← Kit Consulting

IX · Advanced · Security

Cybersecurity certification preparation

For SMEs with basic protection, a fit-for-purpose plan, and ISMS docs that want stronger protection, AI, and to prepare the ISMS for ISO 27001 and medium-high ENS certification (certification not included).

Category
Servicio de Asesoramiento en Ciberseguridad (Preparación para Certificación)
Type
Advanced
Price
€6,000 (VAT excluded). Annex IV / Acelera Pyme aid amount: €6,000 in segments A, B and C.
Segments
SMEs from 10 to under 250 employees (voucher A €12,000 · B €18,000 · C €24,000).
Coverage
Nationwide Spain · Any productive sector
Advisor
Pedro Armando Manfredi · Kit Digital IA · Barcelona
URL
https://kit-digital-ia.com/kit-consulting/ciberseguridad-certificacion

What we can offer

A firm of 10 to 250 that sells to large clients or the Administration and needs the ISO 27001 / ENS file. You contract certification; we leave the file ready. After the basic service.

  • ISMS manual (PDCA) and ISO 27001 / ENS statement of applicability.
  • Training by profile and metrics (incidents, MTTI/MTTD).
  • Internal audit independent from implementers.
  • Procedure and SoA drafts; the Security Officer signs.
  • File for a certification body. Certificate not included. After basic.

Who it is for

SMEs selling to clients or public bodies that need to present an ISMS for certification, excluding the certifier’s fee.

Activities

  • Pentesting and vulnerability analysis.
  • Review of policies, plans, and procedures; gaps and improvements.
  • Proactive data protection and response.
  • Awareness and risk culture.
  • Documentation to apply for ISMS certification (ISO 27001 and medium-high ENS, CCN-STIC 825). Certification not included.
  • Security use case.

Initial diagnosis

  • Builds on the existing security posture and basic ISMS.

Results and deliverables

  • ISMS manual with PDCA cycle and asset-protection policies/procedures.
  • ISO 27001 and ENS statement of applicability (CCN-STIC 804), approved by the Security Officer.
  • Training programme by profile and critical function.
  • Advanced rules (crisis, continuity) and security metrics (incidents, MTTI/MTTD).
  • Internal ISMS audit plan and report, independent from the implementation team.

Use case

  • Documentary file ready for a certification body (the certificate itself is out of scope).

How we deliver

  • ISMS document pack aligned to ISO 27001 and ENS, auditor-ready.
  • Internal audit independent from whoever implemented the system.
  • AI drafts procedures, training by profile, and SoA comments; the Security Officer signs.
  • The SME contracts certification with an accredited body; we prepare the ground.
Annex IV limits
  • Requires a prior Agreement for Cybersecurity (basic).
  • Delivery starts after the basic service is finished and justified.
  • Certification by an accredited body is not included in the €6,000.

Justification: on-site kickoff, work meetings, on-site close with sign-off, technical memo, and evidence per the call. Delivery window: 3 months from Agreement validation. Rules: Orden TDF/436/2024, de 10 de mayo.

Free assessment

Contact