Consulting

Are you ready for ISO 27001 certification?

Whether you need to obtain certification, have received customer requirements, or want to take a more structured approach to information security, we’ll help you get a clear picture of your situation. We’ll assess your current level, identify the most significant gaps, and show you which initiatives will deliver the greatest value.

Consultation with a specialist

With us, you get more than just a report. You get an experienced specialist who will guide you through the results, answer your questions, and help you make the right decisions. We’re by your side throughout the entire process—from the initial consultations to the subsequent implementation, if you need it.

Preliminary Analysis / GAP Analysis

Maturity Assessment

Getting Started

We will assess your current information security practices and compare them with the requirements of ISO 27001.

GAPs

Review

We will review your existing policies, processes, controls, and documentation to identify any gaps.

Risk Assessment

Mapping

We assess the organization’s most critical information assets and risks and identify the areas where security should be strengthened.

Action Plan

Clarification

You will receive a prioritized action plan with specific recommendations so that you know exactly which activities need to be carried out to comply with ISO 27001.

Learn more about ISO 27001 certification

Start with a no-obligation consultation with one of our experts, or purchase a preliminary analysis starting at 10,000 DKK

Why Conduct a Preliminary Analysis?

Get the big picture before you invest

An ISO 27001 preliminary analysis provides you with a clear picture of your current level of security and the areas that require attention. You’ll gain a solid basis for decision-making, a prioritized action plan, and an effective starting point for establishing or further developing an information security management system.

Get a quote for a full ISO 27001 certification process

Includes, among other things,

WorkshopAnalysisReportReviewAction PlanAnnual Cycle
Book a free consultation

The conversation is non-binding

Get an overview of an ISO 27001 gap analysis

The First Step Toward ISO 27001 Certification

Send us an email to get a free 15-minute overview of ISO 27001 with one of our cybersecurity experts. 

By submitting your email address, you agree to our privacy policy and consent to being contacted by nesp.ONE.

View upcoming courses and webinars

Learn how your company can strengthen cybersecurity and achieve compliance with standards such as ISO 27001, NIS2, and CRA.

NIS2 for management 

Copenhagen / August 26, 26

ISO 27001: Certificate Course

Copenhagen / September 2–3, 2026

NIS 2 in Practice

Odense / September 10–11, 2026

ISO 27001: Certificate Course

Copenhagen / Oct. 7–8, 2025

Preliminary Analysis – ISO/IEC 27001

En ISO/IEC 27001-foranalyse giver indblik i, hvor organisationen står i forhold til kravene i standarden. Den identificerer de områder, hvor der er behov for forbedringer, og danner et solidt grundlag for det videre arbejde med informationssikkerhed og en eventuel ISO 27001-certificering.

What does Nesp.ONE's preliminary analysis include?

One of the first steps is to define the scope of the project. Among other things, this involves determining whether the certification should cover the entire organization or only selected parts of it. At the same time, an assessment is made of how information security is organized, including management’s commitment and the allocation of roles and responsibilities.
Organisationens arbejde med risikostyring gennemgås med fokus på, om informationsaktiver er identificeret, relevante risici vurderes systematisk, og passende sikkerhedsforanstaltninger er etableret.
The existing documentation is compared with the requirements of ISO/IEC 27001. This includes, among other things, information security policies, access control policies, procedures, and other documentation that supports the organization’s information security.
Der ses på, hvordan organisationen arbejder med awareness og uddannelse inden for informationssikkerhed, samt om ledelse og medarbejdere har de nødvendige kompetencer og kendskab til virksomhedens politikker og procedurer.
Foranalysen omfatter også organisationens styring af leverandører. Det inkluderer blandt andet risikovurdering af leverandører, kontraktuelle sikkerhedskrav og dokumentation af leverandørernes sikkerhedsniveau, eksempelvis gennem ISO/IEC 27001-certificering eller ISAE-erklæringer.
Organisationens evne til at håndtere informationssikkerhedshændelser og opretholde kritiske forretningsprocesser vurderes. Det omfatter blandt andet rapportering, inddæmning, genopretning og beredskabsplaner.
Technical security is assessed through interviews and a structured questionnaire. The focus includes endpoint security, backup, identity and access management, multi-factor authentication (MFA), network security, and encryption.
Den fysiske beskyttelse af organisationens informationsaktiver gennemgås. Det omfatter blandt andet adgangskontrol, sikring af tekniske installationer, servere, netværksudstyr og øvrige områder, hvor kritiske informationer opbevares eller behandles.

What do you gain from the preliminary analysis?

After gathering information, we prepare a preliminary analysis report that provides an overall picture of the company’s current level of maturity in information security.
The report describes the identified nonconformities with respect to ISO/IEC 27001 and includes specific, prioritized recommendations for the next steps. It provides a solid basis for decision-making, whether the goal is ISO 27001 certification or a general strengthening of the company’s information security.
Preliminary analysis starting at 10,000 DKK. Contact us

Strengthen Your Cybersecurity with the Right Advice

Enter your email address here, and we'll contact you personally with the best possible solution for your business—we look forward to helping you.

Preliminary analysis starting at 10,000 DKK – price subject to the size of the company.

By submitting your email address, you agree to our privacy policy and consent to being contacted by nesp.ONE.