Pillar C — Audit / Strategic Advisory

This pillar covers strategic audit engagements that typically run longer than the first two pillars — from a multi-week ISO quickcheck through to a 12-month preparation project. I am a preparation consultant, not a certification body: TÜV, DEKRA or VdS perform the final certification audit; I bring you to the level those final auditors require.

When this pillar fits

  • ISO 27001 preparation — major customer requires the certificate, or own initiative for market differentiation
  • TISAX (automotive) — supplier obligation in the German automotive industry
  • Sector-specific light audit — hospitality, medical practice, SME with a concrete audit trigger
  • In-house seminar — SME with its own IT department wants methodology transfer

Sub-services

ServiceTriggerPriceLead time
ISO 27001 quickcheck (“is it worth it?”)pre-investment clarityEUR 2901 week
ISO 27001 preparation projectafter positive quickcheckEUR 8000–250006–18 months
TISAX quickcheck (automotive)supplier requirementEUR 2901 week
TISAX preparation projectafter positive quickcheckEUR 5000–150004–12 months
Sector-specific light auditconcrete audit triggerEUR 9902 weeks
Incident report (authority / insurer)post-data-breach reportingEUR 690–14901–2 weeks
In-house seminar (4 hours)SME with internal IT departmentEUR 1500–3000as agreed
Industrial-day workshop (7 hours)industrial deep dive with site visitEUR 3500–7000as agreed

→ Detail in Services overview.

Methodology

  • ISO 27001:2022 — current revision
  • TISAX Assessment Levels (AL1, AL2, AL3)
  • BSI IT-Grundschutz — mapped to ISO 27001
  • PDCA cycle — Plan-Do-Check-Act
  • Risk Assessment Matrix per ISO 27005

Differentiation

  • vs. Big Four (KPMG, EY, Deloitte): approximately one third the cost, faster, personal
  • vs. TÜV / DEKRA certification bodies: I am a preparation consultant, they are the final auditors — complementary, not competitive
  • vs. ISO consultants without IT depth: I understand technical measures, not just documents
  • vs. IT consultants without ISO knowledge: TÜV methodology plus 29 years of tool practice

Credentials

  • CompTIA Security Analytics Professional (CSAP) — audit methodology
  • CompTIA CySA+ — Cybersecurity Analyst
  • TÜV Rheinland IT Security Manager — synergy
  • PSM I (Scrum) — project-management methodology
  • 29 years of IT practice — junior developer through senior fullstack architect
  • Multi-sector experience: hospitality IT, medical-practice IT, metallurgical plant infrastructure, food-industry quality control

→ Detail in Certifications.


Discovery call

For audit engagements, the quickcheck is the entry point — EUR 290, one-week lead time, then a clear go/no-go decision on a full project. No upfront 12-month commitment.

Book a slot · or email alex@alex-sokolov.de