The questions people actually ask us.
Sorted by topic, answered without detours. Where we do not know something, or where it depends on your case, we say so — an FAQ that only confirms the sales pitch helps nobody.
Getting started
Yes. There is a 14-day trial, requested through the contact form on sightadel.com. No payment details required.
Platform, editions and roles
Per framework. You license ISO 27001, NIS2 or DORA individually, each in one of three editions. The editions differ in capacity and response time — internal users, evidence storage, monitored assets, vendors, support — not in the substance of the framework.
In practice: requirements, evidence structure and audit export are identical in Basic and Enterprise.
Setting up ISO/IEC 27001
Two things that often get confused. First, clauses 4 to 10: a management system with context, leadership, planning, operation, evaluation and improvement. Second, Annex A: 93 controls across four themes — organisational, people, physical, technological.
Organisations rarely fail an audit on Annex A. They fail on clauses 9 and 10: internal audit, management review, corrective action. That is the part you cannot buy.
Setting up ISO 9001
The customer decides that, not the standard. ISO 9001 is sector-neutral and is certified for service providers as readily as for manufacturers. The usual trigger is a tender or framework agreement that lists the certificate as a condition of entry.
Setting up NIS2
The test has two stages. First the sector: does your activity fall under the listed entity types? Second the size: from 50 employees or EUR 10 million annual turnover you count as an important entity, from 250 employees or EUR 50 million as an essential one.
Regardless of size, the obligation applies to certain entities — operators of critical installations and providers of certain digital services among them. Our NIS2 checklist includes a sheet that computes the classification.
Setting up DORA
To financial entities in the EU in the broad sense — banks, insurers, investment firms, payment institutions, crypto-asset service providers and more — and to critical ICT third-party providers serving them. The regulation applies directly, since 17 January 2025, with no national transposition.
If you supply software or operations to financial entities, the requirements reach you through the contract even though you are not a financial entity yourself.
Other frameworks
ISO/IEC 27001, ISO 9001, NIS2, DORA, SOC 2, NIST CSF 2.0, BSI C5, GDPR and HACCP, plus custom frameworks. For medical practices there is a dedicated evidence pack for Section 75b SGB V.
Evidence and documents
Anything from which a third party can tell that something was actually done — with a date and an author. Minutes, a screenshot of a setting, an approval in the ticket system, a signed sheet, a log extract.
What is not evidence: a policy that mandates something. That proves intent, not implementation. This confusion is the single most common finding in a first audit.
One piece of evidence, several frameworks
That the same fact is asked for by several frameworks and you evidence it exactly once. Access management appears in ISO 27001 Annex A, in NIS2 measure 9, in DORA's ICT risk management and in the SOC 2 common criteria. That is the same question four times.
Keeping a separate folder per framework means maintaining the same evidence several times — and having it in three different states a year later.
Audit and certification
No. ISO standards are international, and a certificate to ISO/IEC 27001 or ISO 9001 is recognised worldwide provided the issuing certification body is accredited and the accreditation body belongs to the International Accreditation Forum's multilateral recognition arrangement.
Only the legal acts are European: NIS2, DORA, the GDPR and the AI Act. Those reach non-EU providers too, as soon as they supply into the EU or process data of people in the EU. Conversely SOC 2 and NIST are US-shaped and asked for worldwide.
In short: the standard is global, the obligation is regional.
Ongoing operation and framework changes
The work that decides the outcome. A certificate is a snapshot valid for three years with two surveillance audits in between. Between audits the cycles continue: access reviews, vendor assessments, training, restore tests, management review.
The classic mistake is the pause after the first audit. It shows up in the first surveillance audit, because eleven months of evidence are missing.
Security, hosting and data protection
In Germany, with our hosting provider creoline. Development, operations and support are based here as well. No detour through data centres elsewhere, no access under foreign law.
For some of our customers that is the reason they talk to us at all — and for everyone else it is at least one question fewer in the vendor questionnaire.
Pricing, contract and billing
Per framework and edition. ISO 27001 starts at EUR 9,000 per year in the Basic edition, NIS2 and DORA at EUR 4,500, ISO 9001 at EUR 3,800, BSI C5 and GDPR at EUR 2,400, HACCP at EUR 1,800. Professional is 30 % above Basic, Enterprise 60 %. All prices net.
The full list including the edition comparison is available as a PDF in the resources section.