Regulatory readiness

Compliance that survives an audit

Gap analysis scoped against the engineering capacity you actually have, a dated path to close it, and evidence packages written the way an auditor reads them.

Frameworks

Three regimes, one control set

They overlap more than the consultancies suggest. Implement once, evidence three times.

NIS2

Network and Information Security Directive

Applies to essential and important entities, and reaches their suppliers through contract. Management bodies are personally accountable for approving risk-management measures.

  • Scope and entity classification
  • Incident notification within 24 hours
  • Supply-chain security clauses
  • Management liability and board reporting
ISO 27001

Information Security Management System

The certification most customers ask for by name. We take you from gap analysis to a Stage 2 audit that does not produce major nonconformities.

  • Scope definition and statement of applicability
  • Risk assessment methodology
  • Annex A control implementation
  • Internal audit and management review
DORA

Digital Operational Resilience Act

For financial entities and their critical ICT providers. Heavier on testing and third-party register obligations than most teams expect going in.

  • ICT risk management framework
  • Threat-led penetration testing
  • Third-party register and exit plans
  • Major incident classification
Approach

Four steps, no binder

01

Gap analysis against what exists

We audit the controls you actually operate, not the ones the policy describes. The output is a list of gaps with an estimate of the engineering effort each one costs to close.

02

A dated path, not a recommendation deck

Gaps are sequenced against your delivery calendar and your headcount. If the plan requires capacity you do not have, it is not a plan, and we will say so.

03

Implementation alongside your team

We write the evidence, your engineers own the control. A programme that depends on the consultancy staying is a programme that fails at renewal.

04

Audit support and board reporting

Evidence packages prepared the way an auditor reads them, and a quarterly report short enough that your management body actually reviews it.

Straight answers

Three things we correct in most first meetings

“Certification means we are secure.”

It means a management system exists and is being followed. Every organisation we have responded to an incident for held at least one certificate.

“We are too small for NIS2.”

Size thresholds apply to named sectors. Obligations reach smaller suppliers through customer contracts, which is how most organisations first encounter them.

“We can do this in a quarter.”

A first ISO 27001 certification typically takes eight to twelve months from a standing start. Anyone promising a quarter is selling documents, not a system.

Find out where you actually stand

A gap analysis takes three weeks and tells you what the next twelve months cost.

Request a gap analysis