Madrid · Domestic and International Service info@imts.es
ES / EN / PT
ICT Framework Consulting and Implementation

ISO 27001 · ENS · TISAX
ISO 22301 · ISO 20000.
We implement these standards rigorously, without unnecessary red tape.

We support companies and organizations throughout the entire process of implementing and obtaining certification for the leading standards in information security, business continuity, and IT service management. This is a specialized, results-oriented service tailored to the specific needs of Spanish organizations.

STANDARD DELIVERY TIME
12 to 18 months
MINIMUM TERM
6 months
TEMPLATE
PDCA · ISO/IEC
SUPPORT
Until certification
Why now?

The regulatory and competitive landscape has changed irrevocably.

The NIS2 Directive, the DORA Regulation, the requirements of large accounts, and the requirements in public tenders have made certification a critical factor for accessing certain markets, retaining strategic clients, and demonstrating maturity in risk management.

Implementing an ICT framework is not just about passing an audit. It’s about building a solid foundation of governance, processes, and controls that protects your organization, builds trust with your customers, and gives you an edge over competitors who haven’t yet taken that step.

At IMTS, we take a practical, step-by-step approach without overcomplicating the process. Because the implementation must fit your organization as it is, not the other way around.

Programs We Have Implemented

Five standards. In-depth knowledge, not superficial.

01

ISO 27001 — Information Security

The international benchmark standard for information security management. It is the most sought-after certification in the ICT sector and an increasingly common requirement in contracts with major clients, government agencies, and financial institutions. It covers risk management, Annex A controls, asset management, access control, operations, incident management, and continuous improvement.

02

ENS — National Security Framework

Mandatory for Spanish public administrations and technology service providers that process government data or manage government systems. Regulated by Royal Decree 311/2022, it establishes categories (basic, medium, high) and mandatory compliance measures. If your company bids on public sector ICT contracts, compliance with the ENS is essential.

03

TISAX — Automotive Sector

A standard developed by the VDA and managed by the ENX Association. A requirement for OEM suppliers such as Volkswagen, BMW, Mercedes-Benz, Stellantis, and Renault, as well as for the electric and connected mobility ecosystem.

04

ISO 22301 — Business Continuity

Business Continuity Management (BCM). Identification of critical functions, assessment of the impact of a disruption, and plans to maintain operations during a crisis. Particularly relevant for the financial, healthcare, utilities, logistics, and telecommunications sectors. A natural complement to ISO 27001 and the DORA requirements.

05

ISO 20000 — IT Service Management

Aligned with ITIL. A structured framework for designing, delivering, managing, and improving IT services in a controlled and measurable manner. Suitable for MSPs, data centers, IT outsourcing providers, developers with committed SLAs, and internal IT departments seeking to demonstrate operational maturity.

Stages of the Process

Eight phases. A structure that guarantees results without overcomplicating things.

01

Diagnosis and Gap Analysis

Actual starting point. Prioritized gap analysis.

02

Planning

Scope, timeline, resources. A tailored plan, without unrealistic promises.

03

Risk Analysis and SoA

Identification, assessment, selection, and justification of controls.

04

Implementation and Documentation

Policies, procedures, and technical and organizational controls.

05

Training and Awareness

Without people to implement it, even the best system fails.

01

Internal Audit

Independent verification prior to the certification audit.

02

Support for Certification

Coordination with the organization and management of nonconformities.

03

Maintenance and Continuous Improvement

The certificate is just the beginning. Reviews, updates, and regulatory compliance monitoring.

Reasonable Deadlines

What it takes to do a good job.

This is one of the areas where we provide the most clarity. There are promises on the market of implementation within weeks or a few months that simply do not align with what is required for genuine and sustainable certification.

Nuestra posición:

  • A job well done cannot be completed in less than 6 months, and only in organizations with resources well above average, a solid starting point, and a limited scope. This is the most favorable scenario, not the norm.
  • The standard timeframe is 12 to 18 months. This is the time needed for the system to become more than just paperwork—to become an operational reality: controls implemented, procedures adopted, evidence generated, and a culture established.
  • The standard timeframe is 12 to 18 months. This is the time needed for the system to become more than just paperwork—to become an operational reality: controls in place, procedures adopted, evidence generated, and a culture firmly established.
  • Certification isn't something you can prepare for in a matter of weeks. It requires time to analyze risks in depth, implement effective controls, train the team until these practices become second nature, gather evidence throughout the operational cycle, and verify that corrections have been made.
  • If you're looking for an express certification, we're not the right provider for you. If you're looking for a solution that will last and truly protect you, let's talk.
Who Is the ICT Framework Consulting Service For?

Organizations that need certification to grow, bid on contracts, or comply with regulations.

ICT Companies and MSPs Automotive Suppliers (TISAX) Tech Startups and Scale-ups Industrial Companies Financial Sector (DORA · ISO 22301) Public Administration (ENS) Professional Firms Multi-location companies
Real Benefits

Beyond the Certificate: How an Organization Changes After Implementing an ICT Program.

Access to new markets and customers

Many companies and government agencies require certifications for hiring. Obtaining a certification opens doors that would otherwise remain closed.

Advantage in Public Bidding

ENS certification is mandatory for contracting with the government in the ICT sector. ISO 27001 and ISO 20000 are increasingly common requirements in request for proposals.

Proactive Regulatory Compliance

ISO 27001 and ISO 22301 significantly facilitate compliance with NIS2, DORA, and GDPR by sharing principles and controls.

Reduction of Operational Risk

The process identifies vulnerabilities, gaps, and exposures that already exist but are not visible. Managing them reduces their likelihood and impact.

Trust from Customers and Partners

An accredited certificate is an objective sign of maturity. It builds trust among current and potential customers.

Internal Process Improvement

Implementation structures processes, reduces reliance on key personnel, and facilitates knowledge management and continuous operations.

From Theory to Practice

A rigorous technical process, with no shortcuts. Every milestone documented, every check verified.

IMTS is not committed to selling a one-time service. It is committed to being a reliable and specialized partner in security, compliance, and intelligence. Fifteen years of supporting companies and public agencies back this up.

Would you like to know what kind of IT solution you need and how much it would cost to implement it?

Request a no-obligation consultation to discuss your needs.

We’ll get back to you within 48 hours to schedule an initial consultation. No endless forms, no prior commitments.

EMAIL info@imts.es
WEB www.imts.es/en
Seats Madrid · Domestic and International Service
Request a meeting →
IMTS specializes in consulting and the implementation of ICT frameworks. All services are provided by professionals with proven experience in the ISO/IEC 27001, ENS, TISAX, ISO 22301, and ISO/IEC 20000 standards.