Compliance that survives the audit, not just the sales call
ISO 27001, SOC 2, and DORA implementation, risk management, and internal audit — led by an ISO 27001 Lead Auditor and Lead Implementer who has sat on both sides of the certification table. Fixed scope. Fixed fee.
Six disciplines, one accountable programme
ISO 27001 Implementation
End-to-end ISMS build: scoping, gap assessment, Statement of Applicability, risk treatment, and internal audit through to certification-body liaison. Led by a Lead Implementer, audited by a Lead Auditor — the gaps get found before the certification body finds them.
SOC 2 Readiness
Type I and Type II readiness for SaaS and service providers: Trust Services Criteria mapping, control design, evidence collection, and pre-assessment across the full observation window. We prepare you for the auditor you'll actually face.
DORA Compliance
Digital Operational Resilience Act readiness for financial entities and their ICT providers: ICT risk framework, third-party register, incident classification, threat-led penetration testing scoping, and board-level governance. PECB DORA certified.
Risk Assessment & Management
Enterprise and information risk assessments mapped to ISO 27005, NIST, or your own methodology. Risk-scored, prioritised, and tracked — not a one-off spreadsheet that ages out the week after delivery.
Internal Audit & Gap Assessment
Independent internal audit against ISO 27001, SOC 2, PCI DSS, or NIST CSF 2.0. Findings written for the board and for the engineers, with a remediation plan you can actually close.
Vendor & Third-Party Risk
Third-party risk programmes: due-diligence questionnaires, contractual control requirements, continuous monitoring, and the vendor register DORA and ISO both now expect.
How we run a compliance programme
Scoping & Gap Assessment
One or two sessions to map your environment, regulatory exposure, and current control maturity against the target framework. Output: a scoped gap assessment and a fixed-fee roadmap to certification or readiness.
Framework Mapping
Controls mapped once, satisfied many times — ISO 27001, SOC 2, DORA, and PCI DSS share more than they differ. We build a single control set so one piece of evidence answers multiple frameworks.
Implementation & Evidence
Policies, procedures, and technical controls implemented with your team — not handed over as templates. Evidence collected continuously across the observation window, not scrambled the week before the audit.
Internal Audit
A full internal audit against the standard before the external body arrives. Findings are risk-rated and remediated, so the certification audit holds no surprises.
Certification & Ongoing Assurance
Certification-body liaison through to award, then an annual rhythm of surveillance-audit support, risk reviews, and control updates that keeps the certificate valid — and the posture real.