ISO27001,ENSandISO42001CertificationwithNexoSGSI:ThePlatformWeUsedtoCertifyOurselves

One system for all three standards: 73 controls of Spain's National Security Framework (ENS), mandatory for suppliers to the Spanish public sector, 93 from ISO 27001, and 38 from ISO 42001, with its document set, signed evidence, and the calendar of obligations that keeps them alive. We built it to certify Kiwop itself, and in August 2026 we passed the OCA Global audit on all three standards with zero non-conformities. Now we roll it out in your company: if you want to get certified, we take you through to the audit; if you already are, we take away the spreadsheet and the folders.

3 Standards in One Console
0 Non-Conformities in the Audit
12 wks From Kickoff to Audit
Scroll

Executive Summary

What Nexo SGSI is and why it exists.

Getting certified in ISO 27001 or ENS isn't hard because of the controls: it's hard because you have to prove, with dated evidence, that you meet them every week. Most companies hold it together with a consultancy, a spreadsheet, and a shared folder, and they pay for it twice: during implementation and at every surveillance audit, when nobody can find the record the auditor is asking for.

Nexo SGSI is the compliance module of Nexo, Kiwop's management platform. We built it between May and August 2026 to certify our own company on three standards at once, with no external consultancy, and the OCA Global auditor described it in the report as "an exceptional competitive advantage": the records are reliable and real-time because the system generates them as it operates. Since September we've been selling it to other companies, as SaaS or installed on their own infrastructure.

There are two ways in. Get Certified: platform, a document kit tailored to your company, and support from our team through to the certification audit, at a fixed price. Maintain: if you already have the certificate, you migrate your ISMS to Nexo and stop chasing evidence by hand. Either way, the auditor logs in with their own read-only account and finds what they're looking for.

3 Standards ENS Medium · ISO 27001 · ISO 42001
0 NC OCA Global Audit, August 2026
€11,900 Get Certified, One Standard, Fixed Price

The three standards at a glance

Audited at Kiwop by OCA Global in August 2026 with zero non-conformities. The official certification marks will be published once the certificates are issued.

ENS · MEDIUM category

Spain's National Security Framework (RD 311/2022): the 73 measures of Annex II with L0-L5 maturity and the INES report.

ISO/IEC 27001:2022

Information security: the 93 Annex A controls with a two-way Statement of Applicability.

ISO/IEC 42001:2023

AI management: the 38 Annex A controls, cross-mapped with ISO 27001.

What the Platform Does

Thirteen modules covering what an auditor asks for, and what a security officer needs so nothing depends on memory.

All three standards loaded and cross-mapped: 73 measures from ENS Annex II with L0-L5 maturity, 93 controls from ISO 27001 Annex A, and 38 from ISO 42001, with a statement of applicability in both directions
Versioned document set: policies, regulations, and procedures with approval, staff sign-off, history, and classification. You start with 33 templates tailored to your company
Evidence you can verify: every signature carries its hash, the audit trail is immutable and chained, and a single command proves it in front of the auditor
Calendar of obligations: backup reviews, committee meetings, access reviews, drills, internal audit. Generated per year, with reminders, and exportable to your calendar
Incidents, changes, and access requests with a state machine, segregated approval, the GDPR's 72-hour deadline calculated automatically, and notification to the AEPD or CCN-CERT
Vendors and assets: security requirements per vendor, expiring certifications, an asset inventory valued across five dimensions, and CSV import
Training and awareness: a plan per role, videos with verified viewing, a quiz, attendance sign-off, and phishing campaigns with results
Monitoring and correlation: readings from CrowdSec, fail2ban, or Wazuh via webhook, correlation rules, access anomalies, and a dashboard with indicators per process
Read-only external auditor account, a search engine across fourteen areas, a presentation-ready audit mode, the Article 32 INES report, and fifteen PDF reports

Two Paths: Get Certified or Stop Suffering the Certificate You Already Have

The same system, two entry points.

