ISO 27001 and NIS2 assessments that survive auditor scrutiny.
InfosecAgent is the delivery platform for consultants and vCISO providers: structured discovery, drafted ISMS documentation, and evidence-cited assessment reports — so your team runs more engagements without adding headcount.
- Covers:
- ISO/IEC 27001:2022
- NIS2
- Greek Law 5160/2024 overlay
- EU-deployable instances
Two paths to compliance, chosen by client maturity.
One platform meets each client where they are. The two routes run in parallel — and they never produce the same output.
Scope
A three-pass structured discovery interview captures a client's actual posture — no documents required to start. Output: a gap document and a pre-filled assessment.
Document
The platform drafts a client-specific ISMS policy pack and Statement of Applicability from the discovery facts. Your consultant reviews and finalises. Built for clients starting from zero documentation.
Deliverable
- ISMS policy pack
- Statement of Applicability
- Software Bill of Materials
Foundations built from zero.
Assess
38 unified ISO 27001 + NIS2 controls (135 sub-controls), scored against uploaded evidence. Every finding cites its source document, page, and section. Targeted stakeholder interviews cover the gaps; only changed controls are rescored.
Deliverable
- Evidence-cited gap assessment
Built on existing documentation.
Why they're separate. A client starting from zero can't be gap-assessed like a mature one — there's no evidence to review yet — so each route produces its own deliverables.
Built to survive scrutiny.
Findings cite sources.
Every scored control links to the evidence behind it.
Read moreUndocumented claims can't score as compliant.
A deterministic rule caps controls supported only by verbal statements — enforced in code, not in a prompt.
Read moreThe SoA is generated by rules, not AI prose.
Reproducible line by line.
Read moreThe deliverable: a report that shows its work.
Every engagement ends in an evidence-cited assessment report: compliance metrics across all 38 controls, per-domain analysis with maturity levels, and gaps traced to their root causes — each finding referencing the document it came from.
- Scores backed by evidence, not impressions
- Strengths and gaps stated per domain, in auditor-ready language
- Root causes named, so remediation starts in the right place

Built for firms that deliver
- Proposals priced from facts — the sizing Bill of Materials is computed deterministically from discovery answers, not estimated
- Every client walled off — per-client access controls inside one multi-tenant workspace for your whole practice
- Data stays in the EU — with dedicated single-tenant instances available for clients who require them
In scope under Greek Law 5160/2024?
The law requires a designated security officer and documented, demonstrable compliance.
