ISO 27001 and SOC 2, without the template pack
Certification is not a document exercise. An auditor asks for evidence that a control operated over a period, and a folder of freshly written policies with no operating history does not answer that.
We run compliance as an engineering programme: assess the gap, implement the control properly, generate the evidence as a by-product of it running, then prepare you for the audit.
What the engagement includes
- Gap analysis against the target standard with an effort-ranked remediation plan
- Scope definition — often the single biggest lever on cost and timeline
- Risk assessment and treatment plan
- Policy and procedure set written to match how you actually operate
- Technical control implementation, not just documentation
- Evidence collection routines that survive an audit period
- Internal audit and management review preparation
- Support through certification body or auditor engagement
Who this is for
Businesses blocked in enterprise sales by a security questionnaire, companies with a contractual certification deadline, and teams preparing for their first external audit.
How it runs
Every engagement follows the same five stages — discover, architect, implement, validate, defend. See how we work →
How the engagement runs
Five stages, with indicative timing. Exact dates are confirmed at scoping.
-
01
Scope & gap analysis
Scope defined — the biggest single lever on cost — and measured against the standard clause by clause.
Weeks 1–3 -
02
Risk assessment
Asset-based risk assessment and treatment plan an auditor will accept as genuinely yours.
Weeks 3–6 -
03
Implement controls
Technical and organisational controls actually implemented, not documented as intent.
Months 2–5 -
04
Evidence period
Controls run and generate evidence as a by-product. Internal audit and management review completed.
Months 4–8 -
05
Certification audit
Stage 1 and Stage 2 support, findings closed, certificate issued.
Months 8–12