Skip to content

SERVICE

Compliance controls assessment

Maturity against NIST CSF and ISO 27001 grounded in your evidence, not an interview: the agentic tool reads policies, records and configurations and backs every level with the document that supports it. The consultant decides and signs the final level.

CBRT certified 9001 + 27001Agentic toolBlind sampling
AT A GLANCE
Frameworks ISO 27001:2022 · PCI v4.0 · Law 172-13
Diagnosis From 1–3 weeks
Certification 90–180 days by maturity
Result Dossier and closure plan
HOW WE WORK

The methodology, step by step

01

Evidence collection

Policies, records and configurations you provide, without weeks of tabulation.

02

Agentic assessment

✦ AI AGENT

The tool assesses 15 domains against the framework and backs every level document by document.

03

Consultant validation

The consultant decides and signs the final level; blind sampling by a senior guarantees judgment.

04

Financial weighting

✦ AI AGENT

Gaps ordered by what they cost the business, not by the number of failed controls.

05

Executable plan

Owner, deadline, effort and the control that closes each gap.

06

Monitoring

Progress between assessments with overdue-action alerts.

SERVICE TIERS

Pick the tier that answers your question

The price is fixed in writing after a 30-minute scoping and does not change during the contract.

Guided self-assessment

COVERS
Assisted questionnaire
DURATION
1 week
VERIFICATION
IDEAL FOR
Quick first diagnosis
RECOMMENDED

Technical verification

COVERS
Questionnaire + technical sampling
DURATION
2–3 weeks
VERIFICATION
Technical, included
IDEAL FOR
Before an audit or insurance

Verification + re-assessment

COVERS
All + 90-day re-assessment
DURATION
2–3 weeks + follow-up
VERIFICATION
Technical + follow-up
IDEAL FOR
Programs with an annual target

Thirty minutes and we tell you frankly what you need.

Sometimes the answer is "you don't need us yet." We prefer that to selling you something you won't use.