Cyber Security

ISO 22320 – Emergency Management Conformity Assessment

Overview

ISO 22320 specifies requirements for effective incident response. Our assessment helps organizations:

  • Evaluate emergency preparedness against international standards

  • Identify gaps in crisis management processes

  • Improve coordination with first responders and authorities

  • Enhance organizational resilience during disruptions

Who It's For

  • Government emergency response agencies

  • Critical infrastructure operators

  • Corporate security and business continuity teams

  • Healthcare and public safety organizations

  • Disaster recovery service providers

Why an ISO 22320 Assessment Matters

  • Response Effectiveness: Streamline incident command systems

  • Regulatory Compliance: Meet emergency preparedness mandates

  • Stakeholder Coordination: Improve multi-agency collaboration

  • Reputation Protection: Demonstrate crisis readiness

Scope of Our Assessment

  • Command Structure: Incident management team evaluation

  • Communication Systems: Emergency notification processes

  • Response Procedures: Scenario testing and drills review

  • Resource Management: Equipment and personnel readiness

  • Improvement Roadmap: Prioritized enhancement actions

Our 6-Step Assessment Process

  1. Pre-Assessment Questionnaire: Baseline capability review

  2. Document Review: Emergency plans and procedures

  3. Facility Walkthrough: On-site or virtual inspection

  4. Simulation Exercise: Tabletop or functional drill

  5. Stakeholder Interviews: Response team debriefs

  6. Final Report: Conformity Assessment with action plan

Deliverables

  • Conformity Assessment Certificate (valid 1 year)

  • Emergency Preparedness Scorecard

  • Gap Analysis Report

  • Training Recommendations

  • After-Action Review Package

Why Company Certification Int.?

  • Crisis Management Experts: Assessors with FEMA/EMC certifications

  • Real-World Experience: Lessons from actual disaster responses

  • Practical Focus: Actionable recommendations, not just compliance

  • Global Benchmarking: International best practices

FAQ

Q: Is ISO 22320 certification available?
A: No, it's an implementation standard. Our assessment provides formal recognition of your compliance.

Q: How many scenarios should we test?
A: We typically evaluate 2-3 high-risk scenarios relevant to your operations.

Q: Can this integrate with our BCMS?
A: Yes, we align assessments with ISO 22301 business continuity systems.

Q: What's the difference between this and NFPA 1600?
A: ISO 22320 focuses specifically on incident response, while NFPA covers broader continuity planning.

Q: Do you conduct full-scale drills?
A: We offer both tabletop exercises and limited functional drills.

Get Started

Ready to strengthen your emergency response?
[Request Preparedness Assessment] [Download Emergency Checklist]

ISO 90003 – Software Quality Management Conformity Assessment

Overview

ISO 90003 provides guidance for applying ISO 9001 quality principles to software engineering. Our assessment helps organizations:

  • Evaluate software development and maintenance processes

  • Identify gaps in quality management system implementation

  • Improve software reliability and customer satisfaction

  • Prepare for full ISO 9001 certification

Who It's For

  • Software development companies

  • IT departments managing in-house development

  • Embedded systems manufacturers

  • Cloud service providers

  • Organizations pursuing CMMI or Agile maturity

Why an ISO 90003 Assessment Matters

  • Quality Improvement: Reduce defects and rework

  • Customer Confidence: Demonstrate commitment to software quality

  • Process Standardization: Establish consistent development practices

  • Competitive Advantage: Meet procurement requirements for quality systems

Scope of Our Remote/On-Site Assessment

  • Process Evaluation: Requirements management to deployment

  • Document Review: Quality manual, procedures, and records

  • Tool Assessment: Development and testing environments

  • Competency Verification: Team skills and training

  • Improvement Roadmap: Prioritized actions for quality enhancement

Our 6-Step Assessment Process

  1. Scoping Call: Define assessment focus areas

  2. Document Collection: Quality policies, project artifacts

  3. Virtual Interviews: Development team and stakeholders

  4. Process Validation: Review sample projects

  5. Findings Analysis: Gap identification

  6. Final Report: Conformity Assessment with improvement plan

Deliverables

  • Conformity Assessment Certificate

  • Software Quality Maturity Report

  • Process Improvement Plan

  • Tooling Recommendations

  • Executive Presentation Deck

Why Company Certification Int.?

