Consulting · Compliance Advisory

One control set, mapped across every obligation you carry.

Most industrial organisations are subject to several overlapping regimes at once — a sector regulator, a management system standard, a customer's contractual requirements and a data protection law. Run separately they duplicate effort and contradict each other. We map them onto one control set and one evidence base.

One evidence base
Many obligations
Clause-level
Traceable mapping
Audit-ready
Before the assessor

Standards in scope

  • NIS2

    EU network and information security directive

  • ISO/IEC 27001

    Information security management system

  • Sector guidance

    National and regulator cybersecurity requirements

  • Data protection

    Privacy and data protection obligations

Standards

Regimes we most often reconcile.

The goal is never certification for its own sake. It is to satisfy every obligation you actually carry with the smallest set of controls that genuinely reduces risk.

NIS2

EU network and information security directive

Applicability, governance accountability, risk management measures, incident reporting timelines and supply chain obligations for essential and important entities.

How we support you

  • Entity classification and applicability analysis
  • Governance and management accountability setup
  • Risk management measure gap assessment
  • Incident reporting process and timelines
  • Supply chain security requirements
  • Evidence pack for supervisory review
ISO/IEC 27001

Information security management system

The management system that most other obligations can hang from — scope, risk treatment, Statement of Applicability and the operating rhythm behind certification.

How we support you

  • ISMS scoping and gap assessment
  • Risk assessment and treatment planning
  • Statement of Applicability development
  • Documented policy and procedure set
  • Internal audit programme and management review
  • Certification audit support
Sector guidance

National and regulator cybersecurity requirements

Sector-specific cybersecurity guidance for critical infrastructure operators, which usually assumes but does not restate the underlying technical standards.

How we support you

  • Obligation inventory for your sector and region
  • Mapping onto existing IEC 62443 evidence
  • Reporting and notification process design
  • Regulator engagement documentation
  • Self-assessment and submission support
  • Finding closure tracking
Data protection

Privacy and data protection obligations

Where operational and customer data intersect — lawful basis, retention, cross-border transfer and the breach obligations that sit alongside cyber incident reporting.

How we support you

  • Data inventory and processing map
  • Retention and transfer assessment
  • Consent and notice review
  • Breach notification alignment with cyber reporting
  • Processor and vendor agreement review
  • Privacy and security control reconciliation
Services

What a compliance engagement covers.

The same seven services run across every practice, so you can compare scope without re-learning the menu.

Risk assessment

Risk assessment that satisfies several regimes at once rather than repeating the exercise for each auditor.

Advisory & consulting

Working out which obligations genuinely apply, in which order they bite, and where certification is worth the cost.

VA-PT & security testing

Control testing and evidence verification — checking that what is documented is what actually happens.

Compliance & audit readiness

Cross-framework mapping, gap analysis, internal audit and audit-day support with findings tracked to closure.

Implementation support

Closing gaps with controls that serve operations, not just the auditor, and embedding them into normal work.

Security operations

Ongoing obligation tracking, reporting cadence and surveillance audit readiness between certification cycles.

Training & capability

Awareness for staff in scope, and preparation for the people who will face the assessor's questions.

Environments

Typical starting points

  • A customer contract that demands certification
  • A regulator letter with a deadline attached
  • A failed or qualified audit finding
  • Expansion into a market with new obligations
  • Multiple frameworks being run in parallel
  • An acquisition inheriting unknown obligations
  • First-time certification with no baseline
  • Recertification after a lapsed programme
Work products

What you receive

  • Obligation inventory across every applicable regime
  • Cross-framework control mapping matrix
  • Gap assessment with prioritised remediation plan
  • Policy, procedure and evidence documentation set
  • Internal audit reports and corrective action tracker
  • Audit-ready evidence pack per framework
Consulting enquiries

Facing an audit, a regulator or a customer requirement?

Tell us which frameworks are in play and the deadline, and we will map what overlaps and what genuinely needs new work.

Raise an enquiry otfuriouswarrior@svratechcyber.com