If you're not certified yet, Get Certified is a project with a start and an end: we set up the system with your company details, your officers, and the standards you need, we adapt the document kit with you, we support you through the weeks of operation the evidence requires (a procedure written yesterday and never applied is still a procedure with no maturity, and the auditor sees it by the date), and we reach the audit with the internal audit already done. If you already have the certificate, Maintain starts by migrating your documents and your statement of applicability into the system; from there, the calendar, the reminders, and the indicators do the work a person with a spreadsheet does today. Either way, when the surveillance auditor arrives, you hand them an account and they find everything.

nexo-sgsi/entry.yaml
# Two ways to start
get_certified:
standards: [ens_medium, iso27001, iso42001]
document_kit: 33 tailored templates
support: through the audit
price: fixed, from €11,900
maintain:
migration: documents + SoA + evidence
operation: calendar, reminders, KPIs
auditor: read-only account
price: €590/month
3 Standards
33 Templates
15 PDF Reports

SaaS, On-Premise, or for Your Client Portfolio

Where the system lives is up to you.

01

SaaS at nexo.kiwop.com

Your own workspace for your company inside Nexo, isolated from everyone else's by design (isolation is enforced server-side and covered by tests, not just trust). Onboarding in hours, daily backups, updates included. It's the option for most SMEs.

02

On-Premise, on Your Own Infrastructure

The same application, packaged in Docker (PHP, PostgreSQL, Redis) and installed on your servers or your private cloud with a single command. No AI keys, no external services: it only needs an SMTP server for notifications. Built for government bodies, public-sector suppliers, and companies whose data never leaves the building.

03

Consultancies and Auditors

If you implement ISMS for other organizations, each of your clients gets their own workspace with their own catalogues, kit, and auditor. You see all of them from a single account; they only see their own. Let's talk partner terms.

04

No Lock-In

Your documents are markdown and your records live in PostgreSQL: they export in full. The on-premise license is a contract, not a lock. If you ever leave, you take your ISMS with you.

How We Get You to the Audit

What we did with ourselves, now with your team. Twelve to sixteen weeks depending on your starting point.

01

Scope, Officers, and Category

We define the system scope with you (which services and assets are in), appoint the officers each standard requires, and, for ENS, categorize the system based on the valuation of your assets. We provision your workspace with the standards you've chosen.

02

Tailored Document Kit

We install the 33 templates with your company details, your roles, and your system, and we review them with you one by one: what you don't actually do doesn't get written down. Publishing each document is an act of approval by your management, and it stays signed.

03

Operate and Leave a Trail

This is where the audit is won. Your team accepts the policies, completes the training, logs incidents and changes, and reviews access and backups. The year's calendar drives everything, and the system stores the evidence with a date and a signature. We review the maturity of each measure every week.

04

Risks, Internal Audit, and Management Review

Risk analysis using the MAGERIT methodology on your inventory, an internal audit with a plan and findings, and a committee meeting with signed minutes that closes the cycle. We prepare the auditor's pack: statement of applicability, reports, and indicators.

05

Certification Audit

You hire the audit with whichever accredited body you prefer (OCA Global, AENOR, Bureau Veritas, Applus...). The auditor logs in with their read-only account, and we're with you throughout the sessions. Observations are handled inside the system itself.

Is It Right for You?

Nexo SGSI is built for organizations of 10 to 250 people that need the certificate to sell, not to frame it.

Who it's for

  • Technology suppliers to government bodies: ENS is a tender requirement, and MEDIUM and HIGH categories require certification by an accredited body.
  • Software, SaaS, and managed service companies whose clients already ask for ISO 27001 in every vendor approval process.
  • Organizations that develop or operate AI and want ISO 42001 before a client or a regulator asks for it.
  • Already-certified companies holding the system together with a spreadsheet and a shared folder, dreading every surveillance audit.
  • Security and compliance consultancies that implement ISMS for several clients and need a common platform.

Who it's not for

  • Anyone looking for a certificate without operating anything: the system generates evidence as you use it, and with no use there's no evidence.
  • Groups with hundreds of heterogeneous systems and their own GRC team: corporate suites fit better there.
  • Anyone who needs SOC 2, PCI DSS, or NIS2 today: Nexo SGSI covers ENS, ISO 27001, and ISO 42001; the rest is on the roadmap, not in the product.

Pricing

Fixed and published. The certification audit is contracted separately with the accredited body.

A traditional ISO 27001 implementation consultancy for an SME in Spain costs between €8,000 and €30,000 in the first year, and it keeps costing every time you have to prepare for a surveillance audit. Here the price includes the platform, the document kit, and our team through to the audit.