  • Software Specialists: Assessors with SEI and Agile certifications

  • Practical Approach: Focus on implementable improvements

  • Methodology Agnostic: Applicable to Waterfall, Agile, DevOps

  • Global Recognition: Accepted by software procurement teams

FAQ

Q: Is ISO 90003 certification available?
A: No, it's guidance for applying ISO 9001 to software. We assess your alignment and prepare you for ISO 9001 certification.

Q: How does this differ from CMMI?
A: ISO 90003 focuses on quality management systems, while CMMI evaluates process maturity - we can assess both.

Q: Can Agile teams benefit?
A: Absolutely. We tailor assessments for Agile/DevOps environments.

Q: What's the assessment duration?
A: Typically 2-3 weeks depending on organization size.

Q: Do you review our code quality?
A: We evaluate quality processes, not code itself (though we can recommend static analysis tools).

Get Started

Ready to enhance your software quality management?
[Request Assessment] [Download Software Quality Checklist]

ISO 31000 – Risk Management Conformity Assessment

Overview

ISO 31000 provides guidelines for establishing an effective risk management framework. Our assessment helps organizations:

  • Evaluate risk management processes against international best practices

  • Identify gaps in risk identification, analysis, and treatment

  • Strengthen decision-making through systematic risk evaluation

  • Align with corporate governance and compliance requirements

Who It's For

  • Enterprises implementing enterprise risk management (ERM)

  • Financial institutions and insurance companies

  • Project-based organizations managing complex risks

  • Public sector entities and critical infrastructure providers

  • Companies preparing for ISO certification audits (e.g., ISO 9001, 27001)

Why an ISO 31000 Assessment Matters

  • Strategic Advantage: Make risk-informed business decisions

  • Regulatory Compliance: Meet governance requirements (SOX, Basel III, etc.)

  • Resilience Building: Proactively identify operational vulnerabilities

  • Stakeholder Confidence: Demonstrate mature risk management to investors

Scope of Our Assessment

  • Framework Evaluation: Risk management policy and methodology review

  • Process Assessment: Risk identification, analysis, and treatment processes

  • Integration Check: Alignment with other management systems

  • Competency Review: Risk management team capabilities

  • Improvement Plan: Roadmap for risk maturity enhancement

Our 6-Step Assessment Process

  1. Scoping Workshop: Define risk management objectives

  2. Document Review: Risk policies, registers, and treatment plans

  3. Interviews: Engage with risk owners and senior management

  4. Process Validation: Evaluate risk management in practice

  5. Gap Analysis: Compare against ISO 31000 principles

  6. Reporting: Deliver Conformity Assessment and an improvement plan

Deliverables

  • Conformity Assessment Certificate (valid 1 year)

  • Risk Maturity Assessment Report

  • Priority Improvement Roadmap

  • Integration Guide for other standards

  • Executive Presentation Deck

Why Company Certification Int.?

  • Risk Specialists: Assessors with CRMA and ISO 31000 expertise

  • Industry-Tailored: Sector-specific risk evaluation criteria

  • Practical Focus: Actionable recommendations, not just compliance

  • Global Recognition: Accepted by regulators and auditors worldwide

FAQ

Q: Is ISO 31000 certification available?
A: No, ISO 31000 is a guidance standard. Our assessment provides formal recognition of your framework's alignment.

Q: How does this differ from COSO ERM?
A: ISO 31000 is principles-based, while COSO provides a more detailed framework - we can assess against both.

Q: Can small businesses benefit?
A: Absolutely. We scale assessments for SMEs with practical, cost-effective approaches.

Q: What's the typical duration?
A: 2-4 week,s depending on organization size and complexity.

Q: Do you help implement improvements?
A: Yes, we offer optional implementation support packages.

Get Started

Ready to strengthen your risk management framework?
[Request Risk Assessment] [Download Risk Checklist]

ISO 22313 – Business Continuity Management Conformity Assessment

Overview

ISO 22313 provides implementation guidance for business continuity management systems (BCMS) based on ISO 22301. Our assessment helps organizations:

  • Evaluate resilience against operational disruptions

  • Identify critical vulnerabilities in business processes

  • Align with international best practices for continuity planning

  • Prepare for full ISO 22301 certification

Who It's For

  • Corporations requiring business continuity assurance

  • Financial institutions and critical infrastructure providers

  • Healthcare organizations and public sector entities

  • Supply chain managers ensuring operational resilience

  • IT departments managing disaster recovery systems

Why an ISO 22313 Assessment Matters

  • Risk Mitigation: Protect against operational downtime costs

  • Regulatory Compliance: Meet financial, healthcare and data protection requirements

  • Stakeholder Confidence: Demonstrate resilience to clients and investors

  • Competitive Advantage: Qualify for contracts requiring proven BCMS

Scope of Our Assessment

  • BCMS Documentation Review: Policies, risk assessments and recovery plans

  • Process Evaluation: Business Impact Analysis (BIA) methodology validation

  • Facility Assessment: Alternate site readiness (on-site option)

  • Crisis Management Testing: Simulation exercise review

  • Improvement Roadmap: Prioritized actions for ISO 22301 readiness

Our 6-Step Assessment Process

  1. Scope Definition: Identify critical business functions

  2. Document Review: BCMS documentation collection

  3. Virtual/On-Site Evaluation: Process verification (3-5 days)

  4. Management Interviews: Leadership and response team assessments

  5. Findings Workshop: Gap analysis presentation

  6. Final Report: Conformity Assessment with improvement plan

Deliverables

  • Conformity Assessment Certificate (valid 1 year)

  • Resilience Scorecard with maturity ratings

  • Business Continuity Improvement Plan

  • Regulatory Alignment Report

  • Executive Briefing Package

Why Company Certification Int.?

  • BCM Experts: Assessors with CBCP and ISO 22301 Lead Auditor qualifications

  • Sector-Specific Knowledge: Financial, healthcare, and manufacturing experience

  • Actionable Outputs: Clear path to ISO 22301 certification

  • Flexible Engagement: Remote documentation review + optional on-site testing

FAQ

Q: How does this differ from ISO 22301 certification?
A: ISO 22313 provides implementation guidance - our assessment verifies your alignment before pursuing formal 22301 certification.

Q: What's the typical assessment duration?
A: 2-4 weeks, depending on organization size and complexity.

Q: Do you test our disaster recovery plans?
A: Yes, we offer optional tabletop exercises and simulation testing.

Q: Can this help with cyber resilience requirements?
A: Absolutely - we assess integration with IT disaster recovery and cybersecurity frameworks.

Q: Is remote assessment sufficient?
A: Remote covers documentation; we recommend on-site for crisis simulation testing.

Get Started

Ready to strengthen your organizational resilience?
[Request BCMS Assessment] [Download Continuity Checklist]

ISO 21502 – Project Management Conformity Assessment

Overview

ISO 21502 provides guidelines for effective project management. Our assessment helps organizations:

  • Evaluate project processes against international standards

  • Improve project success rates and delivery consistency

  • Enhance stakeholder confidence in project outcomes

  • Identify gaps in governance, planning, and execution

Who It's For

  • Organizations implementing or improving project management offices (PMOs)

  • Project teams seeking performance validation

  • Companies preparing for large-scale projects or tenders

  • Consultants providing project management services

Why an ISO 21502 Assessment Matters

  • Improved Success Rates: Reduce project failures through standardized processes

  • Risk Reduction: Identify weaknesses in project governance early

  • Stakeholder Confidence: Demonstrate professional project management capabilities

  • Competitive Advantage: Qualify for projects requiring proven methodologies

Scope of Our Remote Assessment

  • Process Evaluation: Review project initiation, planning, execution, and closure

  • Document Review: Assess project charters, plans, and performance reports

  • Competency Assessment: Evaluate project team skills and qualifications

  • Stakeholder Analysis: Interview project sponsors and team members

  • Improvement Roadmap: Provide prioritized enhancement recommendations

Our 6-Step Remote Assessment Process

  1. Scoping Session: Define assessment objectives and parameters

  2. Document Collection: Project methodologies, templates, and reports

  3. Virtual Interviews: Engage with project teams and sponsors

  4. Process Validation: Remote observation of project activities

  5. Findings Review: Discuss preliminary assessment results

  6. Final Delivery: Issue Conformity Assessment Certificate and report

Deliverables

  • Conformity Assessment Certificate (valid for 3 years)

  • Detailed Gap Analysis Report with executive summary

  • Project Management Improvement Plan

  • Team Competency Evaluation Report

  • Executive Presentation Deck

Why Company Certification Int.?

