Certification readiness
Walk into the auditreadyevidence in hand.
ISO 27001, GDPR, HDS, Qualiopi. We measure the gap between what you do and what the standard asks for, then help you close it: risk analysis, policies, technical controls, evidence. The certificate comes from an accredited body, not from us.
The standards we prepare you for
They overlap. A well-built ISO 27001 management system is the foundation for HDS, and much of your GDPR documentation draws on it.
ISO 27001
The standard for an information security management system. Scope, risk analysis, choice of Annex A controls, Statement of Applicability. Certification takes a two-stage audit, then a surveillance audit every year and recertification every three years.
GDPR
No GDPR certificate is the accepted benchmark: what you'll be asked for is evidence of compliance. Record of processing, impact assessments, contracts with your processors, retention periods, a breach procedure (72 hours to notify the CNIL, France's data protection authority).
HDS
France's mandatory certification for hosting personal health data on behalf of others. The framework builds on ISO 27001 with health-specific requirements. Depending on what you run yourself, it applies to you directly or goes through your host. Settling that question comes first.
Qualiopi
France's quality certification for training providers, required for your courses to be funded by an OPCO, France Travail or the CPF. The auditor checks, evidence in hand, how you design, run and assess your courses. We prepare the file with you, and Qualiomatic, the software we publish for training providers, keeps it up to date session after session.
What never changes
We don't certify anyone
FI-DATA is not a certification body and doesn't promise you the certificate. We get you to the audit with the work done and the evidence filed.
The documents are yours
Written for your organisation and kept up by your teams. A system that only lives through the consultant rarely survives the surveillance audit.
We know how to say no
If your client doesn't really require a certification, we'll tell you. A well-completed security questionnaire is sometimes enough.
From gap to audit
The order matters: without a risk analysis, your policies won't hold up for long in front of the auditor. An audit always comes down to proving, document by document, that you do what you say.
- Step 1
Gap analysis
What the standard requires, what you already do, what's missing. A written table, requirement by requirement.
- Step 2
Risk analysis
Your assets, the threats, the controls in place. It justifies every control you choose, and the auditor will read it closely.
- Step 3
Policies & documentation
Security policy, procedures, registers. Written for your organisation, not copied from a template nobody follows.
- Step 4
Technical controls
Access management, encryption, logging, backups, patching. For this part we rely on our technical audit.
- Step 5
Audit preparation
A mock audit, evidence you can find in two clicks, interviewees briefed. We also help you compare certification bodies and set a realistic date.
Our other areas of expertise
The technical side of a certification is often handled through an audit, and evidence is easier to produce when your processes are in order.
Audit · pentest · bug bounty
Code quality, technical debt, risks, backups and disaster recovery. Penetration tests and bug bounty programmes.
Agile · Git · CI/CD
Rituals, branching, code review, continuous integration, automated tests, documentation, metrics.
Positioning · tools · quotes
Positioning, brand image, community management, choosing tools and suppliers, second opinion on a quote.
Tell us which standard, and by when.
Describe your situation in a few clicks. On a first 30-minute call, free and with no strings attached, we'll tell you whether the timeline is realistic.