Lumiar
Home/ Services/ Audit and compliance assessment
SERVICE

Audit and compliance assessment

An independent assessment of whether security actually is what you think it is. Against IEC 62443, regulations such as NIS2, CRA and CER, or your own requirements.

Typical situations

If one of these sounds familiar, it is worth a conversation.

The board or group wants to know where you stand.
An inspection has been announced, and you want to find the deviations before they do.
A vendor is being prequalified, and the documentation needs assessment.
You have implemented measures and want confirmation that they work.

Delivery and method

We review the management system, technical documentation and selected systems, and interview the people who operate them. The assessment ends in a report with findings, deviations and recommendations, sorted by risk. Everything is documented, so it can be verified.

We also assist with tenders and procurement, on both sides of the table: buyers get help setting the right requirements and evaluating bids, suppliers get help sharpening their tender writing and building competitive, market-strong documentation of their own systems and solutions.

01Audit report with findings and deviations
02Assessment against the chosen reference
03Prioritised recommendations with rationale
04Review with management
METHODOLOGICAL BASIS
IEC 62443-2-1 (management)
IEC 62443-3-3 (system)
Norwegian petroleum regulations · NIS2 · CRA · CER

Scope and format

DURATION
1 to 3 weeks
depending on scope and reference basis.
WAY OF WORKING
Documents, interviews, site visit
most of it can be done remotely. Site visits are scheduled around operations.
PREREQUISITES
Access and openness
to documentation and personnel. All information is handled under NDA.

Frequently asked questions

Is this a penetration test?
No. We assess management, architecture and practice, and do not test the systems technically. If you need technical testing or spot checks, we help you scope it, commission it well and follow it up.
How disruptive is the audit to operations?
Very little. Most of it is document and interview work, and site visits are planned around operations.
Can the report be shared with clients and authorities?
Yes. It is written so it can serve as documentation towards third parties, if you wish.

Want to know where you actually stand?

Book an introductory call
ANDRE SERVICES
Risk assessment and barrier analysisSecurity architecture and IEC 62443Training and competence