Frequently asked questions
71 questions with direct answers on standards, timelines, scope and ways of working. They are the same ones that appear on each service page, gathered here so you can search them in one place.
On working with SORT
ContactHow long does an ISO/IEC 27001 implementation take?
It depends on scope and starting maturity, but a typical project runs 8 to 14 months up to the certification audit. The gap assessment audit lets us refine that estimate with real data within the first few weeks.
Is the work done on site or remotely?
The methodology is blended: visits to the organisation (on site) combined with remote work. Engagements can start immediately.
What do you need from our team?
Timely answers from your internal counterparts. In our experience no more than two or three days should pass between a request for information or a document review and its response: it is the single variable that most affects the real duration of the project.
Is supporting software included?
Yes. Every activity is supported by SORT Redmine, our platform for administering and controlling the management system, available on premises or in the SORT cloud.
How is the investment structured?
In four independent components: the initial gap assessment audit, the monthly implementation service at the chosen level (Essential, Advanced or Complete), the internal audits, and the SORT Redmine platform. We send the detailed breakdown in the formal proposal.
Do you work outside Uruguay?
Yes. We have supported certifications in Uruguay, the United States, Panama, the Bahamas and Puerto Rico, with the same methodology and blended approach.
On the firm and the team
About the firmWho will actually work on my project?
Senior consultants, not junior profiles learning on your organisation. The managing partner takes part in every project and the assigned team stays the same from start to finish: no rotation, and no layers of intermediation between the person who gathers the facts and the person who decides.
What certifications back the team?
ISO/IEC 27001 Lead Auditor and CISSP at partner level, and across the wider network PMP, ISO/IEC 27001 Lead Auditor, CISM and CEH, among others. For each project we bring in the right profile —technical, management or audit— rather than forcing the problem onto whoever is free.
Does SORT also issue the certificate?
No, and it could not: accreditation rules prevent a certification body from advising the organisation it later audits. We implement the system and support the process; the certificate is issued by an accredited body chosen by the client. That separation is precisely what makes the certificate worth something to a third party.
Which sectors and countries have you worked in?
Healthcare, banking and financial groups, logistics and postal operations, technology and electronic invoicing, fintech, manufacturing and retail. Projects have been delivered in Uruguay, the United States, Panama, the Bahamas and Puerto Rico, with the same methodology and a blended on-site and remote approach.
What happens after we get the certificate?
That is where most projects fall apart. The certificate requires annual surveillance audits and recertification every three years, and a system that is not maintained loses it. We support that stage: keeping the risk analysis current, internal audits, management review and preparation for each external milestone. Several of our clients have worked with us continuously since 2017.
ISO/IEC 27001 consultancy
View the serviceHow long does the project take up to certification?
A typical project runs 8 to 14 months. The implementation baseline is estimated at 12 months and is adjusted according to the agreed scope and the findings of the gap assessment audit.
What methodology do you use to measure the starting point?
Our own methodology, based on a maturity assessment of the 93 Annex A controls of ISO/IEC 27001:2022. Through interviews, document review and the gap assessment audit we determine how far each control is implemented on a six-level scale, which lets us plot the best plan by priority and effort.
Who carries out the internal audit?
Expert auditors independent of the advisory team. That separation is an impartiality requirement of the standard and stops whoever implemented the system from auditing their own work.
Does it integrate with management systems we already have?
Yes. The high-level structure shared by ISO standards allows the ISMS to be integrated with ISO 9001, ISO/IEC 20000-1, ISO 37301 or ISO/IEC 42001, sharing policy, risk management, internal audit and management review.
Security gap assessment
View the serviceIs it useful if we do not want to certify?
Yes, and that is the most common case. The assessment uses ISO/IEC 27001 as its frame of reference because it is complete and widely recognised, but the deliverable is a security roadmap that is useful regardless of any decision to certify.
Is it a penetration test?
No. It includes a high-level vulnerability analysis over infrastructure and systems, which is broader and shallower than a pentest. If you need a focused penetration test, we handle that as a separate engagement.
How often should it be repeated?
Annually, or whenever something significant changes: a merger, a change of critical IT supplier, a new line of business or a serious incident.
Security audits
View the serviceDoes it replace the certification audit?
No. The internal audit is a requirement of the standard and preparation for the external one, but certification is issued by an accredited certification body, which is independent of us.
Can you audit a system you implemented yourselves?
Yes, using auditors from the audit team, independent of the advisory team that worked on the implementation. That separation is what preserves the impartiality the standard requires.
Do you also audit suppliers?
Yes. Audits of critical third parties are increasingly requested, both because of contractual requirements and because of control A.5.22 of ISO/IEC 27001.
Business continuity
View the serviceWhat is the difference between a BCP and a DRP?
The BCP answers how the business keeps operating during the disruption, including manual workarounds. The DRP is narrower: how infrastructure and systems are recovered. The DRP is a part of the BCP, not a synonym for it.
Are backups enough?
No. A backup whose restore has never been tested is not a continuity control. The restore test —with times measured against the committed RTO— is what turns a backup into a real capability.
Can this be done without implementing a full ISMS?
Yes. It is a standalone project, although it fits naturally as part of the ISMS if ISO/IEC 27001 implementation is taken on later.
IT governance and management
View the serviceIs it useful for a small organisation?
Yes, if it is scaled properly. In small organisations the goal is not to create committees but to make clear who decides on technology investments and risks, and with what information. The model is adjusted to the real scale.
Can it be combined with ISO/IEC 20000-1?
Yes, and that is the usual case. Governance sets the direction and the accountability; ISO/IEC 20000-1 formalises service management. We treat them as one programme when the objective includes certification.
ISO/IEC 20000-1 consultancy
View the serviceHow does it differ from ITIL?
ITIL is a body of good practice; ISO/IEC 20000-1 is a certifiable standard with auditable requirements. They complement each other: ITIL guides the how, the standard defines what has to be demonstrated.
Can it be certified together with ISO/IEC 27001?
Yes. They share the high-level structure, so policy, risk management, competence, internal audit and management review are integrated into a single system, with combined audits.
Is it relevant for a managed service provider?
That is exactly the most common use case: for an IT provider, certification is a verifiable commercial argument in front of its clients.
ISO 37001 — Anti-bribery
View the serviceIs it mandatory in Uruguay?
It is not mandatory as a general rule, but it is increasingly requested as a requirement in public tenders, in contracts with multinationals and in international financing operations.
How does it relate to ISO 37301?
ISO 37001 addresses one specific risk —bribery— while ISO 37301 covers compliance in general. Many organisations implement 37001 first because of a concrete requirement, then extend to 37301 reusing the structure.
Does it require a full-time compliance officer?
Not necessarily. The standard requires a compliance function with authority, independence and adequate resources. In mid-sized organisations this is usually resolved with a part-time role reporting directly to the governing body.
ISO 37301 — Compliance
View the serviceWhere should we start?
With the obligations map. It is the deliverable that creates the most immediate value and, in many organisations, the first time everything that must be complied with is consolidated in one place.
How does it relate to personal data protection?
Uruguay’s Law 18.331 and the rules issued by the data protection authority are obligations that go into the map. The compliance system manages them like any other obligation, drawing on the ISMS controls where one exists.
Is it useful if we already have ISO 37001?
Yes, and the incremental effort is smaller. They share structure, compliance function, whistleblowing channel and internal audit; what is added is the breadth of the obligations universe.
AEO / ISO 28000
View the serviceWhat concrete advantage does AEO status bring?
Facilitation at customs controls —fewer physical inspections and faster clearance— and, above all, mutual recognition with the customs administrations of other countries, which carries those benefits over to export operations.
Is ISO 28000 mandatory to become an AEO?
It is not a formal requirement, but most AEO criteria overlap with the requirements of the standard. Implementing ISO 28000 organises the work and leaves the evidence ready for customs validation.
Does it only apply to exporters?
No. The status covers different actors in the chain: importers, exporters, customs brokers, carriers, warehouses and logistics operators, each with its own set of criteria.
ISO/IEC 42001 — AI governance
View the serviceDoes it apply if we only use third-party AI tools?
Yes, and that is the most common scenario. The standard distinguishes between developing, providing and using AI systems. For a user organisation the focus is on the usage policy, supplier assessment, protection of the data being entered, and human oversight of decisions.
How does it integrate with the ISMS we already have?
Naturally: they share the high-level structure, risk management, competence, internal audit and management review. What the AIMS adds is the impact assessment on people and governance of the model life cycle and its data.
How does it relate to Uruguayan regulation?
The work aligns with the National Artificial Intelligence Strategy 2024–2030 and the regulatory sandboxes promoted by AGESIC, and with the personal data protection framework of Law 18.331 supervised by the data protection authority.
Can it be certified?
Yes. ISO/IEC 42001 is certifiable by accredited bodies, under the same scheme of certification and surveillance audits as ISO/IEC 27001.
SORT Redmine
View the solutionIs SORT Redmine only for ISO/IEC 27001?
No. It is ready for any management system with the high-level structure: ISO/IEC 27001, ISO/IEC 20000-1, ISO 37001, ISO 37301, ISO 28000 and ISO/IEC 42001. When an organisation runs more than one standard, they share the same repository of documents, risks and actions instead of duplicating them.
Where is the data hosted?
Wherever the organisation decides. On premises, the platform runs entirely in your infrastructure and the data never leaves it. In cloud mode, it runs in SORT’s infrastructure, under the processing and retention terms agreed by contract.
Does it replace the document management system we already have?
Not necessarily. Many organisations keep their corporate repository for general documentation and use SORT Redmine for what the repository does not do: the life cycle of the management system —risks, incidents, actions, audits and schedule— which is where traceability gets lost.
What does it cost?
The platform is built on free software, so there is no per-user licensing. The cost covers implementation, configuration and support, and varies with the deployment mode and the number of standards in scope. It is quoted case by case from the intake form.
SORT ThreatLens
View the solutionHow is it different from a vulnerability feed?
A feed publishes everything and leaves the filtering to the client. ThreatLens does the filtering: it cross-references the flow against the organisation’s specific inventory and delivers only what affects it, with an explanation of why it matters and what action follows. In practice the difference is between hundreds of entries a month and a handful of actionable ones.
Does it cover the ISO/IEC 27001:2022 threat intelligence control?
Yes. The 2022 version introduced threat intelligence as a new Annex A control, and requires that the information collected be analysed and used. ThreatLens produces exactly that evidence: collection, contextualised analysis and documented use within the risk cycle.
Does it require installing anything in our infrastructure?
No. The service works from the declared inventory and external sources; it deploys no agents and does not access the client’s internal systems. When you also want to see real exposure from the outside, the right service is SORT ASM.
SORT ASM
View the solutionIs ASM the same as a penetration test?
No. A pentest is point-in-time and deep: it tries to exploit what it finds within a set window. ASM is continuous and broad: it does not exploit, but it permanently watches what is exposed and flags changes. They complement each other —ASM usually shows where a pentest is worth aiming— and neither replaces the other.
Can the scanning affect our services?
No. Discovery relies on public sources and non-intrusive probes, equivalent to what any search engine does. No exploits or load tests are run against the client’s infrastructure.
Why is it limited to two domains or IPs?
Because that is the scope included in the Advanced level of the service model, and it covers the usual case: the corporate domain and the main application. Organisations with a larger surface contract additional scope, quoted by the number of assets.
SORT SecurityAcademy
View the solutionDoes it work as competence evidence for ISO/IEC 27001?
Yes. The standard requires determining the necessary competence, ensuring it, and retaining documented information as evidence. Named certification per path, with date and assessment result, is exactly the record an auditor looks for against that requirement.
Can it be combined with simulated phishing exercises?
Yes, and it is the recommended approach. A controlled phishing exercise before assigning content shows where the real exposure is and allows the training to be targeted rather than distributed uniformly. After the programme, a second exercise measures whether anything changed.
How much time does it take each person?
The paths are built as short modules, a few minutes each, completed over weeks rather than in one sitting. Retention from a single two-hour annual session is markedly worse than from twelve brief contacts spread across the year.
Pioneers in the healthcare sector
Read the case studyHow long does ISO/IEC 27001 certification take in a healthcare institution?
It depends on the starting maturity and the scope, but a complete implementation and certification project in a healthcare organisation usually falls between nine and eighteen months, from the gap assessment audit to stage 2 of certification. In this case the project ran during the COVID-19 pandemic, with the team working remotely.
What does certifying with no non-conformities mean?
It means the external auditor found no breach of the standard’s requirements at stage 2 of the initial certification —neither major nor minor. It is an uncommon result: the usual outcome is to close the audit with some minor non-conformities that the organisation must resolve before receiving the certificate.
Does ISO/IEC 27001 cover the protection of medical records?
ISO/IEC 27001 is not a healthcare-specific standard, but its risk analysis and controls apply to the information assets the organisation defines within its scope, medical records included. In Uruguay it is complemented by Law 18.331 on personal data protection, which treats health data as sensitive data with reinforced requirements.
Global financial group
Read the case studyDoes ISO/IEC 27001 help with the SWIFT security framework?
It does not replace it, but it makes it much easier. The SWIFT Customer Security Programme requires specific controls over the messaging environment; an ISO/IEC 27001 ISMS already provides the governance, risk analysis, access management and evidence that framework requires, so the annual attestation stops being an isolated exercise and rests on a system that is already running.
Can only part of the group be certified?
Yes. ISO/IEC 27001 is certified against a declared scope, which can be a process, a business unit or a specific entity. It is common to start with the process or entity with the greatest exposure and extend the scope in later cycles, provided the interfaces with what is left out are identified and treated.
What does certifying a hosting, colocation and DRP service involve?
It means the scope covers not only the organisation’s own information but that of the clients it hosts, with additional demands on physical security, segregation, capacity management and continuity. The disaster recovery plan stops being a document and becomes a proven capability, with periodic tests whose evidence is audited.
Leading postal and logistics operator
Read the case studyDoes ISO/IEC 27001 certification reduce client audits?
In practice, yes. A certificate issued by an accredited body answers in a standardised way what each client asks separately in its supplier questionnaires and audits. It does not eliminate every review —a client may request additional evidence about its own service— but it significantly reduces their frequency and scope.
What is the difference between implementing and maintaining an ISMS?
Implementation builds the system up to certification. Maintenance sustains it afterwards: keeping the risk analysis current, internal audits, management review, handling incidents and non-conformities, and preparing the annual surveillance audits and the recertification every three years. An ISMS that is not maintained loses its certificate.
How is information protected in a physical logistics operation?
With controls that combine the physical and the logical: a documented chain of custody, security of sorting and storage areas, access control, confidentiality agreements with staff and third parties, and sustained awareness. In logistics the most exposed link is almost never the server: it is the point where information changes hands.
Certified electronic invoicing in Panama
Read the case studyWhat changed in ISO/IEC 27001:2022 compared with the 2013 version?
Annex A went from 114 controls across fourteen domains to 93 controls grouped into four themes —organisational, people, physical and technological— with five attributes that allow them to be filtered. Eleven new controls were added, among them threat intelligence, cloud services security, configuration management, information deletion, data masking, data leakage prevention and secure coding.
How much can an ISO/IEC 27001 certification be accelerated?
The limit is evidence: the standard requires the system to have been operating —at least one internal audit cycle, a management review and process records— before stage 2. An organisation with already mature processes can cover that ground in a few months; one starting from scratch will rarely do it in under a year, because there is no way to manufacture operating history.
What is a Qualified Authorised Provider (PAC) in Panama?
It is a company authorised by Panama’s tax authority to validate and transmit electronic tax documents on behalf of taxpayers. Because it acts as an intermediary for third-party tax information, its exposure and its responsibility in information security are considerably greater than those of an ordinary software provider.
Consumer lending fintech
Read the case studyWhat security requirements apply to accessing the central bank credit risk database?
Access to credit risk information is restricted to authorised entities and subject to the confidentiality established by central bank regulation, in addition to the obligations of Law 18.331 on personal data protection. In practice it requires named user access control, traceability of every query, safeguarding of the data, and a management framework that sustains all of it verifiably.
Does a fintech need to certify ISO/IEC 27001?
Not always as a legal obligation, but increasingly under pressure from the chain: correspondent banks, payment processors and data sources demand evidence of a security framework. Implementing the system and certifying it are separable decisions: some organisations implement out of operational necessity and certify later, when the certificate starts to have commercial value.
Manufacturing and retail
Read the case studyShould we certify ISO/IEC 27001 or run an assessment first?
Unless there is a contractual requirement with a deadline, it is better to assess first. The gap assessment audit costs a fraction of a certification project, measures the real distance to the standard, and lets you decide with data whether the certificate justifies the investment or whether executing the improvement plan is enough.
What does a security gap assessment include?
A management assessment —policies, roles, processes, third-party management, continuity— and a technical one, with a high-level vulnerability analysis of the exposed surface. It closes with a report that ranks the gaps by risk and effort, and with a set of immediate actions the organisation can execute without waiting for the full plan.
