DGA-Authorized Information Security Audit in Georgia
DGA-authorized information security audits for critical information system subjects – meeting the mandatory requirements of Georgia’s Law on Information Security.

Why This Audit Matters
Georgia’s Law on Information Security designates certain organizations as Critical Information System (CIS) Subjects – entities whose continuous operation is essential to national defense, economic security, government function, or public life. These organizations are legally required to undergo a mandatory initial security audit, followed by periodic audits and penetration testing, to verify compliance with minimum information security requirements. Non-compliance carries fines ranging from 5,000 to 20,000 GEL per violation. IO Consulting is authorized by the Digital Governance Agency (DGA) to conduct these audits on behalf of CIS subjects.
Who Is Classified as a Critical Information System Subject
The law divides CIS subjects into three categories, each defined by government decree:
- Category I – State and municipal government bodies, and state-owned enterprises
- Category II – Electronic communications companies designated by Government decree
- Category III – Private companies designated by Government decree, including commercial banks and other entities in sectors deemed critical to economic security
If your organization has been notified of inclusion in the CIS registry or you’re uncertain whether you qualify, we can help you determine your obligations and audit scope.

What You Get
Mandatory Initial Security Audit
A comprehensive assessment against Georgia’s minimum information security requirements, fulfilling your legal obligation as a newly classified CIS subject.
Periodic Compliance Audits
Ongoing audits at the intervals required by law, verifying continued compliance with information security policy and minimum standards as your systems evolve.
Gap Analysis Against Regulation
Minimum requirements under the law are informed by ISO, NIST, and ISACA standards – we assess your environment against the specific framework applicable to your category.
Non-Conformity & Corrective Action Support
If gaps are identified, we help you analyze root causes and build a corrective action plan and implementation timeline, as required for submission to the Digital Governance Agency (and, for commercial banks, the National Bank of Georgia).
DGA-Compliant Audit Reporting
Audit findings and reports documented in the format required for submission to the Digital Governance Agency, satisfying your statutory reporting obligations.

Our Audit Methodology
- Scoping & Category Confirmation – Confirm your CIS category and the specific minimum requirements applicable to your organization.
- Documentation Review – Review your information security policy and existing controls against statutory minimum requirements.
- Control & System Assessment – Assess technical and organizational controls, coordinated with your information security manager and/or computer security specialist as required by law.
- Compliance Evaluation – Evaluate compliance against ISO, NIST, and ISACA-informed minimum requirements for your category.
- Reporting – Deliver a DGA-compliant audit report documenting findings, non-conformities, and required corrective actions.
- Corrective Action & Follow-Up Support – Support development of the corrective action plan and implementation schedule, including submission coordination with the Digital Governance Agency.
Who This Is For
Organizations that need to:
- Complete their mandatory initial security audit as a newly designated CIS subject
- Fulfill periodic audit obligations under the Law on Information Security
- Address non-conformities identified in a previous DGA or internal audit
- Commercial banks needing to submit corrective action plans to the National Bank of Georgia within statutory deadlines
- Understand whether their organization qualifies as a CIS subject and what obligations apply

Why IO Consulting
IO Consulting is authorized by Georgia’s Digital Governance Agency (DGA) to conduct information security audits for critical information system subjects. Our team combines this regulatory authorization with certified expertise: CISA, CISM, ISO/IEC 27001 Senior Lead Auditor and Lead Implementer and 15+ years of combined experience across financial services, healthcare, energy, and enterprise sectors. We understand not only the technical requirements of the law, but the practical realities of implementing and sustaining compliance within a real organization.
