Pillar C — Audit / Strategic Advisory
This pillar covers strategic audit engagements that typically run longer than the first two pillars — from a multi-week ISO quickcheck through to a 12-month preparation project. I am a preparation consultant, not a certification body: TÜV, DEKRA or VdS perform the final certification audit; I bring you to the level those final auditors require.
When this pillar fits
- ISO 27001 preparation — major customer requires the certificate, or own initiative for market differentiation
- TISAX (automotive) — supplier obligation in the German automotive industry
- Sector-specific light audit — hospitality, medical practice, SME with a concrete audit trigger
- In-house seminar — SME with its own IT department wants methodology transfer
Sub-services
| Service | Trigger | Price | Lead time |
|---|---|---|---|
| ISO 27001 quickcheck (“is it worth it?”) | pre-investment clarity | EUR 290 | 1 week |
| ISO 27001 preparation project | after positive quickcheck | EUR 8000–25000 | 6–18 months |
| TISAX quickcheck (automotive) | supplier requirement | EUR 290 | 1 week |
| TISAX preparation project | after positive quickcheck | EUR 5000–15000 | 4–12 months |
| Sector-specific light audit | concrete audit trigger | EUR 990 | 2 weeks |
| Incident report (authority / insurer) | post-data-breach reporting | EUR 690–1490 | 1–2 weeks |
| In-house seminar (4 hours) | SME with internal IT department | EUR 1500–3000 | as agreed |
| Industrial-day workshop (7 hours) | industrial deep dive with site visit | EUR 3500–7000 | as agreed |
→ Detail in Services overview.
Methodology
- ISO 27001:2022 — current revision
- TISAX Assessment Levels (AL1, AL2, AL3)
- BSI IT-Grundschutz — mapped to ISO 27001
- PDCA cycle — Plan-Do-Check-Act
- Risk Assessment Matrix per ISO 27005
Differentiation
- vs. Big Four (KPMG, EY, Deloitte): approximately one third the cost, faster, personal
- vs. TÜV / DEKRA certification bodies: I am a preparation consultant, they are the final auditors — complementary, not competitive
- vs. ISO consultants without IT depth: I understand technical measures, not just documents
- vs. IT consultants without ISO knowledge: TÜV methodology plus 29 years of tool practice
Credentials
- CompTIA Security Analytics Professional (CSAP) — audit methodology
- CompTIA CySA+ — Cybersecurity Analyst
- TÜV Rheinland IT Security Manager — synergy
- PSM I (Scrum) — project-management methodology
- 29 years of IT practice — junior developer through senior fullstack architect
- Multi-sector experience: hospitality IT, medical-practice IT, metallurgical plant infrastructure, food-industry quality control
→ Detail in Certifications.
Discovery call
For audit engagements, the quickcheck is the entry point — EUR 290, one-week lead time, then a clear go/no-go decision on a full project. No upfront 12-month commitment.
→ Book a slot · or email alex@alex-sokolov.de