Skip
NORMITIC
ISO/IEC TR 27016

Information Security Management — Organisational Economics

Guidance for the economic evaluation of information-security investments — translating security decisions into cost, benefit and risk language for management.

WHO IT'S FOR

CISOs, finance leaders and management teams budgeting security investments.

WHY NORMITIC?
  • Independent, impartial ISO/IEC TR 27016 assessment
  • Audit teams with 25+ years of management-system practice behind them
  • We only audit — we do not sell consulting to the organisations we assess
  • A written quote within 24 hours, and an audit plan you see before we start
FREQUENTLY ASKED
What is ISO/IEC TR 27016?
Guidance for the economic evaluation of information-security investments — translating security decisions into cost, benefit and risk language for management.
How long does ISO/IEC TR 27016 certification take?
It depends on your scope, sites and organisation size. After your application, Normitic issues a quote within 24 hours and plans the Stage 1 (documentation) and Stage 2 (on-site) audits with you.
How does Normitic run a ISO/IEC TR 27016 audit?
We audit against the published requirements of ISO/IEC TR 27016. The audit team is assigned on competence for your sector, and the certificate decision is made by someone independent of that team.
Response within 24h

Ready whenyou are.

A free 20-minute discovery call to map your current state, goals and certification roadmap.