Governance, Risk and Compliance Services
Very few organisations pursue a security certification because they woke up wanting one. They pursue it because a customer will not sign without it, an investor asked during due diligence, a regulator introduced a deadline, or a large contract turned out to have a requirement buried in the annexes.
Which means compliance is usually a revenue problem wearing a security costume. The certificate is not the goal. Closing the deal is the goal, and the certificate is standing in the way.
We treat it accordingly. Our job is to get you compliant on the shortest realistic path, with the least disruption to the people who need to be building your actual product.
What we do and what we do not do
We prepare you for certification and support you through the audit. We are not a certification body, and no consultancy that implements your management system can also certify it. Any firm offering both is either misdescribing the service or working outside the rules of the scheme.
For ISO 27001 you will need an accredited certification body. For SOC 2 you will need a licensed CPA firm. We help you select one, prepare everything they will ask for, and stay involved through fieldwork so the audit does not become your problem to manage alone.
Frameworks we work with
SOC 2
The default requirement for software companies selling into the United States. Type I confirms your controls are designed properly at a point in time. Type II confirms they operated properly over a period, typically three to twelve months. Enterprise buyers usually want Type II, though Type I is often enough to unblock a deal while you build the observation window.
ISO 27001
The international standard for information security management, and the one most commonly requested in the UK, Europe, the Middle East and Asia. Broader in scope than SOC 2 and structured around a management system rather than a fixed control set, which means it takes longer to implement and lasts longer once you have it.
GDPR and UK GDPR
Data protection obligations covering anyone handling personal data of people in the UK or European Union, regardless of where the organisation itself is based. Records of processing, lawful basis, data subject rights, retention, transfers, breach notification and processor agreements.
PCI DSS
Required wherever card payment data is handled. Version 4.0 requirements are now in force and considerably more prescriptive than earlier versions.
HIPAA
United States healthcare data, covering both covered entities and business associates. Vendors serving healthcare clients are frequently caught by this without realising.
NIS2 and DORA
European directives now driving substantial compliance work. NIS2 covers essential and important entities across a wide range of sectors. DORA applies to financial entities and their critical technology providers, with specific requirements around resilience testing and third party risk.
NIST frameworks
Cybersecurity Framework 2.0 as a general structure, and 800 171 with CMMC for organisations in the United States defence supply chain.
Cyber Essentials
A UK scheme, inexpensive and quick, and a hard requirement for many public sector contracts. Often the right starting point for smaller organisations that are not yet ready for ISO 27001.
How an engagement runs
Gap assessment. We measure your current position against the framework and produce a clear picture of where you stand. Most organisations are further along than they expect on technical controls and further behind than they expect on documentation and evidence.
Remediation planning. A prioritised plan with owners and dates, separating what must be done before audit from what can follow. This is where an experienced implementer saves you the most money, because a large proportion of what people assume is mandatory turns out to be optional once scope is properly defined.
Implementation. Policies, procedures, risk assessment, asset inventory, access reviews, supplier management, training and the technical controls the framework requires. We write documentation that reflects how your organisation actually works. Generic templates fail audits because auditors ask staff whether the process described is the process followed.
Evidence collection. Continuous evidence gathering rather than a scramble before fieldwork. Where a compliance automation platform is in use, we configure it properly so evidence collects itself.
Audit support. We help you select an auditor, prepare your team for interviews, manage the evidence request list and stay present through fieldwork.
Maintenance. Certification is not a finish line. Surveillance audits, annual reviews, recertification and continuous evidence collection all continue afterwards, and this is where most self managed programmes quietly fall apart in year two.
Individual services
- SOC 2 Readiness and Audit Support
- ISO 27001 Implementation
- GDPR and Data Protection Consulting
- PCI DSS Compliance
- HIPAA Compliance
- NIS2 and DORA Readiness
- NIST CSF and 800 171 Alignment
- Cyber Essentials Certification Support
- Vendor Risk Management
- Security Questionnaire Response
- Compliance Automation Implementation
- DPO as a Service and EU Representative
Security questionnaire response
A specific problem worth naming separately. You win a large contract, then their procurement team sends a security questionnaire with two hundred questions and a two week deadline. Nobody at your company knows how to answer half of them and the deal is now stalled on paperwork.
We complete these for you. We build a reusable answer library from your first questionnaire so the second one takes a fraction of the time, flag any answers that would fail and need remediation first, and handle the follow up questions the buyer's security team sends back.
This is frequently how clients meet us, and it usually leads to the certification conversation once they realise how often the questionnaire will arrive.
Compliance automation platforms
Vanta, Drata, Sprinto and similar platforms automate a meaningful part of evidence collection and control monitoring. They are genuinely useful and they are not a compliance programme. The software will tell you a control is failing. It will not write your risk assessment, define your scope, run your management review or answer an auditor asking how your access review process works.
We implement and configure these platforms, connect them to your systems properly, and deliver the human work around them. If you have already bought one and are staring at a dashboard of red items with no plan, that is a common place to start.
Who this is for
Software companies whose sales cycle has started stalling on security review. Businesses expanding into regulated markets or new jurisdictions. Organisations in a supply chain where a larger customer has imposed requirements. Companies preparing for funding, acquisition or due diligence. Any business that has recently had a customer ask a question it could not answer.
Frequently asked questions
How long does SOC 2 take?
Type I is achievable in roughly two to four months from a reasonable starting position. Type II requires an observation period on top, most commonly three months for a first report and twelve months thereafter.
How long does ISO 27001 take?
Typically six to twelve months, depending on scope, organisation size and how much documentation already exists. Certification involves a two stage audit, and the management system needs to have been operating for long enough to produce evidence before stage two.
Should we do SOC 2 or ISO 27001?
Largely a question of who is asking. United States buyers generally expect SOC 2. European, UK and Asian buyers generally expect ISO 27001. If your customer base spans both, the frameworks overlap substantially and doing the second after the first costs far less than doing it independently.
Do we need a certification to answer security questionnaires?
No, and a questionnaire is often the cheaper way to unblock a single deal. Certification becomes worthwhile once questionnaires start arriving regularly, because the time spent answering them eventually exceeds the cost of certifying.
What does compliance cost in total?
Audit fees are separate from consulting fees, and tooling is separate again. We give you a full picture at proposal stage covering all three, because the surprise is usually the audit invoice rather than ours.
Can you take over a programme that has stalled?
Yes, and it is common. A failed or paused programme usually needs scope reduced rather than effort increased.
Are you a certification body?
No. Certification must come from an accredited body or licensed audit firm that is independent of the implementation work. We prepare you and support you through their process.
Find out how far you are from audit ready
Book a call and we will map your current position against the framework you need, then tell you honestly how long it will take and what it will cost.