/certification

Certification readiness

Walk into the auditreadyevidence in hand.

ISO 27001, GDPR, HDS, Qualiopi. We measure the gap between what you do and what the standard asks for, then help you close it: risk analysis, policies, technical controls, evidence. The certificate comes from an accredited body, not from us.

The standards we prepare you for

They overlap. A well-built ISO 27001 management system is the foundation for HDS, and much of your GDPR documentation draws on it.

  • ISO 27001

    The standard for an information security management system. Scope, risk analysis, choice of Annex A controls, Statement of Applicability. Certification takes a two-stage audit, then a surveillance audit every year and recertification every three years.

  • GDPR

    No GDPR certificate is the accepted benchmark: what you'll be asked for is evidence of compliance. Record of processing, impact assessments, contracts with your processors, retention periods, a breach procedure (72 hours to notify the CNIL, France's data protection authority).

  • HDS

    France's mandatory certification for hosting personal health data on behalf of others. The framework builds on ISO 27001 with health-specific requirements. Depending on what you run yourself, it applies to you directly or goes through your host. Settling that question comes first.

  • Qualiopi

    France's quality certification for training providers, required for your courses to be funded by an OPCO, France Travail or the CPF. The auditor checks, evidence in hand, how you design, run and assess your courses. We prepare the file with you, and Qualiomatic, the software we publish for training providers, keeps it up to date session after session.

What never changes

  • We don't certify anyone

    FI-DATA is not a certification body and doesn't promise you the certificate. We get you to the audit with the work done and the evidence filed.

  • The documents are yours

    Written for your organisation and kept up by your teams. A system that only lives through the consultant rarely survives the surveillance audit.

  • We know how to say no

    If your client doesn't really require a certification, we'll tell you. A well-completed security questionnaire is sometimes enough.

From gap to audit

The order matters: without a risk analysis, your policies won't hold up for long in front of the auditor. An audit always comes down to proving, document by document, that you do what you say.

  • Step 1

    Gap analysis

    What the standard requires, what you already do, what's missing. A written table, requirement by requirement.

  • Step 2

    Risk analysis

    Your assets, the threats, the controls in place. It justifies every control you choose, and the auditor will read it closely.

  • Step 3

    Policies & documentation

    Security policy, procedures, registers. Written for your organisation, not copied from a template nobody follows.

  • Step 4

    Technical controls

    Access management, encryption, logging, backups, patching. For this part we rely on our technical audit.

  • Step 5

    Audit preparation

    A mock audit, evidence you can find in two clicks, interviewees briefed. We also help you compare certification bodies and set a realistic date.

Tell us which standard, and by when.

Describe your situation in a few clicks. On a first 30-minute call, free and with no strings attached, we'll tell you whether the timeline is realistic.

contact@fi-data.fr +33 6 35 43 81 53