>
🇵🇹 Portugal office · HQ London, UK · Audits worldwide

International certification for information security, AI governance and privacy

BALTUM is an internationally recognised certification body and compliance group. We deliver structured, evidence-based programmes across ISO management systems, cybersecurity frameworks, and regulatory mandates. Our expert team — fluent in English and Portuguese — combines rigorous audit methodology with proprietary BALTUM tools that optimise the process and make certification competitive and predictable in cost. Certificates issued through our IAF MLA-registered partner network are recognised in 100+ countries worldwide.

🏛️ HQ: London, United Kingdom🇵🇹 Office: Porto, Portugal 🌍 On-site & remote audits worldwide✅ 15+ standards & frameworks
10+
Years of operation
6+
Accredited cert. partners
15+
Standards & frameworks
3
Continents covered

A structured path from compliance readiness to internationally recognised certification

BALTUM operates as an independent certification and compliance consultancy. We combine rigorous audit methodology with practical implementation support — enabling organisations to achieve internationally recognised certifications without operational disruption.

Our engagement model is designed to match the complexity of your regulatory environment. Whether you are pursuing a first certification or managing a multi-standard compliance programme, BALTUM provides a clearly scoped, fully documented, and auditable path to certification.

🤝

Accredited certification partners

  • Swiss Approval — Switzerland, USA
  • Tayllorcox — Czech Republic
  • Unicert — Germany
🇵🇹

Portugal — Local presence, global standards

Porto, Portugal · info@bcert.org

🏛️

Institutional memberships

  • UK Cyber Security Council
  • CREST — Registered Ethical Security Testers
  • GALA — Globalization and Localization Association
  • ELQN — E-Learning Quality Network
  • AIEI — AI Ethics and Integrity International
🎯

Outcome-driven methodology

Certifications that demonstrate measurable governance maturity, not mere procedural compliance.

🌐

Global auditor network

Qualified lead auditors with domain expertise across cybersecurity, privacy, quality, and AI governance.

📐

Scalable engagement model

Structured programmes for growth-stage companies, mid-market, and enterprise — scoped to your maturity level.

🎓

BALTUM Academy

Accredited training curricula for internal auditors, compliance officers, and management teams — delivered online globally.

Comprehensive coverage across ISO, security, and regulatory compliance

REGULATORY

⚖️ Privacy & Regulation

  • GDPR — EU & UK 🇪🇺🇬🇧
  • UAE Personal Data Protection Law 🇦🇪
  • PIPEDA — Canada 🇨🇦
  • LGPD — Brazil 🇧🇷
  • DORA — Digital Operational Resilience 🇪🇺
  • MiCA — Crypto-Assets Regulation 🇪🇺
  • NIS2 — Cybersecurity Directive 🇪🇺
🗺️

Require a multi-standard or custom scope?

BALTUM architects integrated compliance programmes that address multiple frameworks simultaneously — reducing audit duplication and accelerating certification timelines for organisations operating across jurisdictions including Portugal, EU and UK.

Discuss your scope →

Trusted across regulated and high-growth industries

Our client portfolio spans financial services, technology, healthcare, and critical infrastructure — including organisations headquartered or operating in Portugal seeking international market recognition.

🏢 Translation & LSPs🎓 Education & EdTech💱 Crypto & Digital Assets⛓️ Blockchain & Web3🏦 Banking & Financial Services🗄️ Data Centres🩺 MedTech & Healthcare🛍️ Retail & E-commerce👩‍💻 IT Outstaffing & MSPs🛢️ Energy & Resources✈️ Travel & Hospitality🏭 Manufacturing💻 SaaS & Software

Independent rigour. Practical delivery. Internationally recognised outcomes.

🏛️

Decade of expertise

Over 10 years delivering certification programmes across diverse industries and jurisdictions.

🔬

Qualified lead auditors

An international panel of domain-specialist auditors covering cybersecurity, privacy, quality, AI and continuity.

📐

Tailored programme design

Each engagement is scoped to your organisational context, regulatory obligations, and strategic objectives.

📋

Accreditation-aligned

All audit and certification activities are conducted in alignment with ISO 17021 and relevant accreditation frameworks.