  • Project Management Specialists: Assessors with PMP/PRINCE2 certifications

  • Practical Recommendations: Actionable insights, not just compliance checks

  • Global Recognition: Accepted by international clients and partners

  • Flexible Engagement: Remote or hybrid assessment options

FAQ

Q: Is ISO 21502 certification available?
A: No, ISO 21502 is a guidance standard. Our Conformity Assessment provides formal recognition of your alignment.

Q: How does this differ from PMP or PRINCE2?
A: ISO 21502 is a framework standard, while PMP/PRINCE2 are methodologies. We assess against ISO's best practices.

Q: Can we assess specific projects only?
A: Yes, we offer both organizational PM assessments and individual project evaluations.

Q: What's the typical assessment duration?
A: 3-5 weeks depending on organizational size and project complexity.

Q: Do you provide post-assessment support?
A: Yes, optional implementation coaching and annual reviews are available.

Get Started

Ready to elevate your project management capabilities?

ISO 20400 – Sustainable Procurement Conformity Assessment

Overview

ISO 20400 provides guidelines for integrating sustainability into procurement processes. Our assessment helps organizations:

  • Align purchasing practices with ESG (Environmental, Social, Governance) goals

  • Meet stakeholder expectations for ethical sourcing

  • Reduce risks in supply chains

  • Improve compliance with international standards

Who It’s For

  • Corporations implementing sustainable procurement policies

  • Public sector organizations with ESG mandates

  • Suppliers aiming to meet client sustainability requirements

  • NGOs and institutions promoting ethical supply chains

Why an ISO 20400 Assessment Matters

  • Risk Mitigation: Identify unsustainable practices in your supply chain

  • Cost Savings: Optimize procurement through resource-efficient processes

  • Reputation Boost: Demonstrate commitment to ethical sourcing

  • Competitive Edge: Qualify for tenders requiring sustainable procurement proof

Scope of Our Remote Assessment

  • Policy Review: Evaluate procurement policies against ISO 20400 guidelines

  • Supplier Evaluation: Assess sustainability criteria in vendor selection

  • Process Audit: Review purchasing workflows for ESG integration

  • Stakeholder Interviews: Engage with procurement teams and suppliers

  • Improvement Plan: Prioritized actions to enhance sustainability

Our 6-Step Remote Assessment Process

  1. Scoping Call: Define assessment focus areas

  2. Document Submission: Procurement policies, supplier codes of conduct

  3. Virtual Interviews: Key personnel and supplier discussions

  4. Data Analysis: Review purchasing data and sustainability metrics

  5. Findings Workshop: Present gaps and improvement opportunities

  6. Final Report: Issue Conformity Assessment Certificate

Deliverables

  • Conformity Assessment Certificate (valid 3 years)

  • Sustainable Procurement Gap Report

  • Supplier Engagement Toolkit

  • Customized Implementation Roadmap

  • Executive Summary Presentation

Why Company Certification Int.?

  • Sector-Specific Expertise: Tailored for manufacturing, healthcare, retail, etc.

  • Actionable Insights: Clear steps to improve procurement sustainability

  • Global Standards Alignment: Complies with UN SDGs and ESG frameworks

  • Remote Efficiency: No disruption to operations

Get Started

Ready to transform your procurement practices?

FAQ

Q: Is ISO 20400 certification possible?
A: No, ISO 20400 is a guidance standard (not certifiable). Our Conformity Assessment provides formal recognition of your alignment with its best practices.

Q: How long does the assessment take?
A: Typically 4-6 weeks, depending on organization size and complexity.

Q: Can small businesses benefit from this?
A: Absolutely! We tailor assessments for SMEs with scalable solutions.

Q: What’s the difference between this and ISO 26000?
A: ISO 20400 focuses specifically on sustainable procurement, while ISO 26000 covers broader social responsibility.

Q: Do you assess suppliers too?
A: Yes, we offer supplier sustainability evaluations as an add-on service.

