ISO 42001, EU AI Act, ISO 27001 & NIS2 Compliance Consultancy | SIXE
REGULATORY COMPLIANCE · AI & CYBERSECURITY

Compliance consultancy: ISO 42001, EU AI Act, ISO 27001 & NIS2

Compliance that holds up in an audit. We get you there with an assessment, a gap analysis and a pre-audit — from the first review to the certification audit itself.

ISO/IEC 42001 — the first certifiable AI management standard. Our team is certified as lead auditor in the frameworks we support, so we speak the same language as the body that will certify you.

§

01 · The regulatory map

Four frameworks, two worlds that no longer separate.

AI and cybersecurity are now regulated together and audited with the same logic: scope it, close the gaps and prove it with evidence. These are the frameworks we support, and who they bind.

AI

ISO/IEC 42001

AI management system

Consultancy and implementation of the AI management system for organisations that build, integrate or use AI and need to prove governance to clients, tenders and regulators.

AI

EU AI Act

Regulation (EU) 2024/1689

Mandatory for anyone placing AI systems on the EU market. Risk-based governance obligations, on a timeline that has already started.

Cybersecurity

NIS2

Directive (EU) 2022/2555

Binds essential and important entities. Incident reporting within 24 and 72 hours, with direct accountability for management.

Cybersecurity

ISO/IEC 27001

Information security management

The de-facto standard clients and tenders ask for — consultancy, implementation and internal audit. The base NIS2 and much of the AI Act build on.

Does your case combine several?

Most cases span AI and cybersecurity at once. A single assessment covers every framework that applies to you, with no duplicated work.

§

02 · Regulatory pressure

Why now.

This is not a compliance fad: hard deadlines and fines on turnover. Arriving prepared costs less than arriving late.

35 M€ / 7%
Maximum AI Act fine on worldwide turnover for prohibited practices.
10 M€ / 2%
NIS2 fine for essential entities on global annual turnover.
24 / 72 h
NIS2 deadlines for early warning and full notification of a significant incident.
1st
ISO/IEC 42001 is the first certifiable international AI management standard. Adopting it now puts you ahead of your sector.

Figures as published in each framework. Confirm against the current official source before using them in sales material.

§

03 · How we work

Three steps to audit-ready.

The same method for any of the frameworks. No generic templates: the deliverable is your organisation measured against the standard, not an off-the-shelf report.

1
Assessment

Where you stand today

We measure your real maturity against the standard — the initial assessment. An honest starting point, no surprises later.

2
Gap Analysis

What is missing, in what order

Every open requirement, prioritised by risk and effort, with a roadmap your team can actually execute.

3
Pre-audit

The dress rehearsal

A mock certification audit with a lead auditor, so the real day holds no open questions.

SIXE prepares and supports; it does not certify. The certification audit is issued by an independent accredited body — for impartiality, whoever helps you implement cannot be the one who certifies you. Our lead auditor certification is your guarantee that we prepare the process to the same criteria.

§

04 · Why SIXE

We know what we are talking about.

  • A team certified as lead auditor in the frameworks we support — we do not read the standard second-hand.
  • Listed in INCIBE's catalogue of cybersecurity companies.
  • IBM, Red Hat, Canonical and SUSE Business Partner since 2009: compliance on real critical systems, not on slides.
  • The same people from start to finish, in your language, from assessment to pre-audit.
ISO/IEC 42001AI management
EU AI ActAI Act
ISO/IEC 27001Information security
NIS2EU Directive
Lead AuditorCertified team
§

Let us talk.

Tell us which framework you are facing and within days we send back an initial assessment and a proposal with the phases itemised — assessment, gap analysis and pre-audit.

+34 91 198 02 43 (UE)  ·  +1 628 900 3024 (EE.UU.)  ·  Mon–Fri 8:30–16:30 (GMT+1)