Regulation Compliance

We do the same thing for every regulation, because the problem is always the same: gap analysis, action plan and remediation. We measure the distance between what the regulation demands and what you have, turn it into prioritised tasks and work alongside you until compliance holds up in front of an auditor.

Choose your regulation

Regulation (EU) 2024/1689AI Act · EU AI RegulationIn general application since 2 August 2026, with AESIA inspecting and fining. Transparency and AI literacy are already enforceable: the postponement only reaches high-risk systems.View service →Directive (EU) 2022/2555NIS2Essential and important entities. Spain has still not transposed it and the Commission has already referred the case to the CJEU: the clock starts when the law is published, not when you start.View service →Regulation (EU) 2022/2554DORADigital operational resilience for the financial sector. Applicable since January 2025, with no transposition to wait for.View service →Regulation (EU) 2023/1114MiCACrypto-asset service providers. The Spanish transitional regime ended on 1 July 2026.View service →ISO/IEC 27001:2022ISO 27001The certificate your client understands without explanation. 93 controls and a management system that carries the rest underneath.View service →Royal Decree 311/2022ENSThe Spanish National Security Framework. Mandatory for the public sector and for anyone who supplies it.View service →CIS Controls v8.1CIS 18The 18 critical controls, by implementation group. The cheapest way to cut real risk before certifying anything.View service →

We also work on

GDPR and the Spanish LOPDGDD: compliance assessment, data protection impact assessments and the data protection officer role, with a certified DPO on the team.
ISO 22301: business continuity, where the requirement is not protecting data but guaranteeing the service keeps running.
PCI DSS: technical preparation for cardholder data environments.

The three steps, whatever the regulation

Phase 1
Gap analysis
We measure the real distance between what the regulation demands and what you have today, control by control. No generic checklists: we review evidence, not statements of intent.
Phase 2
Action plan
Every gap becomes a task with an owner, an effort estimate and a priority based on risk. You decide what comes first knowing what protects you most.
Phase 3
Remediation
We work alongside you through delivery: policies, procedures, technical controls and evidence, until compliance holds up in front of an auditor.

Why us and not a generalist consultancy

We audit and we attack. The same team that drafts the Statement of Applicability runs penetration tests. That avoids the control that is written but does not work — the most common finding in any serious audit.
We do not sell certificates. We do not certify, and we say so before starting: certification is issued by an accredited independent body. We take you to it.
We reuse across frameworks. If you hold ISO 27001 and NIS2 is now on you, we do not start from zero: we map what already serves and work only the difference.
The plan is budgetable. Every gap carries an owner and an effort estimate, so management can decide with numbers.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

Several regulations apply to us at once. Does each need its own project?
No, and doing it separately is the most expensive route. We build a single risk assessment and one body of evidence, and from there cover what is specific to each regulation. It is common for an organisation to have ISO 27001, the ENS and NIS2 on the table at the same time.
Where do I start if I have nothing?
With the gap analysis of whichever regulation binds you first, and in parallel with the CIS Controls, which cut real risk from the first quarter while the rest progresses.
What does it cost?
It depends on scope, and scope cannot be guessed over the phone. That is why the first half hour is free: it exists to scope the work so you receive a proposal with a real number, not a range.
Do you work with our law firm?
Yes, and that is the norm. We cover the technical and management side; the legal fit and the formal file stay with your advisers. Working in parallel beats working in sequence.
Half an hour to know what you are facing
We tell you which regulations apply, in what order to tackle them and what a sensible gap analysis scope would be. No forms: phone, email or calendar.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES