Services
Advisory services
Twelve services, one evidence base. Where the requirements overlap, the documentation is written once.
Statutory duty
CSA / NIS2 compliance
We deliver full implementation of cyber security for essential and important entities under the Croatian Cybersecurity Act. We cover everything from establishing...
6 stepsView service →
EU regulation
GDPR compliance
We establish every personal data protection process - from the record of processing activities and impact assessments to DPO support and breach notification to...
6 stepsView service →
International standard
ISO/IEC 27001 - Information security
Gap analysis, ISMS implementation, risk assessment, Statement of Applicability and full preparation for the certification audit against ISO/IEC 27001:2022.
6 stepsView service →
Quality management
ISO 9001 - Quality management
QMS implementation, process documentation, quality objectives and KPIs, and preparation for the certification audit.
6 stepsView service →
Environmental standard
ISO 14001 - Environmental management
EMS implementation - identification of environmental aspects and impacts, a legal compliance register, carbon footprint reduction and certification readiness.
6 stepsView service →
Business continuity
ISO 22301 - Business continuity
Business impact analysis, RTO and RPO definition, business continuity and disaster recovery plans, exercising and preparation for certification against ISO...
6 stepsView service →
Financial sector
DORA - Digital operational resilience
Compliance with the EU DORA regulation for the financial sector - ICT risk management framework, third-party risk, resilience testing and regulatory reporting.
6 stepsView service →
Supply chain
Vendor risk management
Third-party risk assessment, due diligence questionnaires, automated risk scoring, continuous monitoring and contractual security clauses across the supply chain.
5 stepsView service →
Offensive security
Security audits and testing
Penetration testing, vulnerability assessment, configuration review, social engineering simulations and reports written for both technical and board-level...
6 stepsView service →
Independent review
Audits and internal reviews
We carry out internal audits of management systems and compliance reviews, and we walk your documentation the way an external auditor or certification body will...
5 stepsView service →
GDPR Art. 37-39
External data protection officer
We take on the data protection officer function. An external DPO is expressly provided for by the GDPR and for most organisations is cheaper and more independent...
5 stepsView service →
Leadership and oversight
External CISO
Measure 1 of Annex II requires a named responsible person who sets direction, reports to the board and secures resources. For most organisations a permanent hire...
5 stepsView service →