Service
Compliance readiness
Getting policy, practice, and evidence into a state that survives an audit — SOC 2, HIPAA, PCI DSS, GDPR, NIS2, ISO 27001.
The problem
Things we hear in the first call.
“A customer told us no SOC 2 report, no contract.”
“We wrote policies two years ago. Nobody follows them.”
“We handle patient records and we are not certain what that obligates us to do.”
What we do
Gap assessment
Your current state mapped control by control against the framework in question, with the gaps stated plainly.
Policy set
Policies written to be followed by the company you actually are, not copied from a template built for a company of two thousand.
Control implementation
Access reviews, change management, logging, vendor review, and training put in place as working routines with named owners.
Evidence and audit trail
A collection calendar so evidence accumulates through the year instead of being reconstructed the week before fieldwork.
Data and vendor mapping
What personal data you hold, where it goes, and which processor sits behind it — the record GDPR and NIS2 work expects.
Audit support
We prepare the narrative, sit in the walkthroughs, and handle auditor requests alongside your team.
How an engagement runs
Durations are typical for a company of 10 to 250 people. Scope is confirmed before anything starts.
Gap assessment
Scope the framework, review controls and evidence, and produce a gap report you can take to a customer or a board.
Remediation plan
Every gap gets an owner, an effort estimate, and a date. Anything you can defer is marked as deferrable.
Implementation
Controls become routines. Evidence starts accumulating. Staff are trained on the parts that touch their work.
Audit support
We help you select an auditor, prepare the walkthroughs, and manage requests through fieldwork.
What you get
Documents and access you keep, whether or not the engagement continues.
- Gap report mapped control by control
- Policy set with review dates and owners
- Evidence collection calendar
- Data inventory and processing record
- Vendor risk register
- Auditor-facing control narrative
Common questions
No. Certification and attestation come from an independent auditor or certification body, and no consultant can issue them. We prepare you for that process and work alongside the firm you appoint. We do not hold certifications on your behalf or claim any as our own.
Readiness work is commonly two to six months depending on your starting point. After that, a Type I looks at a point in time and a Type II covers an observation period your auditor sets. We build the plan around the date your customer needs.
Often not. The two overlap heavily, and which one matters depends on where your customers are. We will tell you if one report answers both sets of questions.
It can, if you offer services to or monitor people in the EU or UK. The obligations follow the data subject, not your incorporation. We scope that early rather than assuming either way.
A platform collects evidence well and decides nothing. It will not scope your framework, write a policy that matches how you actually work, or answer an auditor's question about an exception. Where you already pay for one, we work inside it rather than duplicating it.
Turn a stalled deal into a scheduled audit.
A 30-minute call, no obligation. Send a request and we confirm a time by email within one business day.
Book a consultation