What it is

Compliance certifications are often more achievable than companies expect — if you approach them correctly. We design a structured path through whichever framework you're targeting, eliminate the busywork, and focus your effort on the things that actually affect your security posture.

Is this for you?

Compliance isn't the goal — but it can be a forcing function for building something real. If certification is on your roadmap, we make sure you actually get there without destroying your team.

  • UK government contracts or procurement require Cyber Essentials or Cyber Essentials+
  • Enterprise clients or partners require ISO 27001 as a precondition
  • NIS2 or DORA obligations are coming for your sector
  • GDPR compliance has stalled and you need a structured approach
  • You've failed an audit before and need to understand why

What we help with

  • Cyber Essentials / Cyber Essentials+: Typically achievable in 4–8 weeks. We handle the technical controls checklist and submission review.
  • ISO 27001: Full ISMS implementation — gap assessment, risk treatment, policy development, internal audit, and auditor liaison. Usually 3–6 months.
  • NIS2 / DORA:gap analysis against directive requirements, entity classification, essential entity obligations assessment, and remediation roadmap.
  • GDPR: Data flow mapping, DPIA support, subject access request handling, breach notification procedures.

Day rate

From £1,400 per day. Engagements scoped at the start with clear milestones — no surprise bills.