One control set, mapped across every obligation you carry.
Most industrial organisations are subject to several overlapping regimes at once — a sector regulator, a management system standard, a customer's contractual requirements and a data protection law. Run separately they duplicate effort and contradict each other. We map them onto one control set and one evidence base.
- One evidence base
- Many obligations
- Clause-level
- Traceable mapping
- Audit-ready
- Before the assessor
Standards in scope
NIS2
EU network and information security directive
ISO/IEC 27001
Information security management system
Sector guidance
National and regulator cybersecurity requirements
Data protection
Privacy and data protection obligations
Regimes we most often reconcile.
The goal is never certification for its own sake. It is to satisfy every obligation you actually carry with the smallest set of controls that genuinely reduces risk.
EU network and information security directive
Applicability, governance accountability, risk management measures, incident reporting timelines and supply chain obligations for essential and important entities.
How we support you
- Entity classification and applicability analysis
- Governance and management accountability setup
- Risk management measure gap assessment
- Incident reporting process and timelines
- Supply chain security requirements
- Evidence pack for supervisory review
Information security management system
The management system that most other obligations can hang from — scope, risk treatment, Statement of Applicability and the operating rhythm behind certification.
How we support you
- ISMS scoping and gap assessment
- Risk assessment and treatment planning
- Statement of Applicability development
- Documented policy and procedure set
- Internal audit programme and management review
- Certification audit support
National and regulator cybersecurity requirements
Sector-specific cybersecurity guidance for critical infrastructure operators, which usually assumes but does not restate the underlying technical standards.
How we support you
- Obligation inventory for your sector and region
- Mapping onto existing IEC 62443 evidence
- Reporting and notification process design
- Regulator engagement documentation
- Self-assessment and submission support
- Finding closure tracking
Privacy and data protection obligations
Where operational and customer data intersect — lawful basis, retention, cross-border transfer and the breach obligations that sit alongside cyber incident reporting.
How we support you
- Data inventory and processing map
- Retention and transfer assessment
- Consent and notice review
- Breach notification alignment with cyber reporting
- Processor and vendor agreement review
- Privacy and security control reconciliation
What a compliance engagement covers.
The same seven services run across every practice, so you can compare scope without re-learning the menu.
Risk assessment
Risk assessment that satisfies several regimes at once rather than repeating the exercise for each auditor.
Advisory & consulting
Working out which obligations genuinely apply, in which order they bite, and where certification is worth the cost.
VA-PT & security testing
Control testing and evidence verification — checking that what is documented is what actually happens.
Compliance & audit readiness
Cross-framework mapping, gap analysis, internal audit and audit-day support with findings tracked to closure.
Implementation support
Closing gaps with controls that serve operations, not just the auditor, and embedding them into normal work.
Security operations
Ongoing obligation tracking, reporting cadence and surveillance audit readiness between certification cycles.
Training & capability
Awareness for staff in scope, and preparation for the people who will face the assessor's questions.
Typical starting points
- A customer contract that demands certification
- A regulator letter with a deadline attached
- A failed or qualified audit finding
- Expansion into a market with new obligations
- Multiple frameworks being run in parallel
- An acquisition inheriting unknown obligations
- First-time certification with no baseline
- Recertification after a lapsed programme
What you receive
- Obligation inventory across every applicable regime
- Cross-framework control mapping matrix
- Gap assessment with prioritised remediation plan
- Policy, procedure and evidence documentation set
- Internal audit reports and corrective action tracker
- Audit-ready evidence pack per framework
Facing an audit, a regulator or a customer requirement?
Tell us which frameworks are in play and the deadline, and we will map what overlaps and what genuinely needs new work.