Audit
Annual internal cybersecurity audit
NIS2 asks for policies to assess whether security measures are effective, and ISO 27001 requires internal audits at planned intervals. We carry out the audit independently, check whether the measures work in practice and leave a report with nonconformities and deadlines.
Scope and price are confirmed in writing before work starts.
Discuss your caseThe benefit for your organisation
- You meet the internal-audit requirement with an independent auditor.
- Management sees which measures work in practice and which exist only on paper.
- Every nonconformity has a deadline and an owner.
Annual internal audit
Annual programme and plan, review of documents and records, interviews and on-site checks of selected measures. A report for management.
from €3 900usually 2–3 weeks
Base scope
One organisation of up to 100 staff and up to 10 key systems. Larger organisations, more units or several standards at once are quoted in writing.
by quotationfor a larger scope
What the rules require
- NIS2 requires policies and procedures to assess the effectiveness of cybersecurity risk-management measures (Art. 21(2)(f)).
- ISO 27001 requires internal audits at planned intervals; national rules can set a fixed cycle. In Bulgaria, for example, the 2019 ordinance requires an internal audit at least once a year, which a third party may carry out on the entity’s behalf.
- The auditor must be independent of the work audited. Nonconformities are documented with the requirement, the observed state and a deadline.
- We check the national rules that apply at the time of the audit.
How it works
- An annual audit programme and plan approved by management.
- Review of documents and records: policies, registers, test reports, supplier contracts.
- Interviews and on-site checks of selected measures: access, backups and restore, incidents, suppliers.
- A method based on ISO 19011, with sampling and evidence for each finding.
What you receive
- A findings report: for each nonconformity the requirement, the observed state and a deadline.
- A management summary with priorities.
- Follow-up of remediation at the next audit or by agreement.
Independence
If Dyasol implemented the measures being audited, we do not audit our own work: we recommend another auditor or audit only the parts we did not work on. Preparing for certification: readiness and evidence pack.
Boundaries
- This is an internal audit, not a certification audit, which is carried out by an accredited certification body.
- The audit does not replace a review by the competent authority.
General information, not a legal opinion.