Search Client login
Capability · Compliance

Compliance done well is an edge, not a burden.

ISO 9001/14001/27001/45001 implementation and certification, compliance with the Spanish National Security Framework (ENS), MAGERIT risk analysis and GDPR/NIS2/DORA cybersecurity for organisations and public bodies.

Capability · Compliance

Compliance done well sets the winners apart.

ISO 9001 opens the door to public tenders. ENS is mandatory to supply the Spanish public administration. NIS2 redefines cyber accountability. I work each one with practical judgement: meet what really applies, without unnecessary paperwork.

Explore

Explore now.

Shall we talk about your project?

First session free of charge. Tell me the context and, if we are a good fit, I'll prepare a tailored proposal within five working days.

Frequently asked questions

How does this apply to my SME?

It applies as long as you serve Spanish customers or process Spanish data; the framework is mandatory above thresholds we summarise in the table.

What does it cost in 2026?

Indicative ranges for SMEs 10-50 employees: 2,500-12,000 EUR for documentation + auditor fees vary by AENOR / BV / SGS / LRQA.

Which Spanish regulation applies?

BOE references RD 311/2022 (ENS), Regulation EU 2016/679 (GDPR), LOPDGDD, NIS2, DORA and the EU AI Act 2024/1689 depending on scope.

How long does the implementation take?

Average runs 4-7 months for a single ISO. Compound integrated SGI (9001+14001+27001) usually 8-12 months.

Can I co-finance it with Kit Digital or Kit Consulting?

Yes, Kit Consulting 2026 covers up to 24,000 EUR in advisory hours; Kit Digital covers tools (CRM, ERP, ciberseguridad) up to 29,000 EUR.

References: AENOR · BOE · ISO