Start Here

Get Certified

€11,900

One standard (ISO 27001 or ENS MEDIUM category). Two standards: €16,900. All three (with ISO 42001): €21,900.

  • System provisioning with your standards and officers
  • Document kit of 33 templates tailored with you
  • Weekly support through the certification audit
  • Risk analysis, internal audit, and the auditor's pack
  • 12 months of the SaaS platform included
I want to get certified

Maintain

€590/month

For already-certified companies. Annual commitment. Unlimited users within scope.

  • Migration of your documents, SoA, and evidence
  • Calendar of obligations, reminders, and indicators
  • External auditor account for every surveillance audit
  • INES and PDF reports included
  • Updates and daily backups
Migrate my ISMS

On-Premise

€9,900

Installation on your own infrastructure. After that, €2,900/year for updates and support.

  • Docker image and deployment on your servers or private cloud
  • No external services, no AI keys
  • Initial setup and training for your security officer
  • Versioned updates throughout the contract
  • Compatible with Get Certified and with Maintain
Talk about on-premise

Certification audit not included: for an SME, between €2,000 and €5,500 depending on the body and the number of audit days. Prices exclude VAT.

Get Certified: What You Walk Away With

What's in and what's not, so there are no surprises.

Incluido

  • Your workspace in Nexo SGSI with the standards you chose loaded and cross-mapped
  • Complete document set, tailored and approved by your management
  • Statement of applicability generated from the system
  • Risk analysis (MAGERIT) on your asset inventory
  • Training plan completed and signed off by staff
  • Internal audit with a plan, findings, and actions
  • Committee minutes and management review
  • Auditor's pack: reports, indicators, and a read-only account

No incluido

  • Certification audit (you contract this yourself with the accredited body)
  • Pentesting, hardening, or equipment: these are separate services

We Proved It on Ourselves, and the Auditor Wrote It Down

The module was born on 24 May 2026. On 17 August, the OCA Global certification audit began: ENS MEDIUM category, ISO/IEC 27001, and ISO/IEC 42001, from 17 to 27 August. None of the three standards left a single non-conformity. The ENS report highlights three strengths: the implementation is in-house, with no external consultancy and visible leadership from management; Nexo as the core of the system is "an exceptional competitive advantage" that makes the records reliable and real-time; and maintenance is fully calendarized. That's the difference between an ISMS living in folders and one that's actually operated: the auditor doesn't ask for the document, they open it themselves. How the platform is built, in the Nexo case study.

3 Standards Audited at Once
0 Non-Conformities
12 Weeks from Kickoff to Audit
204 Measures and Controls Managed

Summary for the Security Officer and the CTO

How it's built and what it needs.

Nexo SGSI is a module of Nexo (Laravel + React on PostgreSQL) isolated by workspace from the very first query: every table carries its company identifier, and authorization policies resolve by security role (security officer, system officer, information officer, DPO, external auditor), not by application role. Evidence integrity isn't a promise: signatures are HMAC over the content with a dedicated key, the audit trail is hash-chained, and a database trigger rejects any deletion or modification. sgsi:verify-evidence checks it in seconds, live, in front of anyone who wants to see it.

The on-premise install is a Docker image with php-fpm, nginx, PostgreSQL 17, Redis, a scheduler, and backups, a one-screen .env, and a single startup command. The module doesn't use AI or call any external service: it needs an SMTP server and nothing else. Wazuh, CrowdSec, or fail2ban connect via webhook with a token per workspace. There's an API for incidents and vendors, iCal export for the calendar, CSV export for assets, and fifteen PDF reports with clean metadata.

What It Prevents

The four risks we see in ISMS that reach audit still living in folders.

Scattered evidence: the auditor asks for a record and nobody knows where it is

Mitigation:

Every record is born inside the system, with a date, a signature, and a link to the measure or control it evidences. The auditor's search finds it in seconds.

Procedures written and never applied (insufficient maturity)

Mitigation:

The calendar forces every activity to run, and the system records the execution. The maturity of each measure is calculated on what's done, not on what's written.

Dependency on a consultancy for every surveillance audit

Mitigation:

The knowledge stays in your system and your team. With Maintain, the annual surveillance audit means opening the auditor's account, not hiring anyone again.

