Services

Compliance & certification

We help organisations shape good policy and implement it — right through to certification. Using tools your organisation already has, or the best tools on the market.

Standards we work with

  • GDPR — privacy policy, processing register and data breach procedures.
  • ISO 9001 — quality management.
  • ISO 14001 — environmental management.
  • ISO 27001 / 27002 — information security, including ISMS setup.

From policy to certificate

  1. Assessment

    Where do you stand now? A baseline measurement of processes, risks and existing documentation.

  2. Policy and processes

    Practical policy that fits your organisation — no paper tiger.

  3. Implementation

    Rolling out processes and measures, with buy-in from staff.

  4. Certification

    Guidance through the external audit, until the certificate is in hand — and afterwards.

Looking for ongoing coverage of the security role? Take a look at (CI)SO as a Service.

Our approach: pragmatic steps to the certificate

Risk-driven

No tick-box exercises: the risk analysis determines which measures get priority. That way you meet the standard and become genuinely more secure.

Policy that's actually lived

Documentation that fits your organisation: concise, understandable and workable. Policy that sits in a drawer protects no one.

Continuous improvement

With a plan-do-check-act cycle and guidance through internal and external audits, your management system stays current — even after the certificate is achieved.

See our full approach

Food for thought…

Question to ponder 1

Are your customers already asking for an ISO 27001 certificate in tenders?

Question to ponder 2

If the Dutch Data Protection Authority called tomorrow, would your processing register be ready?

Question to ponder 3

Is your policy something that's actually lived by — or a folder that only gets opened before the audit?

Question to ponder 4

Does everyone know what to do in the event of a data breach, even on a Friday afternoon?

Question to ponder 5

How much revenue are you missing out on because you're not (yet) certified?

Ready to get started with compliance or certification?

Request a no-obligation IT assessment + action plan