Compliance & Governance (ISO 27001, SOC 2, NIS2, GDPR)
Gap assessment, policy writing and audit preparation across the frameworks your customers demand.
Security certifications open doors: enterprise deals, tenders and regulated sectors. Getting there is mostly organisation and evidence. We assess where you stand against the framework, write the policies and controls that close the gaps and prepare you for the audit with the evidence in order.
The controls we design are meant to be operated, not just documented, so compliance improves security rather than distracting from it.
- Policies are written by people who also run penetration tests, so they reflect real threats.
- We aim for the lightest control set that passes, which keeps the programme sustainable.
- Our IT team can implement technical controls rather than leaving them on a to-do list.
- A technology supplier to banks, airlines or governments that must hold ISO 27001 or SOC 2 to stay on the vendor list.
- A group bringing several subsidiaries under one information security management system.
- An operator classed as essential or important under NIS2 with a reporting deadline.
- A contract is conditional on certification by a date.
- Policies were bought as templates and never adapted.
- Evidence for audits is gathered in a rush the week before.
- Several frameworks apply and each is handled by a different team.
What is included.
- 01
Framework selection
Which certifications matter for your customers and regulators, and in what order.
- 02
Gap assessment
Current controls measured against the standard with a prioritised remediation plan.
- 03
Policy and control design
Policies, procedures and technical controls written for your organisation.
- 04
Evidence and tooling
Compliance platform setup or a lightweight evidence process.
- 05
Audit preparation
Internal audit, readiness review and support during the external audit.
Four steps, no surprises.
- 01
Scope
Frameworks, boundaries and timelines agreed.
- 02
Assess
Gap assessment and remediation plan.
- 03
Build
Policies, controls and evidence processes implemented.
- 04
Certify
Internal audit, readiness review and external audit support.
From first meeting to steady state.
- 01Weeks 1 to 4
Scope and assess
Frameworks, boundaries and timelines agreed, then a gap assessment and remediation plan.
- 02Months 2 to 5
Build
Policies, controls and evidence processes implemented with owners, with our engineers on the technical controls.
- 03Months 6 to 8
Certify
Internal audit, readiness review and support through the external audit.
- Gaps closed against the framework, tracked to certification.
- Nonconformities raised at the external audit.
- Time spent gathering evidence per audit cycle.
- Share of controls with an owner and current evidence.
- Lead compliance consultant
- Information security officer
- Technical control engineer
- Engagement director
- Gap assessment report.
- Policy and procedure pack.
- Risk register and statement of applicability.
- Evidence process or compliance platform setup.
- Audit-readiness checklist and audit support.
Compliance programmes are fixed scope and typically take four to nine months to first certification depending on framework and starting point. Ongoing maintenance, internal audits and surveillance support run on an annual retainer.
Compliance & Business Continuity
GDPR, ISO 27001 and NIS2 readiness with backup and disaster recovery plans that have been tested.
AI Consulting & AutomationAI Governance, Risk & Compliance
Model risk controls, EU AI Act readiness and responsible-AI policies that regulators and customers accept.
CybersecuritySecurity Awareness Training
Role-based training and phishing simulations that reduce human risk and prove it.
Compliance & Governance (ISO 27001, SOC 2, NIS2, GDPR), in plain terms.
ISO 27001 is recognised across Europe and most industries. SOC 2 is expected by North American enterprise buyers. Many software companies end up doing both, and the control sets overlap heavily.
Four to nine months for most organisations. Those with mature IT and a small scope can be faster.
Helpful for SOC 2 and for organisations with several frameworks. Not essential for a first ISO 27001 certification. We recommend based on your size.
No, but it requires demonstrable risk management and reporting. ISO 27001 is a practical way to structure that.