Security documents in a third-party SaaS outside your control

Mitigation:

On-premise mode inside your own infrastructure, with no external services. And on SaaS, your data sits on EU servers with isolation by design.

Frequently Asked Questions

What people ask us before getting started.

Is Kiwop certified in ISO 27001, ENS, and ISO 42001?

We passed the OCA Global certification audit (a body accredited by ENAC) on all three standards, from 17 to 27 August 2026, with zero non-conformities. The certificates are issued in the weeks following the report; as soon as we have them, we'll publish their numbers and scope here. The entire management system, from the security policy to the last record, lives in Nexo SGSI.

How much does it cost to get ISO 27001 certified with Nexo SGSI?

€11,900 for one standard (ISO 27001 or ENS MEDIUM category), €16,900 for two, and €21,900 for all three, with twelve months of the platform included. The certification audit is contracted separately with the accredited body you choose: for an SME it usually costs between €2,000 and €5,500 depending on the number of days. Compare that with a traditional implementation consultancy, which costs between €8,000 and €30,000 in Spain in the first year and leaves no tool behind.

How long does it take to get certified?

We went from the module's first commit to the audit in twelve weeks, building the tool at the same time. With the platform already built, the work plan runs twelve to sixteen weeks depending on your starting point, and most of it isn't paperwork: it's operating the system so dated evidence actually exists. On top of that, you need to add the certification body's availability, which is usually a matter of weeks.

What is ENS and who's required to get certified?

The National Security Framework (ENS) (Royal Decree 311/2022) sets the security measures for systems that support Spanish public administration services, and it also applies to the companies that supply those services: tenders require it. Systems in the BASIC category can self-declare conformity; those in the MEDIUM and HIGH categories need certification by a body accredited by ENAC. Nexo SGSI carries the 73 Annex II measures with their maturity levels, the 110 HIGH-category questions, and generates the INES report.

What's ISO 42001 for if I already have ISO 27001?

ISO/IEC 42001 is the standard for AI management systems: it governs which AI you use or develop, with what data, what impact it has, and who's accountable. It shares its structure with ISO 27001 (which is why the three standards cross-reference each other in Nexo SGSI), and it's what a client or a regulator will ask of anyone operating AI. One important nuance: 42001 certification doesn't grant a presumption of conformity with the EU AI Act; that will come from the harmonized standards the EU publishes. For the regulation itself, we have a dedicated EU AI Act compliance service.

I'm already certified. What do I gain by migrating to Nexo SGSI?

You stop holding the system together by hand. We migrate your documents, your statement of applicability, and your evidence; from there, the year's calendar distributes the obligations, reminders arrive on their own, indicators log themselves, and when the surveillance audit comes around, the auditor logs in with their account and finds everything. It costs €590/month with an annual commitment and unlimited users within scope.

Can I install it on my own servers?

Yes. The on-premise mode is the same application, packaged in Docker and installed on your infrastructure or your private cloud. It needs no external service, no AI keys, and no connection to Kiwop: just a mail server for notifications. It costs €9,900 for the installation and €2,900/year for updates and support. It's the natural choice for government bodies and for systems whose data can't leave the building.

Does it use artificial intelligence?

The SGSI module doesn't use AI for anything it certifies: signatures, the audit trail, catalogues, and indicators are conventional, deterministic code, because an auditor won't accept evidence a model might have made up. Nexo's AI lives in other modules (assistant and agents); in the ISMS, AI is the object governed by ISO 42001, not the tool.

What happens to my data if I leave the service?

You take all of it with you. The documents are markdown, the records live in PostgreSQL, and the reports are PDF: they all export. On-premise, the license is contractual, with no technical lock-in. We don't sell dependency; we sell a system that works and a team that knows it.

Show Us Your Starting Point and We'll Tell You Which Week You'd Be Ready for Audit

A 30-minute video call with the people who built the system and passed the audit. No obligation: if your case doesn't fit, we'll tell you.

Request a demo
No commitment Response in 24h Custom proposal
Last updated: August 2026

Initial technical
consultation.

AI, security and performance. Diagnosis with phased proposal.

NDA available
Response <24h
Phased proposal

Your first meeting is with a Solutions Architect, not a salesperson.

Request diagnosis