Skip to content

Services

Compliance & Regulatory

Six frameworks asking overlapping questions. One evidence base that answers all of them.

Prove it once. Use the proof everywhere.

Compliance becomes expensive at the moment it fragments. A NIS2 programme run by one team, an ISO 27001 project run by another, a SOC 2 audit answered by a third, and a GDPR register nobody has opened since it was written. The same control gets implemented three times, evidenced three ways, and maintained by nobody.

We work the other way round. One unified control framework, mapped across NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act. A control is designed once, implemented once, and its evidence is produced once — then reused by every audit that asks for it. In practice the overlap is around seventy per cent.

The other half of this practice is the calendar. Certificates need maintaining, registers need updating, and regulations change. That work is better done continuously at a known monthly cost than rediscovered eight weeks before a surveillance audit.

Compliance & Regulatory

European cybersecurity regulation

NIS2, DORA and the CRA, translated from legal text into a plan with dates and owners.

  • NIS2, DORA and CRA applicability assessmentTypical duration: 2–4 days

    A short, decisive answer to the question that blocks everything else: which regulations apply to which of your entities, in which member states, and from when.

    You receive

    • Entity-by-entity applicability analysis
    • Classification as essential, important or out of scope
    • Registration and notification obligations
    • Deadline calendar per jurisdiction
  • NIS2 gap analysis and compliance programmeTypical duration: 10–30 days

    Assessment against the ten measures of Article 21 and the governance duties of Article 20, followed by a programme that closes the gaps in the order a regulator would expect.

    You receive

    • Gap analysis against Articles 20 and 21
    • Management body training and accountability record
    • Incident notification procedure (24h, 72h, one month)
    • Compliance programme with owners and dates
  • DORA compliance programmeTypical duration: 20–60 days

    The full DORA scope for financial entities and their ICT providers: ICT risk management, incident classification and reporting, the register of information, and preparation for threat-led penetration testing.

    You receive

    • ICT risk management framework
    • Register of information, ready for submission
    • Incident classification and reporting procedure
    • Third-party contract remediation plan and TLPT readiness
  • Cyber Resilience Act complianceTypical duration: 15–40 days

    For manufacturers and software vendors placing products on the EU market: security by design, vulnerability handling, SBOM, and the technical documentation the CRA requires you to keep.

    You receive

    • Product classification and conformity route
    • Secure development and vulnerability handling process
    • SBOM generation and maintenance
    • Technical documentation and declaration of conformity
  • Supplier compliance and security assurance plansTypical duration: 3–8 days

    The security annexes, assurance plans and audit rights that make your contracts defensible, whether you are the client asking or the supplier answering.

    You receive

    • Security assurance plan template
    • Contractual security annex
    • Supplier evidence review
    • Audit and exit clauses

Standards and certifications

ISO 27001 and SOC 2 run as projects with a date, not as open-ended programmes.

  • ISO/IEC 27001:2022 certification supportTypical duration: 6–14 months

    From scoping to the certification audit: statement of applicability, risk treatment, documented information, internal audit and management review, with the certification body chosen early.

    You receive

    • Scope, SoA and risk treatment plan
    • Complete documented ISMS
    • Internal audit and management review
    • Stage 1 and Stage 2 audit support
  • ISO 27001 internal audit and maintenanceTypical duration: Recurring

    The annual cycle that keeps the certificate: internal audit programme, management review, corrective actions and surveillance audit preparation, run without consuming your team.

    You receive

    • Annual internal audit programme
    • Audit reports and non-conformities
    • Management review pack
    • Surveillance audit preparation
  • SOC 2 Type I and Type IITypical duration: 4–12 months

    Trust services criteria selected for what your customers actually ask about, controls designed to be evidenced automatically, and an auditor engaged at the right moment.

    You receive

    • Criteria selection and control matrix
    • Control design and evidence automation
    • Readiness assessment before the audit
    • Audit coordination through to report
  • ISO 27017, 27018, 27701 and 22301 extensionsTypical duration: 10–30 days

    Extensions built on an existing ISO 27001 system: cloud controls, personal data in the cloud, a privacy information management system, or business continuity.

    You receive

    • Extension scoping and delta analysis
    • Additional controls and documentation
    • Integration with the existing ISMS
    • Audit preparation
  • HDS, SecNumCloud, PCI DSS and TISAXTypical duration: Scoped per engagementDelivered with a qualified partner

    Sector and national qualifications prepared with qualified partners, so the scheme-specific requirements are handled by people who hold the qualification themselves.

    You receive

    • Scheme applicability and scoping
    • Gap analysis against the reference framework
    • Remediation plan with partner support
    • Assessment coordination

Personal data

GDPR and the local laws that apply wherever your data actually sits.

  • GDPR audit and complianceTypical duration: 8–20 days

    Records of processing that reflect reality, lawful bases that hold, retention actually enforced, and a data subject request process that meets the one-month clock.

    You receive

    • Record of processing activities
    • Lawful basis and retention analysis
    • Data subject rights procedure
    • Remediation plan with priorities
  • Outsourced data protection officerTypical duration: Recurring

    A designated DPO with the independence the regulation requires, handling the register, the impact assessments, the requests and the relationship with the supervisory authority.

    You receive

    • DPO designation and authority notification
    • Register and DPIA maintenance
    • Data subject request handling
    • Annual DPO report to management
  • DPIA and privacy by designTypical duration: 3–10 days

    Impact assessments for the processing that needs one, and design reviews early enough that the answer can still change the architecture.

