SECaaS.IT

The PRISM difference

The auditor is already in the package.

Others leave you searching for a certification body at the end. In the PRISM Certified package the auditor is planned in from the start — with a fixed date and fixed price. That is one reason why our customers are certified in an average of 3 months.

1

Scheduling

The audit date is fixed early in the project — the target date is set before you implement the first measure.

2

Pre-audit

The auditor reviews your evidence in PRISM in advance — surprises in the certification audit are eliminated.

3

Certification audit

Stage 1 and Stage 2 according to the standard — documents, dates and findings all run through the platform.

4

Certificate & surveillance

After certification, PRISM accompanies the surveillance audits in operations mode.

Frequently asked: is this independent?

Yes — and this is formally safeguarded. The model was aligned with and confirmed by the Chamber of Public Accountants. You conclude the contract for the certification audit directly with the independent audit firm (here: BFMT Wirtschaftsprüfungsgesellschaft) — not with SECaaS.IT. The separation of consulting and auditing is thus fully maintained, both legally and organisationally.

What we take off your hands is the search, the scheduling and the price negotiation: one point of contact, one fixed price, one target date.

Standards & Frameworks

Auditing — which standards?

Our accredited auditors cover the most common standards.

ISO/IEC 27001:2022

ISMS — Information Security Management System

BSI C5 (2020 & 2026)

Cloud Security Catalogue Type 1 & Type 2

TISAX (VDA ISA 6.0)

Assessment Level 1, 2 & 3

ISO 9001:2015

Quality Management System

ISO 14001:2015

Environmental Management System

ISO 50001:2018

Energy Management System

For auditors & certification bodies

Work as an auditor with PRISM Audit.

PRISM Audit is built for external auditors and certification bodies: client data isolation, your own branding in the report generator, remote fieldwork without email file ping-pong. If you are an accredited auditor looking to cooperate with us or use PRISM Audit in your certification practice — we would love to hear from you.

  • Client data isolation — fully separated per customer
  • Your own branding in the report generator (PDF · DOCX)
  • Remote fieldwork — no email file collection
  • TISAX workflow, IIA standards, ISO 27001 natively
  • API access for your own integrations

Certificate with a target date, not an open-ended project.

In the initial call we give you a realistic audit date for your scope.