Family 01
Information security
ISO/IEC 27001 ISMS, gap assessments, security audits and business continuity.




2017Founded in Uruguay
who we are
SORT Consulting is a Uruguayan firm founded in 2017, highly specialised in information security and cybersecurity. We understand that for many organisations cybersecurity is hard to cover without specialist support.
That is why we take a holistic approach: we work as your partner, continuously and closely, to build security solutions that are current and made to measure.
01
Services that add real value and fully meet the client’s needs and expectations.
02
Professional ethics and the highest standards of conduct in everything we do.
03
We innovate in processes, services and solutions to stay ahead of the curve.
04
We help our clients reach the highest international standards — the state of the art in each field.
our services
Family 01
ISO/IEC 27001 ISMS, gap assessments, security audits and business continuity.
Family 02
Technology governance framework and service management systems under ISO/IEC 20000.
Family 03
Anti-bribery and compliance management systems, focused on culture and reporting.
Family 04
Logistics chain security and preparation for Authorised Economic Operator status.
Family 05
Artificial intelligence management systems certifiable under ISO/IEC 42001.
service model
Essential
For organisations looking to implement and sustain an ISMS that stays current and auditable.
Advanced
For organisations moving from a reactive to a proactive posture: anticipating threats and knowing what they actually expose on the internet.
Complete
For organisations that treat security as one system, where technology, processes and people are managed with the same rigour.
why choose us
Certifications supported in Uruguay, the United States, Panama, the Bahamas and Puerto Rico.

01
Exclusive focus on information security, with ISO 27001 Lead Auditors and CISSP certification.
02
Continuous, tailored support; we join your Security Committee as one more member.
03
Management, threat intelligence, attack surface and the human factor in a single model.
04
SORT Redmine holds the management system up and makes day-to-day compliance visible.
05
Certifications supported in Uruguay, the United States, Panama, the Bahamas and Puerto Rico.
our experience

Healthcare
The first institution in its sector in Uruguay to certify ISO/IEC 27001, with no non-conformities.

Financial
ISMS implemented at head office and at a critical subsidiary, across two Caribbean jurisdictions.

Logistics
The first certified logistics operator in the country, with the ISMS maintained continuously.

Technology
One of the country’s first ISO/IEC 27001:2022 certifications, achieved in record time.
our clients











in our clients’ words
The SORT team supported us throughout the implementation of our Information Security Management System with great professionalism and solidity, and we achieved certification. We still work with them today; they are a cornerstone of our ongoing security framework.
Juan VoelkerDirectorTranslated from SpanishSORT has been with us since 2017; their team is part of the organisation by now. They earned our trust through very close support that allowed us to transform the culture of the organisation and establish security as a core pillar.
Fernando RamaDirectorTranslated from SpanishSORT helped us consolidate our Information Security Management System and achieve certification in record time. Their advice adds value to the development process of eFacturapty.
Sebastián NoguezPresidentTranslated from SpanishWe have relied on SORT’s advice since 2017 across several key processes. Together we consolidated our IT Service Management processes by implementing Redmine, and we are now developing our Information Security Plan, in which they play an active role as members of our Security Committee.
María de la Paz ArocenaHead of ITTranslated from Spanishinsights

Eighteen pages covering the risk assessment, the applicable regulatory framework and the ISO/IEC 42001 governance model. Free download.
Read more
The first certifiable standard for artificial intelligence management systems does not ask you to slow AI down: it asks you to know what is being used, who answers for it, and what happens when it fails.
Read more
How to design an integrity and compliance framework without duplicating structures, committees or documentation. What the two standards share and where they diverge.
Read morefrequently asked questions
The answers are complete below, with nothing asked in return. If your question is not here, write to us.
It depends on scope and starting maturity, but a typical project runs 8 to 14 months up to the certification audit. The gap assessment audit lets us refine that estimate with real data within the first few weeks.
The methodology is blended: visits to the organisation (on site) combined with remote work. Engagements can start immediately.
Timely answers from your internal counterparts. In our experience no more than two or three days should pass between a request for information or a document review and its response: it is the single variable that most affects the real duration of the project.
Yes. Every activity is supported by SORT Redmine, our platform for administering and controlling the management system, available on premises or in the SORT cloud.
In four independent components: the initial gap assessment audit, the monthly implementation service at the chosen level (Essential, Advanced or Complete), the internal audits, and the SORT Redmine platform. We send the detailed breakdown in the formal proposal.
Yes. We have supported certifications in Uruguay, the United States, Panama, the Bahamas and Puerto Rico, with the same methodology and blended approach.
your business partner