    You receive

    • DPIA screening and full assessments
    • Design review with privacy requirements
    • Mitigation measures and residual risk
    • Consultation file if required
  • International transfers and local lawsTypical duration: 5–15 days

    Transfer mechanisms, impact assessments and local registration duties across the jurisdictions we cover: Tunisia, Morocco, Senegal, Ivory Coast, Brazil (LGPD), Argentina and Colombia.

    You receive

    • Transfer mapping and mechanism selection
    • Transfer impact assessments
    • Local law gap analysis per country
    • Local registration and filing support

Artificial intelligence

The AI Act and ISO 42001, applied to the systems you are already deploying.

  • AI Act qualificationTypical duration: 3–8 days

    For each AI system: are you a provider or a deployer, is it prohibited, high risk, limited risk or minimal, and which obligations start on which date.

    You receive

    • AI system inventory
    • Role and risk classification per system
    • Obligation matrix with dates
    • Decision record for the file
  • AI Act high-risk complianceTypical duration: 15–40 days

    The full obligation set for high-risk systems: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment.

    You receive

    • AI risk management system
    • Data governance and quality measures
    • Technical documentation file
    • Human oversight design and conformity route
  • ISO/IEC 42001 AI management systemTypical duration: 20–40 days

    A management system for AI that carries much of the AI Act evidence with it, built on your existing ISO 27001 system rather than alongside it.

    You receive

    • Scope and AI policy
    • AI impact assessment process
    • Controls and documented information
    • Internal audit and certification preparation
  • Generative AI acceptable-use policyTypical duration: 3–6 days

    A short, usable policy that says which tools are approved, what may be pasted into them, who reviews the output, and what happens to shadow AI already in use.

    You receive

    • Acceptable-use policy
    • Approved tool list and approval route
    • Data classification rules for prompts
    • Staff communication pack

Compliance governance

One control framework, one evidence base, every audit served from it.

  • Unified control frameworkTypical duration: 5–12 days

    One set of controls mapped across NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act, so evidence is produced once and answers every audit that asks for it.

    You receive

    • Unified control catalogue
    • Cross-framework mapping matrix
    • Evidence plan per control
    • Audit response playbook
  • GRC toolingTypical duration: 5–15 days

    Selection and implementation of a compliance platform — Vanta, Drata, Secureframe or a European alternative — configured around your control framework rather than the vendor's default.

    You receive

    • Requirements and tool selection
    • Platform configuration and integrations
    • Automated evidence collection
    • Team handover and runbook
  • Board and executive trainingTypical duration: 2–4 hours

    A focused session for directors on what NIS2 and DORA make them personally accountable for, what to ask, and what a good answer sounds like.

    You receive

    • Tailored session for the management body
    • Director obligation briefing note
    • Question set for oversight
    • Attendance record for the compliance file
  • Compliance-as-a-ServiceTypical duration: Recurring

    Compliance run as a subscription: the calendar, the evidence, the internal audits, the supplier reviews and the regulatory watch, handled continuously instead of in an annual panic.

    You receive

    • Annual compliance calendar
    • Continuous evidence collection
    • Quarterly compliance report
    • Regulatory change watch

NIS2 Ready

From applicability to a defensible compliance position, with the governance duties covered.

Duration
8–12 weeks
Price
€18,000 to €35,000
excl. VAT, indicative

Discuss this pack — NIS2 Ready

DORA Essentials

The four DORA pillars covered, including the register of information ready for submission.

Duration
10–16 weeks
Price
€30,000 to €60,000
excl. VAT, indicative

Discuss this pack — DORA Essentials

ISO 27001 in 9 months

A certification project with a date, a fixed price and a certification body engaged early.

Duration
9 months
Price
€25,000 to €45,000
excl. VAT, indicative, excludes certification body fees

Discuss this pack — ISO 27001 in 9 months

SOC 2 Fast Track

Type I, then the observation window for Type II, with evidence collected automatically.

Duration
4–6 months
Price
€20,000 to €40,000
excl. VAT, indicative, excludes auditor fees

Discuss this pack — SOC 2 Fast Track

AI Act Check

Every AI system inventoried, classified and dated, with the obligations that follow.

Duration
3–4 weeks
Price
€6,000 to €12,000
excl. VAT, indicative

Discuss this pack — AI Act Check

Compliance-as-a-Service

Your compliance obligations run continuously: evidence collected as it is produced, internal audits on schedule, regulatory changes watched, and the audit answered without a scramble.

What is included

  • Annual compliance calendar
  • Continuous evidence collection
  • Internal audit programme
  • Quarterly compliance report
  • Regulatory change watch

Available tiers

  • One framework
  • Two frameworks
  • Multi-framework
Compliance

Discuss this service — Compliance-as-a-Service

Outsourced DPO

A designated data protection officer with the independence the GDPR requires, handling the register, impact assessments, data subject requests and the supervisory authority.

What is included

  • DPO designation and notification
  • Register and DPIA maintenance
  • Data subject request handling
  • Staff advice and training
  • Annual report to management
Compliance

Discuss this service — Outsourced DPO

Multi-country regulatory support

One point of contact for regulatory questions across Europe, French-speaking Africa and South America, answered with local partners who practise in that jurisdiction.

What is included

  • Regulatory watch per country
  • Local filing and registration support
  • Cross-border transfer maintenance
  • Local partner coordination
  • Consolidated quarterly briefing
Compliance

Discuss this service — Multi-country regulatory support

Start with applicability

Two to four days settles which regulations apply to which entity, from when, and what has to be registered. Everything else is easier to plan afterwards.