Cybersecurity · Governance and compliance
Certification as a by-product of how you already operate
ISO 27001, SOC 2, Cyber Essentials, DORA and NIS2, implemented as controls that run and produce their own evidence. The aim is that an audit becomes a report from the system rather than a project that stops delivery.
Where this starts
Compliance costs the most in the wrong places
The expensive part of certification is rarely the certificate. It is the six weeks beforehand when engineers stop delivering and start collecting screenshots, the sales cycles held up by a questionnaire nobody owns, and the controls that are genuine for one month a year. Auditors are not the problem. Evidence that has to be manufactured rather than produced is the problem.
What we usually find
- Evidence gathered by hand in the weeks before an audit, then discarded
- Policies written to satisfy a standard and unrecognisable to the teams they describe
- A risk register maintained for the auditor rather than used for decisions
- Security questionnaires answered from scratch each time by whoever happens to be free
- Controls owned by a security function that only engineering can actually operate
- Two or three frameworks implemented separately over the same underlying controls
Our position
A control that only holds during audit season is not a control. It is a performance, and everyone involved knows it.
What the work covers
Implementation, not interpretation
Plenty of firms will tell you what a clause requires. The work that changes anything is turning the clause into something that runs, owned by someone who is not surprised to have it.
One control set, mapped outward
ISO 27001, SOC 2, Cyber Essentials Plus and PCI DSS overlap heavily. We implement a single set of controls and map it to each framework, so a second certification is an evidence exercise rather than a second programme with a second budget.
Policy that matches practice
Policies written from what teams actually do, versioned in the repository alongside the systems they govern. A policy nobody follows is an audit finding that has not been written down yet.
Risk management that informs decisions
A register scoped to real business impact, reviewed on a cadence tied to change rather than to the calendar, with treatment decisions recorded where the engineering work is actually planned.
Third party and supply chain risk
Proportionate due diligence, concentration risk made visible, and contractual security requirements that match what you are able to monitor. This is increasingly the sharp end of assessment under DORA and NIS2.
Sector regimes
DORA for financial entities, NIS2 for essential and important entities, and UK GDPR throughout. We establish what applies, what it means operationally, and what genuinely has to change, which is usually less than a vendor will tell you and more than you hoped.
Customer assurance
A maintained questionnaire answer library and a trust page, so a security review shortens a sales cycle instead of stalling it for a fortnight.
How it stays fixed
Evidence the system produces
The measure of a good compliance programme is how little anyone has to do in the month before the audit.
- Mapping
- One control, many frameworks, so evidence collected once satisfies every standard it maps to and nobody collects the same artefact twice.
- Collection
- Evidence pulled from systems of record on a schedule: access reviews, change approvals, scan results, training completion. Dated, attributable and stored, rather than screenshotted.
- Policy as code
- Technical controls asserted by the pipeline, so the statement in the policy and the behaviour of the estate cannot diverge without something visibly failing.
- Exceptions
- Time limited, owned and visible, which is what makes an exception process credible to an auditor rather than a documented route around the control.
- Reporting
- A standing view of control health for the board built from the same underlying data as the audit pack, so there is only ever one version of the truth to defend.
What you are left holding
- A single control set mapped to every framework you are asked about
- Evidence collected automatically, dated and attributable
- Policies your engineers recognise as a description of their own work
- A questionnaire answer library that shortens security reviews
- A board report produced from the same data as the audit pack
Tell us which certification is blocking a deal
We will tell you what is genuinely missing, what you already satisfy and have simply never evidenced, and how long the real gap takes to close.