ISO 19011 – Management Systems Auditing Conformity Assessment

Overview

ISO 19011 provides internationally recognized guidelines for auditing management systems. Our assessment helps organizations:

  • Evaluate and improve internal audit processes

  • Ensure compliance with ISO 9001, ISO 14001, and other standards

  • Enhance audit program effectiveness

  • Train competent auditors

Who It’s For

  • Organizations implementing or maintaining management systems

  • Internal audit teams seeking performance validation

  • Companies preparing for certification audits

  • Consultants providing audit services

Why an ISO 19011 Assessment Matters

  • Improve Audit Quality: Identify gaps in your audit processes

  • Risk Reduction: Strengthen compliance with management system standards

  • Competitive Advantage: Demonstrate robust audit capabilities to stakeholders

  • Cost Savings: Optimize resources through more effective audits

Scope of Our Remote Assessment

  • Gap Analysis: Compare audit processes against ISO 19011 guidelines

  • Document Review: Audit procedures, checklists, and reports

  • Competency Evaluation: Assess auditor skills and qualifications

  • Process Mapping: Review audit planning, execution, and follow-up

  • Recommendations: Provide actionable improvement steps

Our 6-Step Remote Assessment Process

  1. Kick-off Meeting: Define scope and objectives

  2. Document Submission: Audit manuals, reports, and records

  3. Virtual Interviews: Engage with audit team and management

  4. Process Evaluation: Remote observation of audit activities

  5. Findings Review: Discuss preliminary results

  6. Final Report: Deliver assessment certificate and improvement plan

Deliverables

  • Conformity Assessment Certificate

  • Detailed Gap Analysis Report

  • Audit Process Improvement Plan

  • Auditor Competency Evaluation

  • Executive Presentation Deck

Why Company Certification Int.?

  • Specialized Expertise: Focused on management system audits

  • Practical Approach: Real-world recommendations, not just compliance

  • Global Recognition: Accepted by certification bodies worldwide

  • Flexible Engagement: Remote or on-site options available

ISO 10002 Customer Complaint Handling Assessment

Overview
ISO 10002 is the internationally recognized guidance for effective customer complaint handling. It helps organizations of all sizes and sectors implement transparent, fair, and improvement-focused processes, covering complaint receipt, investigation, resolution, and systemic improvements.

Who It's For

✔ Organizations aiming to embed customer-centric practices into their operations
✔ Companies seeking stronger customer satisfaction credentials for tenders and stakeholders
✔ Service providers, retailers, and public bodies wanting to demonstrate complaint handling excellence

Why a Complaint Handling Assessment Matters

  • Boost Customer Loyalty: Prove you value and act on customer feedback
  •  Mitigate Risks: Identify gaps in complaint resolution before they escalate
  • Win Business: Differentiate in procurement processes with independent validation
  • Drive Improvement: Get data-backed insights to enhance your processes

Scope of Our Remote Assessment

Gap Analysis

  • Compare your complaint handling against ISO 10002 principles

Process Mapping

  • Evaluate complaint channels, response times, and escalation paths

Document & Data Review

  • Audit complaint logs, policies, training materials, and resolution records

Virtual Interviews & Workshops

  • Conduct remote sessions with customer service teams and management

Recommendations & Roadmap

  • Deliver prioritized actions aligned with ISO 10002 best practices

Our 6-Step Remote Assessment Process

  1. Kick-off & Scoping Call: Define objectives and assessment parameters

  2. Document Collection: Secure transfer of complaint handling documentation

  3. Virtual Interviews: Validate implementation with relevant teams

  4. Preliminary Findings Review: Share initial observations for feedback

  5. Final Report & Certificate: Issue Conformity Assessment Certificate with gap matrix

  6. Follow-up Support: Optional implementation guidance sessions

Deliverables

  •  Conformity Assessment Certificate confirming ISO 10002 alignment
  • Comprehensive Gap Analysis Report with executive summary
  •  Tailored Improvement Roadmap with clear timelines
  •  Presentation Deck for leadership teams

Why Company Certification Int.?

  • Remote-First Expertise: Streamlined online assessment process
  • 15+ Years' Experience: Across retail, healthcare, finance, and public sector
  • Actionable Insights: Practical recommendations, not just compliance checks
  • Global Recognition: Assessments accepted by international partners

Ready to transform complaints into customer satisfaction opportunities?

