Service

Compliance readiness

Getting policy, practice, and evidence into a state that survives an audit — SOC 2, HIPAA, PCI DSS, GDPR, NIS2, ISO 27001.

The problem

Things we hear in the first call.

“A customer told us no SOC 2 report, no contract.”

“We wrote policies two years ago. Nobody follows them.”

“We handle patient records and we are not certain what that obligates us to do.”

What we do

Gap assessment

Your current state mapped control by control against the framework in question, with the gaps stated plainly.

Policy set

Policies written to be followed by the company you actually are, not copied from a template built for a company of two thousand.

Control implementation

Access reviews, change management, logging, vendor review, and training put in place as working routines with named owners.

Evidence and audit trail

A collection calendar so evidence accumulates through the year instead of being reconstructed the week before fieldwork.

Data and vendor mapping

What personal data you hold, where it goes, and which processor sits behind it — the record GDPR and NIS2 work expects.

Audit support

We prepare the narrative, sit in the walkthroughs, and handle auditor requests alongside your team.

How an engagement runs

Durations are typical for a company of 10 to 250 people. Scope is confirmed before anything starts.

01

Gap assessment

Scope the framework, review controls and evidence, and produce a gap report you can take to a customer or a board.

2–3 weeks
02

Remediation plan

Every gap gets an owner, an effort estimate, and a date. Anything you can defer is marked as deferrable.

1 week
03

Implementation

Controls become routines. Evidence starts accumulating. Staff are trained on the parts that touch their work.

2–6 months
04

Audit support

We help you select an auditor, prepare the walkthroughs, and manage requests through fieldwork.

As scheduled

What you get

Documents and access you keep, whether or not the engagement continues.

  • Gap report mapped control by control
  • Policy set with review dates and owners
  • Evidence collection calendar
  • Data inventory and processing record
  • Vendor risk register
  • Auditor-facing control narrative

Common questions

No. Certification and attestation come from an independent auditor or certification body, and no consultant can issue them. We prepare you for that process and work alongside the firm you appoint. We do not hold certifications on your behalf or claim any as our own.

Turn a stalled deal into a scheduled audit.

A 30-minute call, no obligation. Send a request and we confirm a time by email within one business day.

Book a consultation

+1 (917) 540-1649hello@itgloryconsult.online