SaaS and technology
Demonstrable security for B2B customers, cloud providers, MSPs, and product teams.
We accompany companies that need to be certified, respond to customer demands or convert information security into a maintainable and proportionate system.
Especially useful if an enterprise client requires it, you want to sell more trust, you handle sensitive information or you need to organize controls before growing.
Demonstrable security for B2B customers, cloud providers, MSPs, and product teams.
Protection of customer information, contracts, confidential data and continuity.
Companies that combine ISO 27001 with ENS, NIS2, DORA or contractual requirements.
A proportionate system, without oversizing documentation or impossible controls.
We do not sell individual templates. We build the system with justified, evidence and responsible decisions.
Certification fails when the documentation is not used. That's why we prioritize clarity, ownership and follow-through.
A simple roadmap for management, IT and audit to understand what is being done and why.
Context, scope, gaps and quick wins.
Weeks 1–4 · Initial reportAssets, threats, impact and treatment.
Month 2 · MatrixTechnical and organizational measures.
Months 2–4 · SoARecords, training, incidents and audit.
Months 4–6 · ISMS FolderCorrective actions, internal audit and monitoring.
Continuous · Annual planIndicative proportion of work in an SME, according to our experience accompanying implementations. The diagnosis adjusts to your case.
We define a coherent route when there are public contracts, regulatory requirements or the need to validate technical controls.
If you provide services to the Administration, we review what controls and evidence can be coordinated.
See ENS adaptation →Risk, supplier, incident and continuity management may require a common roadmap.
See NIS2 preparation →The auditor does not accept empty policies. We complement the ISMS with real pentesting: applications, APIs and infrastructure, with a technical and executive report.
See pentesting →We are not a certifying entity: we prepare the system, the evidence and the internal audit for an independent evaluation.
The price depends on the actual scope: headquarters, systems, people and maturity. After the diagnosis we give you a final written figure.
Gap analysis, ISMS scope, gaps and prioritized roadmap. The honest starting point before committing to an entire project.
Price closed after initial call
Request diagnosis →From diagnosis to audit: risks, SoA, policies, evidence, training and support before the certifying entity.
Budget by scope
Request proposal →Maintenance of the ISMS, annual internal audits, continuous improvement and support in certificate renewals.
Fee according to support level
Talk about maintenance →Answers designed to decide scope, times and internal effort.
In an SME it usually takes between 4 and 9 months from the diagnosis to the certification audit, depending on scope, maturity and internal availability. The initial diagnosis (3-4 weeks) allows it to be limited with a closed figure.
The certification is issued by an independent certifying entity. Blue Moon prepares the ISMS, evidence, internal audit and support. In addition, part of our team has the AENOR ISO 27001 Lead Auditor certification, which provides an expert vision of the certification process.
It depends on the objective. ENS and ISO 27001 share controls and evidence, but respond to different frameworks. They can work together to avoid duplication.
Information on processes, assets, suppliers, managers, incidents, existing controls and availability to validate decisions.