Gap analysis
We compare the controls of your target framework one by one with your current practice. Each control is marked “in place, partial, missing” and noted with its evidence.
When you prepare for a standard or regulation we make clear where to start: we measure the current state, rank the gaps and prepare policies and evidence files with you. Certification decisions belong to accredited bodies; we get you ready for that day.
We compare the controls of your target framework one by one with your current practice. Each control is marked “in place, partial, missing” and noted with its evidence.
Instead of copying a template we write documents that match how you work and that your team can actually follow. Each document has an owner and a review date.
We arrange the records an audit will ask for by control number and flag what is missing. As a last step we run a mock audit to see the surprise questions in advance.
From all controls in the framework to those ready for audit, the list gets sharper at every stage.
We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.
Each step ends with something concrete in your hands; we move on with your approval.
We examine the current state with data and find the real source of the problem.
We rank findings by impact and effort and make clear what comes first.
We write down decisions, settings and processes so that someone else can carry them on.
We review the output together and work your feedback into the next version.
What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.
Tell us what you need; we will define the scope together.
Tell us about your projectNo. Doki is not a certification body and does not issue certificates. This service prepares you for the audit; the certificate decision depends on the independent audit by the accredited body you choose.
Yes, on the security side. We run a gap analysis against the technical and organisational measures GDPR and NIS2 expect, prepare policy drafts and the incident notification plan, and help close the gaps. Legal matters such as whether you are in scope and data processing agreements are handled through your lawyer's assessment.
Yes. Only systems you are authorised for and have approved in writing are assessed.
Tell us what you need; we will define the scope together.