ISO 27001 and NIS2 assessments that survive auditor scrutiny.

InfosecAgent is the delivery platform for consultants and vCISO providers: structured discovery, drafted ISMS documentation, and evidence-cited assessment reports — so your team runs more engagements without adding headcount.

  • Covers:
  • ISO/IEC 27001:2022
  • NIS2
  • Greek Law 5160/2024 overlay
  • EU-deployable instances

Two paths to compliance, chosen by client maturity.

One platform meets each client where they are. The two routes run in parallel — and they never produce the same output.

Starting from zeroLower maturity — no documentation needed to begin

Scope

A three-pass structured discovery interview captures a client's actual posture — no documents required to start. Output: a gap document and a pre-filled assessment.

Document

The platform drafts a client-specific ISMS policy pack and Statement of Applicability from the discovery facts. Your consultant reviews and finalises. Built for clients starting from zero documentation.

Deliverable

  • ISMS policy pack
  • Statement of Applicability
  • Software Bill of Materials

Foundations built from zero.

Evidence in handHigher maturity — documentation ready to review

Assess

38 unified ISO 27001 + NIS2 controls (135 sub-controls), scored against uploaded evidence. Every finding cites its source document, page, and section. Targeted stakeholder interviews cover the gaps; only changed controls are rescored.

Deliverable

  • Evidence-cited gap assessment

Built on existing documentation.

Why they're separate. A client starting from zero can't be gap-assessed like a mature one — there's no evidence to review yet — so each route produces its own deliverables.

The deliverable: a report that shows its work.

Every engagement ends in an evidence-cited assessment report: compliance metrics across all 38 controls, per-domain analysis with maturity levels, and gaps traced to their root causes — each finding referencing the document it came from.

  • Scores backed by evidence, not impressions
  • Strengths and gaps stated per domain, in auditor-ready language
  • Root causes named, so remediation starts in the right place
Page from a sample InfosecAgent assessment report showing compliance metrics across 38 controls and an evidence-cited Asset Management domain analysis
From a sample assessment report — compliance metrics and evidence-cited domain analysis.

Built for firms that deliver

  • Proposals priced from facts — the sizing Bill of Materials is computed deterministically from discovery answers, not estimated
  • Every client walled off — per-client access controls inside one multi-tenant workspace for your whole practice
  • Data stays in the EU — with dedicated single-tenant instances available for clients who require them

In scope under Greek Law 5160/2024?

The law requires a designated security officer and documented, demonstrable compliance.

See how InfosecAgent supports this

See a full engagement, end to end, in 30 minutes.