Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

Audit and assessment

Audit services: internal, supplier and readiness audits

Short, bounded engagements that produce a scored report and a prioritised action plan. Every audit is conducted personally by our founder, a Lead Auditor in six ISO standards who has been the accountable party in internal and external audits — and knows what a certification body will actually accept as evidence.

Internal auditSupplier auditReadiness reviewNIS2 gap assessment
In brief

What kinds of audit are there?

Management system audits come in three kinds. A first-party audit is an internal audit, which every ISO management system standard requires before and between certification cycles. A second-party audit is performed by or for a customer on its supplier — the route NIS2 Article 21(2)(d) points to for supply chain security. A third-party audit is the certification audit carried out by an accredited certification body. Infosec Academy performs first- and second-party audits and readiness reviews; it does not perform certification audits.

Why it matters

Four audit services

Internal audit

A full internal audit against ISO/IEC 27001, 27701, 22301, 20000-1, 42001 or ISO 9001 — single or integrated — with programme, plan, findings and corrective action follow-up. Often outsourced by organisations without a qualified internal audit team.

Supplier security audit

A second-party audit of a critical supplier against your contract, NIS2 Article 21(2)(d) and ISO/IEC 27001 controls. For suppliers in Türkiye, conducted on site and in Turkish.

Pre-certification readiness review

A mock audit before Stage 1 or Stage 2: documentation, records and interviews tested the way a certification body will test them, so findings are closed before they are raised.

NIS2 gap assessment

A structured assessment against the national act — for example the Slovak Decree 227/2025 or Romania’s GEO 155/2024 — and ISO/IEC 27002 controls, scored and prioritised.

How we deliver

The assessment engagement model

Short and bounded, with a defined scope and a defined output.

  1. Scope and criteria

    What is audited, against which standard, contract or national act, and at which sites.

  2. Planning and document review

    Audit plan, sampling approach and a review of the documented system before fieldwork.

  3. Fieldwork

    Interviews, observation and evidence sampling — on site where it needs to be, remote where it does not.

  4. Finding classification

    Nonconformities, observations and opportunities for improvement, each tied to a requirement and evidence.

  5. Scored report and action plan

    A scored report with a prioritised action plan, presented in a closing meeting.

  6. Follow-up verification

    Optional verification that corrective actions have been implemented and are effective.

Engagement summary

Engagement model
Assessment — short, bounded, fixed scope
Output
Scored report and prioritised action plan
Languages
English and Turkish; report in English by default
Conducted by
Our founder personally, a Lead Auditor in six ISO standards

Our approach

  • Findings tied to specific requirements and evidence, never opinion
  • Evidence tested the way a certification body will test it
  • Integrated audits across several standards where they share a system
  • Supplier audits on site in Türkiye, in Turkish
  • Objectivity preserved where we contributed to the system
What you receive

What you receive

  • Audit plan and sampling approach
  • Opening and closing meeting records
  • Scored audit report
  • Finding register with requirement and evidence references
  • Prioritised action plan
  • Management summary for the board or management body
  • Supplier audit report for your third-party risk file
  • Follow-up verification note (optional)
Neutrality

What we do not do — and why it matters to you

We are not a certification body

Certificates are issued by accredited certification bodies. Under ISO/IEC 17021-1 a certification body may not provide consultancy to the organisations it certifies — and we keep the same separation from our side: we never take part in the certification audit of an organisation we have advised. Our audits are first-party (internal) and second-party (supplier) audits, and readiness reviews that prepare you for the certification body’s audit.

Where we built part of the system ourselves, we say so at scoping and structure the internal audit so that no one audits their own work.

First-party

Internal audit on your behalf, against the standard and your own requirements. Required by every ISO management system standard.

Second-party

Supplier security audit on behalf of a customer, against contract terms, NIS2 Article 21(2)(d) and the relevant standard.

Third-party

Certification audit by an accredited body. Not something we perform — we prepare you for it and support you through it.

Frequently asked questions

Questions we are asked

Can you do our internal audit if we built the system ourselves?

Yes, and that is the cleanest arrangement. An external internal auditor brings objectivity and the perspective of someone who knows what certification bodies look for. The audit satisfies the internal audit requirement of the standard and produces the records the certification body will ask to see.

What is a pre-certification readiness review?

A mock audit before the certification body arrives. We test documentation, records and interviews the way the Stage 1 and Stage 2 auditors will, classify what we find, and give you a prioritised list to close beforehand. It does not replace the certification audit and does not guarantee its outcome.

Can you audit our supplier in Türkiye?

Yes. We conduct second-party security audits of Turkish suppliers on site and in Turkish, against your contract, NIS2 Article 21(2)(d) and ISO/IEC 27001 controls, and report in English. Where the audit reveals contract gaps, we can remediate the contract too.

Do you carry out certification audits?

No. Certification audits are performed by accredited certification bodies, and we never take part in the certification audit of an organisation we have advised. That separation is what keeps both our advice and your certificate credible.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.