ISMS gaps

Your ISMS is in place, but one part of it does not hold. We close the gap, not the whole programme.

We close the gap with the artefact it needs: a rule, a procedure or a register of evidence. So the evidence is ready before the auditor arrives.

What you get

  • The artefact that closes the gap, fitted to your system landscape instead of a generic template. For example a cryptography standard, a logging concept or a register of evidence.
  • Developed against the requirements that apply to you: NIS2, DORA and its technical regulatory standards, MaGo and the German Insurance Supervision Act (VAG), or ISO 27001, depending on your sector.
  • A handover to your IT, not just a document. Your team understands it and produces the verification record themselves.
  • No software that simulates a rule. A rule that actually runs.

3,000 to
6,000 euros

Duration
Within 2 weeks of the assessment
Price
Fixed, per closed gap
Prerequisite
Assessment, 7,500 to 12,000 euros, separate
First engagement
with the assessment 10,500 to 18,000 euros; each further gap 3,000 to 6,000
Price driver
Your system landscape, not headcount
After that
You decide

The assessment measures your whole company; a gap closes a single, known finding. That is why the same amount of time costs less here.

Read-only access, no changes to your systems. Implementation stays with your IT. No framework agreement, no automatic renewal.

The criterion and the evidence

Executable means: system, target value, role, verification record

One criterion, not a footnote: every rule names a system, a target value, a responsible role and a verification record, and operations can implement it without further questions. If a rule does not meet that, it is not finished.

For a regulated firm, a standard is not a document you show once, it is a live register with test evidence. We map every rule against Annex A of ISO 27001, with ISO 27002 as the substantive reference, and against the DORA requirements for ICT risk management. One record per control. For firms in scope of DORA, the VAIT has been withdrawn since January 2025; we work against DORA, the related RTS and ISO 27001.

Sample data, no client material

Requirement
ISO 27001 A.8.24, DORA (RTS on ICT risk management, encryption)
System
Databases holding personal or contractually protected data
Target value
AES-256-GCM at rest; TLS 1.2 or higher in transit, AEAD suites only (e.g. ECDHE with AES-256-GCM), no legacy RC4 or CBC suites
Responsible role
The database owner implements it, IT leadership signs off
Verification record
Configuration export of the encryption setting, every six months

Written by someone who sat on both sides of the audit table as a CISO. The founder.

Case

A case

An insurer had to present a binding cryptography standard before the DORA deadline. They wanted this one gap closed, not a whole programme. We developed the standard based on DORA, its technical regulatory standards and ISO 27001. For firms outside DORA's scope, we develop just as readily against MaGo or VAG, or against ISO 27001 alone, whichever applies to you.

  • The ISMS was already in place. The standards could not be executed by their own IT.
  • Out of it: a cryptography standard and a logging concept their own team understands and can run.

When your system cannot meet the rule

A rule no system in the house can meet is not a rule. It is a risk nobody sees any more. So every rule gets an exception path, not a silent breach:

  1. Compensating control

    If a system cannot reach the target value, we define what mitigates the risk instead.

  2. Time-boxed exception

    Owner and deadline are in the document, not in one person's head.

  3. Risk acceptance

    A named role accepts the risk deliberately and it is documented, instead of staying open unnoticed.

Three assurances before you commission

The assessment runs first

A standard starts with an assessment of your affected systems. Without it, we do not know what target value your systems can actually carry. The assessment therefore runs first and is commissioned separately.

Your certificate stays untouched

The standard does not replace any document in your ISMS. Your ISMS controls and approves it, like any other document.

What we hand over

You get the documentation, the access and the knowledge behind it. You retain ownership of your systems. If something needs permanent support, we tell you beforehand. Then you decide whether we take it on.

Second opinion

Does an existing provider already write your standards, and you are not sure the verification record behind them really holds up? That is what the second opinion checks, independent, because we earn nothing on the operation.

Intro call

hello@controlpunkt.com

We reply within one business day.

What to put in the first email

  • Who you are and your company.
  • What it is about: the trigger, the real problem. A sentence or two is enough.
  • If a customer, an investor or a regulator has set a deadline: add the date.
  • After an incident: where the forensics stand.