Remediating and auditing are two different things and it is worth keeping them apart. Remediating is building the system until it complies. Auditing is coming afterwards, independently, and checking whether it really does. This page is the second.
When a compliance audit is called for
Ahead of a certification, to reach the external audit without surprises.
As the mandatory internal audit within a management system already in place.
When a client or a tender requires it and a third party has to evidence it.
To know where you stand before deciding how much to invest in remediation.
After significant change: a new site, a new critical supplier, a cloud migration or an acquisition.
Which frameworks we audit against
ISO/IEC 27001:2022: clauses 4 to 10 and the 93 Annex A controls.
ENS (RD 311/2022): Annex II measures by category.
NIS2: the article 21 risk management measures and the reporting procedure.
DORA: all five pillars, with particular attention to the third-party register of information.
GDPR and the Spanish LOPDGDD: lawfulness, information, rights, processors and security measures.
PCI DSS and CIS Controls v8.1.
How we work
1
Audit plan
Scope, criteria, calendar and people to interview. Agreed in writing so nobody improvises on the day.
2
Document review
Policies, procedures, records, contracts and minutes. What is written against what it claims to do.
3
Interviews
With the people who execute, not only the people who sign. That is where you see whether the procedure exists or has merely been drafted.
4
Technical verification
We genuinely test the technical controls: configurations, permissions, logs and backups. This is where our offensive side sets us apart from a purely documentary audit.
5
Nonconformity report
Every finding with its evidence, its severity and the specific requirement it breaches.
6
Closure plan
Proposed corrective actions, with owner and effort, and subsequent verification of closure.
What you get
Audit report with major and minor nonconformities and observations.
Evidence linked to every finding.
Compliance level per requirement and overall, comparable across successive audits.
Corrective action plan with proposed owners and deadlines.
Executive report for management or the security committee.
Closure verification of the corrected nonconformities.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Questions we get asked
Does this audit certify us?
No. Certification is issued by an accredited independent body. This audit tells you exactly what that body will find, so you can fix it first.
Can you audit us if you implemented the system?
For an internal audit, yes, provided the auditor is not the person who implemented. For a genuinely independent review, the honest answer is that someone else should do it, and we will say so.
How does this differ from a gap analysis?
A gap analysis measures the distance when you have not yet implemented; an audit verifies a system already running, with evidence and formal nonconformities. If you have not started, what you need is the gap analysis.
How long does it take?
From a few days to several weeks, depending on scope, number of sites and quantity of systems. It is fixed when the audit plan is agreed.
Know what the auditor will find
Half an hour to scope the audit and the framework you want to be measured against.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.
You may also need

