One counterpart for compliance work across Central Europe
One counterpart on your side, one method, one set of templates — and local delivery by whoever the local law allows.
If your group operates in several European countries, you already know the shape of the problem. Eight suppliers, eight methodologies, eight report formats — and nobody who can tell you whether it adds up. Each of them is right about their own country. None of them is responsible for the whole.
We work the other way round: one counterpart on your side, one method, one set of templates — and local delivery by whoever the local law allows.
What we do
- NIS2 and national cybersecurity acts — scoping, risk methodology, measures, documentation, self-assessment, audit where the law allows us to perform it
- ISO/IEC 27001 and ISO 22301 — preparation for certification, internal audits, the management system that has to survive it
- Data protection — data protection officer as a continuing service, records of processing, gap assessments
- EU representative under Article 27 GDPR for controllers and processors established outside the EU that are subject to the GDPR: a contact point for data subjects and supervisory authorities, help with setting up the required documentation, and support in meeting GDPR obligations — under a mandate agreement pursuant to Article 27 GDPR.
- TISAX — preparation for assessment against the VDA ISA catalogue
- DORA — register of information, ICT third-party arrangements, contractual requirements
- AI Act — what applies to an organisation that uses AI rather than builds it
- Risk analysis — methodology, register, treatment plan, acceptance of residual risk
- Training — for the roles the regulations require. Courses are currently delivered in Slovak.
Where
Group presence: Slovakia · Czechia · Poland · Hungary · Austria · Germany · Romania · Greece
Audit delivered directly by IOSEC Slovakia: Slovakia · Czechia · Poland · Greece
Elsewhere the engagement is delivered through a group partner — you keep one counterpart, one method and one set of templates.
That order is deliberate. We would rather tell you where we stop than let you find out later.
Whether an audit is required at all — and who is allowed to perform it — differs by country under NIS2. We keep a country-by-country breakdown, verified against primary sources: One directive, eight different obligations.
How one method survives eight legal systems
You cannot run one audit programme across the EU. You can run one method.
Scope definition, risk methodology, evidence structure, self-assessment and management review can be identical in every country. The audit is then a local act performed by whoever the local law allows — and because the evidence underneath it was built the same way everywhere, that local act is short.
The part that most groups underestimate is self-assessment. Several countries require it annually alongside or instead of the audit, no certificate comes out of it, and it is therefore the first thing that gets neglected. It is also the part that a group can genuinely run centrally: one method, one evidence format, one calendar.
Where our work ends
- We do not perform penetration tests or threat-led penetration testing.
- Nobody audits their own work. Where we hold the security manager role at a client, we do not audit that client.
- Certificates against ISO/IEC 27001 and ISO 22301 are issued by an accredited certification body, not by an advisor. TISAX assessments may only be performed by an ENX-accredited provider — we prepare, we do not assess.
Tell us what you are dealing with
Which countries, which regulation, and what already exists. We will tell you what we can deliver ourselves and what goes through a group partner — before you ask.