CYBERSECURITY · DIGITAL DEVELOPMENT · WEB · CRM · AUTOMATION

Protect your business and build what you need to grow.

Two lines of service for companies that need to comply and protect themselves, or create a website, CRM, application and integration that advances the business with a secure technical foundation.

Initial diagnosis30 minutes to know what applies and prioritize ISO 27001:2022ISMS, SoA, audit and maintenance ENS RD 311/2022Basic, Medium, High and AAPP providers NIS2Governance, risks, incidents and supply chain AppSec and pentestingOWASP, APIs, network and executive report
01 — WHAT WE DO

Choose the path your company needs now.

Cybersecurity protects and demonstrates compliance; Digital development creates and connects the tools with which your business operates.

CYBERSECURITY

Cybersecurity and compliance

ISO 27001, ENS, NIS2, pentesting, AppSec and a controls and evidence roadmap.

See cybersecurity →
DIGITAL DEVELOPMENT

Web, CRM and automation

Corporate website, applications, e-commerce, CRM, integrations and custom digital processes.

See digital development →
02 — VERIFIABLE CREDENTIALS

Verifiable credentials, not promises.

What we say can be verified. Part of the team is certified and we work with tools that real clients use.

AENOR

Lead Auditor ISO 27001

Part of the team has the AENOR ISO 27001 Lead Auditor certification.

Meet the team →
TEST

Pentesting with actionable report

Penetration tests with agreed scope, technical and executive report, and remediation support.

See pentesting →
ODOO

Odoo CRM in production

We work with Odoo CRM and have clients who use it daily.

See CRM →
ENS

ENS in implementation

We know the National Security Scheme from the inside: we are in the certification process.

See ENS adaptation →
What we do

Cybersecurity and compliance without turning the website into a manual.

If you are asked for ISO 27001, ENS or NIS2, we start by clarifying what applies, what is missing and what is worth prioritizing.

ENS

Adaptation to the ENS

Adaptation plan for Public Administration suppliers and regulated systems.

See ENS service →
PENTEST

Pentesting

Web, APIs, network and infrastructure testing with technical and executive report.

See pentesting →
WEB

Web development

Corporate websites, platforms, e-commerce and custom integrations with technical SEO and security by design.

See web development →
TRAINING

Equipment and maintenance

Training, monitoring, corrective actions and continuous improvement after implementation.

Consult my case →
Why Blue Moon

Clarity for management, IT and audit.

We translate security requirements into decisions, controls and evidence that the team can maintain.

  • Realistic roadmap before generating documentation.
  • Combined ISO 27001, ENS, NIS2 and GDPR approach to avoid duplication.
  • Technical ability to validate with pentesting, AppSec and secure development.
Diagnosis first

30 minutes to guide scope, urgency and next steps.

Useful documentation

Policies, records and evidence intended to be used, not for decoration.

Technical security

We validate controls with testing, review and practical criteria.

Accompaniment

Implementation, audit, maintenance and continuous improvement.

Blue Moon Method

From initial doubt to an auditable route.

A short process to understand: diagnosis, risks, controls, validation and improvement.

01

Diagnosis

What applies, what is missing and what to prioritize.

Initial report
02

Risks

Assets, threats, impact and treatment.

Roadmap
03

Controls

Measures, those responsible, policies and evidence.

ISMS/plan
04

Validation

Internal audit, technical review or pentest.

Evidence
05

Improvement

Monitoring, training and incidents.

Annual plan
ISO 27001 · ENS · NIS2

What rule affects you and how to avoid duplicate work.

ISO 27001 provides international recognition; ENS is key for the Spanish public sector; NIS2 raises European standards for governance, continuity, incidents and supply chain. If they are designed together, they share controls and evidence.

CriterionISO 27001ENSNIS2
What isInternational standard for information security and ISMS.Mandatory Spanish framework for the public sector and its ICT suppliers.European directive to strengthen cybersecurity of critical sectors and supply chains.
Who appliesAny company that wants to protect information, sell more trust or access demanding customers.Public Administrations and private companies that provide services to the AAPP.Essential or important entities and suppliers that may be affected by contractual requirements.
MandatoryIt is not always mandatory, but more and more clients require it as a requirement.Yes when applied by RD 311/2022 or by public specifications and contracts.It depends on sector, size, activity and national transposition; It is advisable to analyze applicability as soon as possible.
Indicative deadline4–9 months depending on size, maturity and internal availability.3–8 months depending on Basic, Medium or High category.2–6 months for diagnosis, gap plan and first priority controls.
CombinationIt is advisable to address them in the same roadmap: inventory, risks, controls, evidence, incidents and suppliers can be reused.
Quick doubts

Short answers before diagnosis.

We leave only the essentials at home. The rest is worked on in the initial call.

Can ISO 27001, ENS and NIS2 work together?

Yes. They share inventory, risk analysis, controls, evidence, incidents, continuity and suppliers.

How do I know what I really need?

With an initial diagnosis: we review the sector, clients, tenders, obligations and current maturity.

Does the first contact have a cost?

No. The first 30-minute review is to orient the case and decide if it makes sense to move forward.

The form sends the request to a secure endpoint and takes you to a confirmation page. We also leave WhatsApp and email as a direct alternative.

ISO/ENS/NIS2 Diagnostics
DiagnosisWhatsApp