Cybersecurity and AI compliance

Cybersecurity compliance: NIS2, DORA, ISO 27001 and ENS without losing your way

We support the entire regulatory journey, including AI regulation, from initial assessment through certification, with procedures and timelines aligned to your organization.

Request your free GAP analysis →

The problem we solve

The regulatory map has become dense and confusing: NIS2, DORA, ISO 27001, ENS, the AI Act and industrial standards, each with its own scope, language and deadlines.

SMEs often freeze because they assume the rules do not apply, or rush into certification under client pressure. We first determine exactly what applies, then build a realistic plan that does not paralyze daily operations.

Key frameworks, explained clearly

NIS2

Expands risk-management and incident-reporting duties across critical and important sectors, including smaller companies through critical roles and supply chains.

DORA

The EU digital operational resilience regulation for finance, also reaching many software, cloud and IT-support suppliers through contracts.

ISO 27001

The voluntary international standard for an Information Security Management System, increasingly required by major customers.

ENS

Spain’s mandatory security framework for public administrations and, contractually, many of their suppliers.

AI Act

Regulates AI by risk level and also affects non-technology companies using chatbots, assistants, automated recruitment or generative tools.

IEC 62443 and industrial standards

Security requirements for industrial control systems that increasingly overlap with NIS2 in critical and important sectors.

Our support process

  1. 1GAP analysis: establish what you already meet, what is missing and the effort required before resources are committed.
  2. 2Internal audit: assess the detailed requirements of NIS2, ISO 27001, ENS, DORA or another applicable framework and prepare for external audit.
  3. 3Implementation: create policies, procedures, technical controls, response plans, supplier management and understandable documentation.
  4. 4Certification and follow-up: support you before the certification body or authority, provide evidence and stay with you through later audits.

AI governance and control

AI Act compliance requires clear internal rules for how AI is used. We create a framework proportionate to your business and can align it with ISO/IEC 42001 where useful.

  • Inventory formal and informal AI systems and tools.
  • Classify risks and obligations under the AI Act.
  • Define internal policies for tools, data, human oversight and documentation.
  • Train employees who use or supervise AI systems.
  • Continuously review the framework as tools and risks change.

Genuinely adapted to SMEs

  • Break the work into manageable phases prioritized by risk and urgency.
  • Scale documents and controls to the real complexity of your operations.
  • Set a pace your organization can absorb without sacrificing rigor.
  • Explain every step in language non-technical decision-makers can understand.

Who is this service for?

  • Critical or important-sector companies potentially covered by NIS2.
  • Financial entities and technology suppliers affected by DORA.
  • Businesses pursuing ISO 27001 for clients, tenders or international markets.
  • Public-sector suppliers that need ENS accreditation.
  • Industrial organizations combining NIS2 with IEC 62443.
  • Any company using AI that needs to understand and meet AI Act duties.

Why work with us

Compliance should not be a legal threat or an isolated paperwork exercise. Done well, it organizes security, builds trust with clients and partners, and prepares you for requirements that will eventually reach your business.

Frequently asked questions

Your questions, answered

Can NIS2 affect a small company?

Yes, if it performs a critical or unique function or supplies an obligated entity that passes security requirements down by contract.

What is the difference between ISO 27001 and ENS?

ISO 27001 is a voluntary international standard. ENS is mandatory for Spanish public administrations and many suppliers. Their shared principles make progress in one useful for the other.

Can DORA affect me outside finance?

It may affect you contractually if you provide software, cloud or IT support to a financial entity.

How long does ISO 27001 certification take?

It depends on your starting point and scope. A GAP analysis provides an estimate tailored to your situation.

Does the AI Act affect me if I only use a chatbot or generative AI?

Very likely. You do not have to develop AI; using it in daily business can create transparency, training and governance obligations.

What is an AI control framework?

A set of internal rules defining approved tools, permitted data, mandatory human oversight and staff training.

Is ISO/IEC 42001 certification mandatory?

No. The AI Act is law; ISO/IEC 42001 is a voluntary standard that helps structure AI management.

We work for you, so you can stay focused on your business without worries or disruption.

Start with a free GAP analysis →