Stop doing the same work four times over.
Salvik unifies ISO 27001, ISO 42001, NIS2 and ENS with cross-mapping: define a control once and use it to cover the requirements of every framework you follow. On the Pro plan, all four at once, with AI.
7 days free · No card · Spanish and English
Pick a control and see what it covers:
Or walk into the dashboard now, no sign-upGestión de riesgos de seguridad
- 6.1Acciones para tratar riesgos y oportunidades
- 8.2Apreciación de riesgos de seguridad
- 8.3Tratamiento de riesgos de seguridad
- 6.1Acciones para tratar riesgos y oportunidades
- Art.21.2.aPolíticas de análisis de riesgos y seguridad de los sistemas
- op.pl.1Análisis de riesgos
1 control → 6 requirements · 4 frameworks
34 controls · 152 links · 4 frameworks — demo organisation
See it in the demoRSK-01 — ISO 27001: 3
All four standards, already loaded
This is not a roadmap: the requirements are in the product and you can open them right now, without signing up.
116
clauses and Annex A controls
ISO 27001
Information security
62
clauses and Annex A controls
ISO 42001
AI management
15
obligations from art. 20, 21 and 23
NIS2
Cybersecurity (EU)
72
Annex II measures
ENS
Spanish National Security Scheme
Measured in the open demo
34
unified controls
152
links to requirements
22
cover two or more frameworks
Source: the product's own requirement catalogue, counted at every build.
Salvik from the inside
Four screens from the tool. No video, no script: the interface as it is, with sample data.
Compliance dashboard
24 h / 72 h · NIS2Declared implementation
42%
110/265 requirements covered
Implemented controls
26/34
7 in progress
Open incidents
4
4 with NIS2 deadline
Open risks
9
4 high risk
Progress by framework
Attested internal audit
Automation collects evidence, but nobody puts their name to it. Salvik adds what was missing: the control review that feeds the clause 9.2 internal audit of ISO 27001 and ISO 42001 — continuous, AI-assisted and signed by a certified, impartial auditor.
Continuous assurance
The programme spreads reviews across the year instead of concentrating them in an annual sprint. It is a service commitment from the auditor, not an automation: by the time your certification audit arrives, the file is built, not started.
AI proposes, the auditor signs
AI assembles evidence and draft findings; a certified, impartial auditor — Lead Auditor ISO 27001 and ISO 42001 — reviews them, attests them and stands behind every conclusion with their signature.
Report with external timestamp
Assembled only from valid attestations and sent to an independent time-stamping authority (RFC 3161), which attests when it was issued and lets anyone check it has not been altered. If the authority does not respond, the report is still issued and its verification page states that it carries no timestamp.
Who signs, and with what credentials →
An internal audit is not a certification and does not replace one: it is your preparation for the certification audit, which is always performed by an independent body and whose outcome does not depend on Salvik.
Internal audit report
Clause 9.2 · ISO 19011
Signed standards
sha256 · 9f2c…a41bInternal signature record
Lead Auditor ISO 27001 · ISO 42001
That is a consultancy's market price, not a measurement across Salvik customers: there are none yet, and saying so matters. It is the work Salvik does with you every day for a monthly fee, across four frameworks at once rather than one. The internal audit —the cheap part, €1,000–1,200 per standard— is included and signed in the Audited plan.
All your compliance, in one place
From the first control to the audit, without duplicating work across frameworks.
From zero to audit, step by step
The complete walkthrough of Salvik with a sample company: scope and SoA, controls that cover several standards at once, evidence, NIS2 incidents, AI and a signed internal audit.
Download it freeWhat it costs to get up to speed with one standard
Implementation consultancy
€4,000–15,000
A single standard, for a Spanish SME. Market price.
With Salvik
from€47.50/month + VAT
And on Pro, all four frameworks at once: ISO 27001, ISO 42001, NIS2 and ENS.
