Cybersecurity

ISO 27001 and SOC 2, without the template pack

Certification is not a document exercise. An auditor asks for evidence that a control operated over a period, and a folder of freshly written policies with no operating history does not answer that.

We run compliance as an engineering programme: assess the gap, implement the control properly, generate the evidence as a by-product of it running, then prepare you for the audit.

What the engagement includes

  • Gap analysis against the target standard with an effort-ranked remediation plan
  • Scope definition — often the single biggest lever on cost and timeline
  • Risk assessment and treatment plan
  • Policy and procedure set written to match how you actually operate
  • Technical control implementation, not just documentation
  • Evidence collection routines that survive an audit period
  • Internal audit and management review preparation
  • Support through certification body or auditor engagement

Who this is for

Businesses blocked in enterprise sales by a security questionnaire, companies with a contractual certification deadline, and teams preparing for their first external audit.

How it runs

Every engagement follows the same five stages — discover, architect, implement, validate, defend. See how we work →

How the engagement runs

Five stages, with indicative timing. Exact dates are confirmed at scoping.

  1. 01
    Scope & gap analysis

    Scope defined — the biggest single lever on cost — and measured against the standard clause by clause.

    Weeks 1–3
  2. 02
    Risk assessment

    Asset-based risk assessment and treatment plan an auditor will accept as genuinely yours.

    Weeks 3–6
  3. 03
    Implement controls

    Technical and organisational controls actually implemented, not documented as intent.

    Months 2–5
  4. 04
    Evidence period

    Controls run and generate evidence as a by-product. Internal audit and management review completed.

    Months 4–8
  5. 05
    Certification audit

    Stage 1 and Stage 2 support, findings closed, certificate issued.

    Months 8–12

Questions we get asked

Typically six to twelve months from a standing start, driven mostly by how much control implementation is genuinely missing and how long an evidence period the auditor requires. A tight scope shortens both.
No credible consultant can, and an auditor who could be guaranteed is not independent. We can make sure nothing in the audit is a surprise, which is what actually determines the outcome.
Substantially. If you need both, running them together shares most of the control work and evidence. We map the overlap at scoping rather than running two separate programmes.

Every engagement starts free.

We assess your environment first, then scope. No commitment until you have seen how we work.