Internal Security Audit & Management review

Know where you stand. Before your external audit takes place.

An internal security audit is not a box to tick. It is the moment where you find out whether your security policies and initiatives would hold up in an external audit by an independent certification body.

At Cingulum, we conduct internal security audits the same way an external auditor would. We are convinced this is the optimal way to ensure our client passes the external audit.

What is an internal security audit?

An internal security audit evaluates whether your information security management system (ISMS) or cybersecurity framework is working as it should. It checks whether your policies are being followed, whether your controls are in place, and whether you can prove it.

Every ISO standard makes an annual internal audit mandatory. Without a valid internal audit report, your external certification audit cannot proceed. For CyFun (CyberFundamentals Framework), the Centre for Cybersecurity Belgium) requires you to upload your most recent audit or assessment report as part of the NIS2 compliance process.

In short: an internal audit is not optional. The question is who does the audit, and how.

How Cingulum approaches internal audits differently

Most internal audits amount to a walkthrough. Someone asks a few questions, notes a couple of observations, and calls it done. That approach will not prepare you for an external auditor.

Ours will.

We structure our internal audits exactly as an external auditor would, using the same classification system:

This level of rigour means that when your external auditor walks in, there are no surprises. Since Cingulum started conducting internal audits, not a single client that correctly handled the findings reported during our internal audit has failed their external certification audit.

Recognise these lines from your last audit?

We collected the classic excuses auditors hear every year during internal audits. Score a bingo, and take it as your cue to adjust your approach before the external auditor does.

How we work

Our internal audits follow a risk-based methodology. That means we do not treat every clause of the standard with equal weight. Instead, we focus on the areas that matter most to your organisation. Every audit follows four structured steps.

Woman working behind her desk

We start with an intake conversation with the person responsible for your ISMS. At the same time, we collect and review the key documentation:

  • Scope definition
  • Organisational context, including interested parties, their requirements, and any significant recent changes
  • Risk register and risk treatment plan
  • Statement of Applicability (SoA)
  • Previous audit reports

This review gives us a clear picture of where your ISMS stands and which areas carry the most risk going into the audit.

Based on your risk analysis and our document review, we identify the critical business processes and information assets that deserve the most audit attention, particularly those where a failing control would have the greatest impact.

From this, we build a structured audit plan and share it with you in advance, so there are no surprises on the day.

The on-site audit combines interviews, observations during a site visit, and sample testing. We assess whether:

  • Controls are effectively implemented, not just documented
  • Risks are being managed in line with your risk treatment plan
  • Security awareness is sufficiently embedded across the organisation

At the end of the audit, we hold a closing meeting where we present an initial overview of findings, classified the same way an external auditor would:

  • major non-conformities
  • minor non-conformities
  • observations
  • opportunities for improvement
  • recognition of strong practice (where applicable) 

This is an open conversation: findings can be discussed, and if additional evidence is available that affects a classification, there is room to take that into account.

The final written audit report is delivered within two weeks of the closing meeting.

If useful, we can also present the report during your mandatory management review meeting, giving your leadership team a structured basis for decisions about the ISMS objectives going forward.

After the audit, Cingulum can assist with drawing up an improvement plan to address remaining findings, or provide support during the follow-up phase ahead of your external audit.

Which frameworks do we audit?

We conduct internal security audits across a broad range of standards and frameworks:

ISO standards

Belgian and EU frameworks and legislations

  • CyFun Basic, Cyfun Important and CyFun Essential: in line with NIS2 compliance requirements
  • DORA: Digital Operational Resilience Act, for financial institutions (banks, insurance companies)
  • NIST Cybersecurity Framework (CSF)
  • CIS Controls

Upcoming

  • CRA (Cyber Resilience Act): full enforcement from December 2027; preparatory trajectories expected from the second half of 2025 onwards
  • AI Act: Partly applicable since February 2025 with phased implementation planned until 2029
ISO 27001 vs Cyfun

ISO 27001 versus CyFun:
what is the difference?

The most fundamental difference is how conformity is assessed.

ISO 27001 applies a largely binary approach: a control either meets the requirement or it does not. This gives experienced organisations the flexibility to build an ISMS that fits their existing way of working.

CyFun uses a maturity model based on NIST CSF tiers: scoring from 1 (initial) to 5 (optimising). It is more prescriptive and includes step-by-step guidance, which makes it significantly more accessible for organisations that are just getting started.

For a more detailed comparison, including which certificate tends to suit which type of organisation, check out our eBook on CyFun vs ISO 27001

The link between internal audits and NIS2 compliance

If your organisation falls under NIS2 and is pursuing compliance via ISO 27001 or CyFun, your audit documentation is not only useful, it is required.

The CCB (Centre for Cybersecurity Belgium) requires organisations to upload:

  • Their certificate or statement of applicability
  • Their most recent internal or external audit report

An internal audit conducted by Cingulum produces exactly the documentation the CCB expects, structured to hold up to scrutiny.

Business man in a modern office

A word on independence

Internal audits only carry weight if they are conducted independently.

To avoid any bias during the audit, we maintain a clear separation between our implementation and audit team. The consultant who helps implement your ISMS does not conduct your internal audit. Where a senior expert has provided input during an implementation project, a different auditor will always take on the audit.

Curious who you’ll be working with?

Willem Magerman

Lead Auditor

Jorien Aerts

Jorien Aerts

Privacy & Information Security Consultant

Bart van Deursen

Bart Van Deursen

Senior Information Security Consultant

Frequently Asked Questions

Yes. ISO 27001 requires an internal audit before you can move to certification. Think of it as your final test run: it shows whether your ISMS works in practice, not just on paper. It’s also your best opportunity to catch and fix issues before an external auditor does, when the stakes are higher.

Fully independent, even when Cingulum built your ISMS. We assign a separate audit team with no involvement in the implementation. This separation is a requirement of the standard, and it means the findings you get are objective, not a review of our own work.

This depends on your organisation’s size and the scope of your ISMS. As a general guide, internal audits take roughly a third of the time needed for the external audit. ISO publishes guidelines on external audit duration based on company size, and in practice, most internal audits run 3 to 7 working days, from planning through to reporting.

We recommend scheduling your internal audit three months before your external audit. That buffer gives you time to:

  • Prepare the documents and processes your auditor will review
  • Address any findings properly, rather than rushing fixes
  • Align your management team on treatment plans and next steps

Leaving less time than this often means findings get patched rather than resolved, which can resurface during certification.

Yes. Depending on what the audit uncovers, we can offer guidance on how to approach a fix, or work alongside your team to implement it directly. Either way, the goal is a resolution that holds up, not just a checkbox.

Yes, it’s built for that purpose. If it helps, we can also join the meeting itself to walk your management team through the findings directly, so nothing gets lost in translation between the report and the room.

Even though we prefer to do an internal audit at the client’s location, it’s often not required. We can work remote or on site. The one exception is when Annex A.7 (physical controls) falls within the audit scope. In that case, we do need to visit your location to assess physical security measures directly.

Ready for your internal audit? Let's talk!

Een interne security audit is je laatste check voor het echte werk. Zorg dat hij je goed voorbereidt.


Cingulum does everything possible to protect and respect your privacy. You can unsubscribe from our mailings at any time. For more information about how we process your data, please read our privacy statement.