concentrated and planned.
Discovery interviews are scheduled inside your team's working day, not ours. They are recorded and summarised, because the person who missed the risk session is always the one who had the answer.
All documentation lives in a shared space with version and access control. No policies circulating by email in their third revision, which is how two different truths turn up on audit day.
If your scope includes facilities that have to be seen — a data centre, a plant — a visit is planned and quoted separately, with its costs in plain view. It is not buried in the price paid by those who do not need it.
A confidentiality agreement before the first interview, and a contract setting out scope, deliverables, milestones and currency of payment. The law governing the contract is agreed with you, not imposed on you.
A board showing how far each gap has been closed and who owns each action. The board should be able to answer «where are we?» without asking anyone for a report.
In the final phase we train auditors inside your organisation. It is a requirement of the standard, and it is also what decides whether the system survives its second year: if internal audit always depends on an outsider, it happens once and is abandoned.
The gap assessment can be engaged on its own: it is a useful diagnosis in itself and commits you to nothing. The scope and deliverables are set out in the proposal.
Information Security
How the value is determined
International proposals are quoted in US dollars (USD), net. The value of each project comes from four factors:
Build your scope in the quote builder and get the proposal with figures in dollars within 24 business hours. No meeting first, and no details needed until the end.
The last panel combines privacy and AI governance into a single project: they share the records of processing and the impact assessment, which is why they cost less together than apart.
ISO 27701
ISO 42001
ISO 9001
ISO 22301
ISO 20000-1
One single project, not 2 por separado
How the value is determined
International proposals are quoted in US dollars (USD), net. The value of each project comes from four factors:
Build your scope in the quote builder and get the proposal with figures in dollars within 24 business hours. No meeting first, and no details needed until the end.
No cost and no sales deck. Tell us which country you operate in, which standard is being asked of you and who is asking — a client, an investor, a regulator — because that changes the scope and the timeline more than the size of the company does. If you already have an audit date committed, say so at the start: it changes the order of the phases.
Your basket is empty
Add regulatory documentation packs or plans