ISO 27701 Privacy Information Management

WHAT IS ISO 27701 & GDPR?

Meet your stakeholders’ privacy demands. ISO 27701 builds on the principles of ISO 27001 with requirements for implementing a Privacy Information Management System (PIMS). This international standard provides organizations with guidance on privacy protection, including the management of personally identifiable information, and helps demonstrate compliance with key regulations such as the EU GDPR through a robust approach to managing information assets.

Certification to ISO 27701 leads to a stronger information security management system that properly addresses the changing requirements and expectations around privacy management and builds trust with stakeholders.

Our ISO 27701 Services

Our experts are equipped to deliver flexible ISO 27701 services through both on-site and remote sessions or as a blend of both; we’re here to work around the unique needs of your business.

SOC 2, ISO 27001, ISO 27701 & GDPR Comaprison

Understand the differences between leading security and privacy frameworks.

Feature SOC 2 ISO 27001 ISO 27701 GDPR
Developed by AICPA (American Institute of Certified Public Accountants) ISO (International Organization for Standardization) ISO (International Organization for Standardization) European Union (EU)
Focus Security, availability, processing integrity, confidentiality, and privacy of customer data Information Security Management System (ISMS) Privacy Information Management System (PIMS) Personal data protection and privacy rights
Applicability Primarily for SaaS, cloud, and technology service providers Any organization handling sensitive information Organizations managing personal data (PII) Any organization handling EU residents' personal data
Framework Trust Services Criteria (TSC) ISO 27001 Annex A controls (aligned with ISO 27002) Extension of ISO 27001 with privacy-specific controls Legal framework defining rights, obligations, and penalties
Certification Type No formal certification, only an attestation report by an independent auditor Formal certification (3-year cycle with audits) Formal certification (must have ISO 27001 first) No official certification, but organizations must demonstrate compliance
Assessment Type Type I: Point-in-time audit; Type II: Continuous assessment over time Certification with surveillance audits Certification with periodic audits (linked to ISO 27001) Self-assessment & regulatory audits by data protection authorities
Legal & Compliance Alignment Helps meet HIPAA, GDPR, CCPA, but does not guarantee compliance Aligns with NIST, GDPR, SOC 2, and other security frameworks Supports GDPR, CCPA, LGPD, and other privacy laws Legally binding in the EU, applies to businesses worldwide handling EU personal data
Audit Frequency Typically annual or per client request 3-year certification cycle with annual surveillance audits Linked to ISO 27001 audit cycle No mandatory audits, but data protection authorities can enforce compliance
Key Deliverable SOC 2 Report (Type I or Type II) ISO 27001 Certification ISO 27701 Certification Compliance documentation & evidence for regulators
Data Protection & Rights Focuses on security but does not define specific privacy rights Focuses on confidentiality, integrity, and availability of information Defines privacy-specific roles (Data Controller, Processor) and compliance requirements Grants individuals rights (access, rectification, erasure, portability, etc.)
Enforcement & Penalties No legal penalties; failing SOC 2 can lead to loss of business No direct penalties, but losing certification can impact business No direct legal penalties, but non-compliance impacts ISO 27701 certification Fines up to €20 million or 4% of global annual turnover for violations
Geographical Influence Primarily North America (U.S.) Global (ISO standards apply worldwide) Global (Designed to align with GDPR & privacy laws) EU and global businesses handling EU citizens' data

ISO 37001 Anti-bribery Management System

WHAT IS ISO 37001?

ISO 37001 certification makes you bring your organization toward a better business environment. It makes your organization be capable of complying with globally recognized anti-bribery best practices and proves your competence toward implementing and managing an Anti-bribery Management System.

The Anti-bribery Management System which is based on ISO 37001, helps your organization prevent, detect, and address bribery towards a better ethical business culture.

ISO 37001, the Anti-bribery management system, specifies measures to help organizations prevent, detect, and address bribery. These include adopting an anti-bribery policy, appointing a person to oversee anti-bribery compliance, training, risk assessments, and due diligence on projects and business associates, implementing financial and commercial controls, and instituting reporting and investigation procedures.

Any organization, large or small, can use ISO 37001, whether it be in the public, private, or voluntary sector, and in any country. It is a flexible tool, which can be adapted according to the size and nature of the organization and the bribery risk it faces.

Pages