Services  /  Prove and comply  /  Audit, certification and compliance

03 · Audit, certification and compliance

Pass the audit. Then keep passing it.

Senior-led preparation for any audit or assessment, from certification to framework maturity, with the evidence and ongoing support that keep you compliant year after year.

Assessment readiness

ISO 27001 · PCI DSS · Cyber Essentials · DCC · CAF

  • ✓  Scope and objectives agreed
  • ✓  Gaps assessed against the framework
  • ✓  Prioritised remediation plan
  • ✓  Controls operating and evidenced
  • ✓  Mock assessment completed

Ready for audit or assessment →

Frameworks and schemes we work to

  • IASMECyber Essentials
  • IASMECyber Essentials Plus
  • MOD · IASMEDefence Cyber Certification
  • ISO/IEC27001:2022
  • PCI SSCPCI DSS v4
  • NISTCSF 2.0
  • Cabinet OfficeGovAssure
  • NCSCCyber Assessment Framework
  • UK GovernmentSecure by Design
  • NHS EnglandDSPT

Why it matters

Certification opens doors to contracts and markets. Last-minute preparation is costly and fragile.

The organisations that do well treat compliance as a continuous discipline, not an annual event. We help you build controls that genuinely work, so the audit confirms what is already true.

Sound familiar?

01   A customer or tender now asks for a certification or assessment.

02   Your audit date is set and the evidence is scattered.

03   You passed last year, but controls have drifted since.

How we help

From first gap to every audit after.

01

Get ready

  • Certification readiness
    Scope, risk assessment and a plan to meet ISO/IEC 27001, Cyber Essentials or PCI DSS.
  • NIST CSF 2.0 maturity assessment
    Benchmark today against the six CSF functions and set a realistic target profile.
  • Gap assessment
    A clear view of where you stand against the framework, with prioritised actions.

02

Get certified

  • Mock audits and assessments
    A realistic rehearsal, so there are no surprises on the day.
  • Evidence and documentation packs
    Policies, records and evidence organised the way assessors expect to see them.
  • Control effectiveness testing
    Proof that each control works in practice, not just on paper.
  • Independent cyber security audits
    An objective view for boards, customers or investors.

03

Stay compliant

  • Internal audits
    The internal audit programme your standard requires, delivered by Lead Auditors.
  • Continuous compliance support
    Regular check-ins that keep evidence current between audits.

Frameworks we support

The standards your customers and regulators ask for.

Certify

ISO/IEC 27001:2022

The international standard for an information security management system.

Often needed for: Enterprise and international contracts

Certify

PCI DSS v4

The security standard for anyone who stores, processes or transmits card data.

Often needed for: Merchants and payment service providers

Certify

Cyber Essentials

UK government-backed scheme covering five technical controls, including Cyber Essentials Plus.

Often needed for: Government contracts and supply chains

Certify

Defence Cyber Certification

The MOD’s certification scheme for defence suppliers, run with IASME. Four levels, all built on Cyber Essentials.

Often needed for: MOD contracts and the defence supply chain

Assess

NCSC Cyber Assessment Framework

Outcome-based assessment for essential services and critical national infrastructure.

Often needed for: Operators of essential services and public bodies

Assess

UK GovAssure

The government cyber assurance scheme for departments and arm’s-length bodies, built on the CAF.

Often needed for: Central government departments

Assess

UK Secure by Design

The government approach to building security into digital services from the start.

Often needed for: Government digital teams and their suppliers

Something else?

Working to another framework?

Tell us which. We map controls across standards, so work done once counts many times.

Ask us →

A typical engagement

Five steps. No surprises on audit day.

01

Scoping call

Free, 30 minutes. What needs assessing, by when, and why.

02

Gap assessment

A clear view of where you stand against the framework, with a prioritised plan.

03

Remediation support

We work alongside your team to close gaps and build evidence.

04

Mock assessment

A full rehearsal, so the real assessment holds no surprises.

05

Assess and sustain

Your assessor or certification body reviews. We keep you ready for the next one.

What you walk away with

■  Gaps closed before the auditor arrives

■  Evidence ready whenever it is asked for

■  Compliance that holds all year

Who you work with

Auditors who have sat on both sides.

ISO/IEC 27001 Lead Auditors

Certified auditors lead every engagement.

Programmes delivered

PCI DSS and ISO 27001 for global security vendors.

Independent

We prepare you for the audit. We never sell it.

Related services

04

Public sector assurance

CAF, GovAssure and DSPT for public bodies.

05

Third-party and supply chain risk

Answer customer questionnaires with confidence.

+

Ongoing advisory

Continuous compliance between audits.

Is your next audit already booked?

Book a free 30-minute call. We will tell you honestly where you stand and what it will take to be ready.