Skip to content
Lorendix

Solutions · Security and compliance

Certification that starts from a working set

Policy sets, control mappings and evidence checklists for ISO 27001, SOC 2 and Cyber Essentials, refined across several certifications. Tailored to how your organisation actually works, so the first draft is close to the final one.

Use cases

Is this you?

Much of a certification effort goes on documents that look alike everywhere. The part that differs is how your organisation really operates.

A certification blocking a contract

A customer requires ISO 27001 or SOC 2 before signing, and there is a date attached.

Starting from nothing

No policies, no control list and no clear idea of how long it should take.

Policies nobody recognises

Documents bought or copied in that describe an organisation which is not yours.

More than one framework

Customers ask for different standards, and each is being handled as a separate project.

What it delivers

The starting set, shaped to you in weeks

Rather than written from a template on the first day and corrected for months.

  • A policy set written to be followed, not filed
  • Control mappings across ISO 27001, SOC 2 and Cyber Essentials
  • Evidence checklists per control, with who provides what
  • A risk register structure and treatment templates
  • Supplier assessment templates
  • An audit readiness checklist for the final weeks

Evidence kit

  • Policies

    Information security, access, change, incident, supplier

  • Control map

    One control set mapped to three frameworks

  • Evidence checklists

    Checklist per control, owner, frequency

  • Risk register

    Structure, scoring, treatment

  • Suppliers

    Assessment questions and tiering

  • Audit readiness

    The last six weeks before the auditor arrives

What we do around it

Documents are quick. Controls are the work.

A kit gets the paperwork right fast. Certification also needs the controls to be real, which is engineering.

Tailoring
Every policy rewritten around how your teams actually work, in sessions with the people it governs.
Gap work
Where a control does not yet exist, we build it: access reviews, logging, backups, change approval.
Evidence
Collection automated from your systems wherever possible, so the next audit takes less effort than this one.
Audit support
Preparation, walkthroughs and remediation of findings through to certification.
Between audits
Ongoing support so the controls hold all year, not only while the auditor is present.

Pricing and demonstrations

Tell us the date you need to be ready

We will show you how much of the kit already fits your organisation, and what is left for you to decide.

Priced by your size, users and the support you need. No tiers.

All solutions