The consultancy price is a market figure, not a measurement across Salvik customers: there are none yet, and saying so matters. The internal audit —the cheap part, €1,000–1,200 per standard— is included and signed in the Audited plan.
Plans and pricing
Base and Pro, no lock-in; Audited is billed yearly. Prices are per organisation and exclude VAT.
Base
€47.50/month+ VAT
Previously, €9550% discount
For the first 12 months; €95/month thereafter. On annual billing, €475 for the first year.
Pro
€122.50/month+ VAT
Previously, €24550% discount
For the first 12 months; €245/month thereafter. On annual billing, €1,225 for the first year.
Audited
€4,650/year+ VAT
The audit cycle runs yearly: this plan is not sold monthly.
Audit cycle included The signed internal audit of two frameworks is part of the fee, not billed separately. Extra framework: €900.
The signature is not discounted. With the offer you get the third framework signed at no cost.
| Features | Base | Pro | Audited |
|---|---|---|---|
| Frameworks on the platform | 1 of your choice | All 4 | All 4 |
| Controls mapped to requirements | Included | Included | Included |
| Cross-mapping across frameworks | Not included | Included | Included |
| Statement of Applicability (SoA) | Included | Included | Included |
| Evidence and tasks | Included | Included | Included |
| AI: policies, questionnaires and gap analysis | Not included | Included | Included |
| Regulatory watch (RegWatch) | Not included | Included | Included |
| Public Trust Center | Not included | Included | Included |
| Management review (9.3) | Not included | Included | Included |
| 9.2 internal audit, SIGNED | Not included | Not included | 2 frameworks |
| Hash-verifiable report | Not included | Not included | Included |
| Users | 1 | Up to 10 | Unlimited |
An internal audit is not a certification and does not replace one: it is your preparation for the certification audit, which is always performed by an independent body and whose outcome does not depend on Salvik.
Do you implement compliance for your clients?
We cannot sign the internal audit for a client we also consult for — that would mean auditing our own work. So we do not sell consultancy. You implement, we sign, and you earn a recurring commission on every client you bring.
Frequently asked questions
What people ask before getting started.
What is cross-mapping?
You define a control once and Salvik connects it to the requirements of ISO 27001, ISO 42001, NIS2 and ENS at the same time. Implement it once and it covers requirements across all four frameworks, with no duplicated work. Following several frameworks at once requires the Pro plan: Base and the free trial follow one. Covering a requirement is not compliance: evidence and audit are what establish that.
Which standards does it cover?
ISO 27001 (information security), ISO 42001 (AI management), NIS2 (EU cybersecurity) and ENS (Spanish National Security Scheme). Enable only the ones that apply to you.
Is it free to start?
Yes. Signing up gives you a 7-day free trial, no card required, on the Base plan: one framework, without the Pro features (AI, RegWatch, Trust Center and management review). When it ends you decide whether to subscribe; we delete nothing and you can export your data.
Is it available in English and Spanish?
The interface is in English and Spanish, and you switch languages with one click. One honest caveat: the requirement catalogues and the text the AI drafts are Spanish-only today.
How do you prove compliance?
Link evidence to each control, export your Statement of Applicability (SoA) as CSV and, on the Pro plan, share your posture through a public Trust Center and a printable executive report for customers and auditors.
Is the attested internal audit a certification?
No — and the distinction matters: certification is always issued by an independent certification body. What Salvik provides is the control review that feeds the clause 9.2 internal audit of ISO 27001 and ISO 42001, run continuously, assisted by AI and signed by a certified, impartial auditor (Lead Auditor ISO 27001 and 42001). It is your preparation for the certification audit; the outcome of that audit depends exclusively on the body performing it.
Start complying today
Create your free account and start with your first standard. All four at once, with their cross-mapping, come with the Pro plan.
265 requirements already loaded across the four frameworks
No credit card · English & Spanish
Or download the free guide «From zero to audit» (PDF, 38 pages, in Spanish)Or walk into the dashboard now, no sign-up