🏅

Internationally recognised

Certificates issued through our accredited partner network carry global recognition — accepted by clients, regulators, and procurement bodies worldwide.

🎓

Integrated training

BALTUM Academy provides supporting curricula that build internal competence, reducing long-term dependency on external consultancy.

Platform-agnostic delivery across leading compliance automation tools

BALTUM consultants are experienced across the leading GRC and compliance automation platforms, enabling seamless integration of our certification programmes into your existing toolchain.

🛡️
Vanta
GRC / SOC 2
📊
Workiva
Compliance reporting
Drata
Continuous compliance
🧾
Hyperproof
Evidence management
🎛️
AllControls
Control framework
Sprinto
Automated audits
🌐
isms.online
ISO 27001 ISMS
🔧
Secfix
Security automation

Accredited international certification bodies

All certifications issued through BALTUM engagements are delivered in cooperation with accredited international certification bodies — ensuring formal recognition by regulators, clients, and institutional stakeholders across global markets.

🏛️

Swiss International

Independent inspection, certification, and quality assurance aligned with internationally recognised standards.

🇬🇧

BCERT

UK-registered certification body specialising in management system audits across quality, security, and environmental domains.

🌍

International CB — ISO / GDPR / ITIL / Agile

Multi-framework certification body delivering audit, certification, and training across global markets.

🌏

G-CERT System Service

Asia-Pacific accredited certification body covering ISO 9001, 14001, 27001 and sector-specific standards.

🇩🇪

UNIVERSAL

Germany-based certification organisation providing conformity assessment for internationally recognised management system standards.

🛡️

4N6 Cybersecurity

Specialist in Cyber Essentials, vulnerability assessment, penetration testing, and security maturity evaluation.

A structured, four-stage path to certification

Our methodology is derived from ISO 17021 audit principles and adapted to minimise operational impact while maintaining the rigour required for internationally recognised certification outcomes.

01

Scoping & gap analysis

Boundary definition, current-state assessment, gap identification, and a tailored project roadmap with defined milestones.

02

Documentation & control design

Development of policies, procedures, risk registers, and an evidence framework mapped to the target standard's control set.

03

Stage 1 & Stage 2 audit

Documentary review followed by a detailed on-site or remote operational audit, findings report, and formal nonconformity register.

04

Certification & surveillance

Nonconformity remediation support, certification decision, certificate issuance, and ongoing surveillance audit planning.

Request a certification proposal

Submit your enquiry and a BALTUM consultant will respond within one business day with a scoping questionnaire and indicative timeline. All enquiries are treated with strict confidentiality.

Portugal Operations

🇵🇹 Porto, Portugal

Porto, Portugal

Primary operations & client support centre

✉ info@bcert.org
Additional offices
🇬🇧 United Kingdom 🇺🇸 United States 🇧🇷 Brazil
🌍 Audit delivery coverage

Remote & on-site audits available across:

🇵🇹 Portugal 🇪🇺 EU 🇬🇧 UK 🇺🇸 USA 🇦🇪 UAE/MENA 🌏 Asia-Pacific

📋 Send request

Frequently asked questions

What differentiates BALTUM from a standard ISO consultancy?+
Unlike standalone consultancies, BALTUM provides an integrated path from readiness assessment through to formal certification — in cooperation with accredited international certification bodies. This means clients work with a single provider rather than coordinating between separate consultancy and audit firms.
What is the typical timeline from engagement to certificate issuance?+
Timelines vary based on organisational size, scope, and current maturity. A focused ISO 27001 engagement for a mid-size organisation typically runs 3–6 months from kick-off to certificate issuance.
What documentary evidence is required for a Stage 2 audit?+
For ISO 27001 this typically includes: information security policies, risk assessment and treatment methodology, Statement of Applicability, asset registers, evidence of control operation, internal audit records, and management review outputs.
Can BALTUM support integrated multi-standard certification?+
Yes. Common combinations include ISO 27001 with ISO 27701 (privacy), ISO 22301 (business continuity), or ISO 9001 (quality) — with a unified evidence framework that reduces audit duplication.
Are BALTUM certificates recognised internationally?+
All certificates are issued through our accredited international certification partner network. Accreditation status and recognition scope are confirmed during the scoping phase.