Ready before the auditor knocks.
For banks, payment companies and licence applicants. We find the gaps against the CBI Cyber Resilience Controls, ISO 27001 and PCI DSS, close them with you, and build the evidence your auditor will ask for.
- Reform standards
- Audit cycle 1
- Technical audit cycle
- Final validation
The Central Bank has set the sequence. Reform standards, two audit cycles and a final validation follow, in that order. We prepare you for the technical audit cycle.
The frameworks we prepare you for
CBI Cyber Resilience Controls
The Central Bank wrote the checklist. We work through it with you.
Banking-reform technical audit
The technical audit cycle is coming. We prepare you for it.
ISO/IEC 27001
ISO 27001, implemented in Baghdad, ready for the certification body you choose.
PCI DSS
PCI DSS readiness for payment companies and merchants that accept cards.
- We prepare you for:
- CBI Cyber Resilience Controls
- ISO/IEC 27001
- PCI DSS
- SWIFT CSP
- NIST CSF
- COBIT 2019
Who signs what
What DigiFort signs
- Gap register
- Readiness scorecard
- Remediation plan
- Evidence pack
- Mock-audit report
What a CBI-approved third party or QSA signs
- Third-party assurance under the Booklet
- The Report on Compliance (RoC)
We are your readiness partner ahead of the CBI-approved auditor. The firm that prepares your evidence does not sign assurance on it — that separation is yours to keep and ours to respect.
Our method
- IdentifyScope, gap register and readiness scorecard
- ProtectRemediation plan, with an owner and a date for each item
- DetectTest findings and a review of logging and monitoring
- RespondIncident-response plan, playbooks and a tabletop exercise
- EvidenceEvidence pack and mock-audit report
Banks: how a confidential engagement runs
Supplier registration with your procurement is usually the first step; then request the pre-qualification pack.
- Supplier registration
- NDA (yours; ours on request once available)
- Scoping
- Proposal in your tender format
- Gap register
- Remediation
- Evidence pack
Payment companies and applicants
A fixed-scope readiness assessment. You receive:
- Licence-checklist mapping
- Penetration-test scope
- Policy-set gap
- Incident-response-plan gap
- Remediation plan
Fixed scope; the quote follows the scoping call.
Boundaries
This is not a certification audit and not a PCI DSS assessment; a certification body and a QSA do those parts.
FAQ
Where is our data handled?
Agreed with you in writing before the engagement starts: where each deliverable is stored, in which region, who can open it, and how it is handed back or deleted when we finish.
Can you also sign the assurance?
No; a CBI-approved firm signs assurance, and we prepare you for it.