Back to Services

Compliance &
Governance

Navigate the regulatory landscape with confidence. We map your controls to the frameworks that matter, identifying gaps, guiding remediation, and ensuring your security programme is audit-ready and defensible.

Frameworks & Standards

Frameworks We Work With

We speak the language of your regulators, auditors, and customers, assessing against the frameworks that are most material to your business.

NIST CSF 2.0 & RMF

NIST Frameworks

Maturity assessment across the six CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover), plus Risk Management Framework support for federal and regulated-sector clients.

CSF 2.0 RMF
ISO 27001:2022

ISO 27001

Full gap analysis against the 93 Annex A controls, ISMS scoping, Statement of Applicability development, and pre-audit readiness support, from first assessment through to certification.

Gap Analysis Cert Readiness
SOC 2 Type I & II

SOC 2

Readiness assessment against the five Trust Services Criteria, evidence collection support, and pre-audit testing to ensure you achieve SOC 2 Type I and Type II with minimal surprises.

Type I/II TSC Mapping
HIPAA / HITECH

HIPAA

Security Rule and Privacy Rule assessments for healthcare organisations and business associates, including required risk analysis, documentation review, and technical safeguard evaluation.

Security Rule Risk Analysis
CMMC 2.0

CMMC

Cybersecurity Maturity Model Certification readiness for defence contractors, covering Level 1 through Level 3 practice domains, gap assessment, and System Security Plan development.

Level 1-3 SSP Support
UK GDPR / Data Protection

GDPR & UK GDPR

Data protection impact assessments, records of processing activity (ROPA), breach notification readiness, and technical/organisational measure reviews aligned to ICO expectations.

DPIA ROPA ICO Ready
Risk Assessment

Gap Analysis &
Control Mapping

Compliance is only valuable when it reflects genuine security. Our gap analyses go deeper than tick-box exercises, assessing not just whether a control exists, but whether it actually works.

Current State Assessment
Structured interviews, document reviews, and technical testing to establish your existing control posture against the target framework.
Gap Identification & Prioritisation
Control gaps identified, evidenced, and risk-rated, so you know which remediation actions will have the greatest compliance and security impact.
Remediation Roadmap
A time-bound, effort-estimated remediation plan, sequenced to meet your certification deadline while maintaining business operations.
Evidence Pack & Documentation
Auditor-ready evidence documentation, policies, procedures, control testing records, and a compliance matrix, structured for seamless handover to your chosen certifying body.
Simulation Exercises

Compliance Incident TTX

Compliance failures become costly when teams do not know how to respond. Our compliance-focused tabletop exercises test your incident response against your regulatory obligations, not just technical controls.

Data Breach Notification Drill

Simulate a personal data breach and walk teams through GDPR 72-hour notification requirements, testing who makes the decision, what evidence is needed, and what gets communicated to the ICO and data subjects.

Regulatory Investigation Scenario

Simulate a regulator's information request or audit, testing your ability to retrieve evidence quickly, respond within deadlines, and coordinate across legal, IT, and compliance functions under pressure.

Third-Party Compliance Failure

A key supplier fails their SOC 2 audit or suffers a breach. Exercise tests: vendor contract triggers, business continuity, customer notification obligations, and how you evidence your due diligence.

6+
Major frameworks covered across our compliance practice
100%
of assessments include executive-ready reporting
Get Started

Audit-Ready.
Genuinely Secure.

Book a free compliance scoping call. We will discuss your regulatory obligations, your current posture, and the fastest path to readiness, no jargon, no unnecessary complexity.