Opulence.
Cybersecurity

Compliance & Governance (ISO 27001, SOC 2, NIS2, GDPR)

Gap assessment, policy writing and audit preparation across the frameworks your customers demand.

Security certifications open doors: enterprise deals, tenders and regulated sectors. Getting there is mostly organisation and evidence. We assess where you stand against the framework, write the policies and controls that close the gaps and prepare you for the audit with the evidence in order.

The controls we design are meant to be operated, not just documented, so compliance improves security rather than distracting from it.

How we're different
  • Policies are written by people who also run penetration tests, so they reflect real threats.
  • We aim for the lightest control set that passes, which keeps the programme sustainable.
  • Our IT team can implement technical controls rather than leaving them on a to-do list.
Who this is for
  • A technology supplier to banks, airlines or governments that must hold ISO 27001 or SOC 2 to stay on the vendor list.
  • A group bringing several subsidiaries under one information security management system.
  • An operator classed as essential or important under NIS2 with a reporting deadline.
Signals you need this now
  • A contract is conditional on certification by a date.
  • Policies were bought as templates and never adapted.
  • Evidence for audits is gathered in a rush the week before.
  • Several frameworks apply and each is handled by a different team.
Scope of work

What is included.

  1. 01

    Framework selection

    Which certifications matter for your customers and regulators, and in what order.

  2. 02

    Gap assessment

    Current controls measured against the standard with a prioritised remediation plan.

  3. 03

    Policy and control design

    Policies, procedures and technical controls written for your organisation.

  4. 04

    Evidence and tooling

    Compliance platform setup or a lightweight evidence process.

  5. 05

    Audit preparation

    Internal audit, readiness review and support during the external audit.

Method

Four steps, no surprises.

  1. 01

    Scope

    Frameworks, boundaries and timelines agreed.

  2. 02

    Assess

    Gap assessment and remediation plan.

  3. 03

    Build

    Policies, controls and evidence processes implemented.

  4. 04

    Certify

    Internal audit, readiness review and external audit support.

How the engagement runs

From first meeting to steady state.

  1. 01Weeks 1 to 4

    Scope and assess

    Frameworks, boundaries and timelines agreed, then a gap assessment and remediation plan.

  2. 02Months 2 to 5

    Build

    Policies, controls and evidence processes implemented with owners, with our engineers on the technical controls.

  3. 03Months 6 to 8

    Certify

    Internal audit, readiness review and support through the external audit.

What we measure
  • Gaps closed against the framework, tracked to certification.
  • Nonconformities raised at the external audit.
  • Time spent gathering evidence per audit cycle.
  • Share of controls with an owner and current evidence.
Who is on the engagement
  • Lead compliance consultant
  • Information security officer
  • Technical control engineer
  • Engagement director
Deliverables
  • Gap assessment report.
  • Policy and procedure pack.
  • Risk register and statement of applicability.
  • Evidence process or compliance platform setup.
  • Audit-readiness checklist and audit support.
Engagement terms

Compliance programmes are fixed scope and typically take four to nine months to first certification depending on framework and starting point. Ongoing maintenance, internal audits and surveillance support run on an annual retainer.

FAQ

Compliance & Governance (ISO 27001, SOC 2, NIS2, GDPR), in plain terms.

ISO 27001 is recognised across Europe and most industries. SOC 2 is expected by North American enterprise buyers. Many software companies end up doing both, and the control sets overlap heavily.

Four to nine months for most organisations. Those with mature IT and a small scope can be faster.

Helpful for SOC 2 and for organisations with several frameworks. Not essential for a first ISO 27001 certification. We recommend based on your size.

No, but it requires demonstrable risk management and reporting. ISO 27001 is a practical way to structure that.

Next step

Ready to talk about compliance & governance (iso 27001, soc 2, nis2, gdpr)?