Compliance and regulation
NIST CSF and CIS Controls
Maturity assessment and improvement plan based on internationally recognised frameworks.
What it involves
What we do
We measure your organisation's maturity against the NIST Cybersecurity Framework 2.0 and the CIS Controls, and build a prioritised, measurable improvement plan.
What's included
- Maturity assessment by function (Govern, Identify, Protect, Detect, Respond, Recover)
- Prioritisation of CIS Controls by implementation group
- Current profile and target profile
- Improvement plan with quick wins
- Periodic maturity tracking
Who it's for
- Multinational organisations
- Companies with no specific regulatory obligation that want a reference framework
- Management teams that need to measure progress
Deliverables
- Maturity report
- Target profile
- Prioritised improvement plan
Reference frameworks and standards
Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.
How we approach it
- DiscoverWe get to know your business, environment, risks and priorities.
- AnalyseWe assess maturity, exposure, compliance and real capabilities.
- DesignWe define strategy, roadmap, architecture and action plan.
- ImplementWe deliver controls, processes, technology and evidence.
- OperateWe monitor, respond and support continuous improvement.
- OptimiseWe measure results, reduce risk and evolve capabilities.
Related services
More in Compliance and regulation
Spanish National Security Framework (ENS)
Adaptation, implementation and preparation for ENS certification for public administrations and their suppliers.
Demonstrate- Categorisation report
- Statement of applicability
- Adaptation plan
NIS2
Adaptation to the NIS2 Directive for essential and important entities.
Demonstrate- Applicability report
- NIS2 gap assessment
- Adaptation plan
DORA
Digital operational resilience for financial entities and their ICT providers.
Demonstrate- DORA gap assessment
- ICT risk framework
- Provider register
ISO/IEC 27001
Implementation and certification of the information security management system.
Demonstrate- Documented ISMS
- Statement of applicability
- Internal audit report
GDPR and LSSI
Data protection and compliance with information society services regulation.
Demonstrate- Record of processing activities
- DPIA
- Legal texts and contracts
Internal audit, gap assessment and due diligence
Functionally segregated review for audits, customers, committees and corporate transactions.
Demonstrate- Audit report
- Findings and risk matrix
- Prioritised action plan
Let's talk
Does NIST CSF and CIS Controls fit your situation?
Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.

