Services / Prove and comply / Audit, certification and compliance
03 · Audit, certification and compliance
Pass the audit. Then keep passing it.
Senior-led preparation for any audit or assessment, from certification to framework maturity, with the evidence and ongoing support that keep you compliant year after year.
Assessment readiness
ISO 27001 · PCI DSS · Cyber Essentials · DCC · CAF
- ✓ Scope and objectives agreed
- ✓ Gaps assessed against the framework
- ✓ Prioritised remediation plan
- ✓ Controls operating and evidenced
- ✓ Mock assessment completed
Ready for audit or assessment →
Frameworks and schemes we work to
- IASMECyber Essentials
- IASMECyber Essentials Plus
- MOD · IASMEDefence Cyber Certification
- ISO/IEC27001:2022
- PCI SSCPCI DSS v4
- NISTCSF 2.0
- Cabinet OfficeGovAssure
- NCSCCyber Assessment Framework
- UK GovernmentSecure by Design
- NHS EnglandDSPT
Why it matters
Certification opens doors to contracts and markets. Last-minute preparation is costly and fragile.
The organisations that do well treat compliance as a continuous discipline, not an annual event. We help you build controls that genuinely work, so the audit confirms what is already true.
Sound familiar?
01 A customer or tender now asks for a certification or assessment.
02 Your audit date is set and the evidence is scattered.
03 You passed last year, but controls have drifted since.
How we help
From first gap to every audit after.
01
Get ready
- Certification readiness
Scope, risk assessment and a plan to meet ISO/IEC 27001, Cyber Essentials or PCI DSS. - NIST CSF 2.0 maturity assessment
Benchmark today against the six CSF functions and set a realistic target profile. - Gap assessment
A clear view of where you stand against the framework, with prioritised actions.
02
Get certified
- Mock audits and assessments
A realistic rehearsal, so there are no surprises on the day. - Evidence and documentation packs
Policies, records and evidence organised the way assessors expect to see them. - Control effectiveness testing
Proof that each control works in practice, not just on paper. - Independent cyber security audits
An objective view for boards, customers or investors.
03
Stay compliant
- Internal audits
The internal audit programme your standard requires, delivered by Lead Auditors. - Continuous compliance support
Regular check-ins that keep evidence current between audits.
Frameworks we support
The standards your customers and regulators ask for.
Certify
ISO/IEC 27001:2022
The international standard for an information security management system.
Often needed for: Enterprise and international contracts
Certify
PCI DSS v4
The security standard for anyone who stores, processes or transmits card data.
Often needed for: Merchants and payment service providers
Certify
Cyber Essentials
UK government-backed scheme covering five technical controls, including Cyber Essentials Plus.
Often needed for: Government contracts and supply chains
Certify
Defence Cyber Certification
The MOD’s certification scheme for defence suppliers, run with IASME. Four levels, all built on Cyber Essentials.
Often needed for: MOD contracts and the defence supply chain
Assess
NCSC Cyber Assessment Framework
Outcome-based assessment for essential services and critical national infrastructure.
Often needed for: Operators of essential services and public bodies
Assess
UK GovAssure
The government cyber assurance scheme for departments and arm’s-length bodies, built on the CAF.
Often needed for: Central government departments
Assess
UK Secure by Design
The government approach to building security into digital services from the start.
Often needed for: Government digital teams and their suppliers
Something else?
Working to another framework?
Tell us which. We map controls across standards, so work done once counts many times.
A typical engagement
Five steps. No surprises on audit day.
01
Scoping call
Free, 30 minutes. What needs assessing, by when, and why.
02
Gap assessment
A clear view of where you stand against the framework, with a prioritised plan.
03
Remediation support
We work alongside your team to close gaps and build evidence.
04
Mock assessment
A full rehearsal, so the real assessment holds no surprises.
05
Assess and sustain
Your assessor or certification body reviews. We keep you ready for the next one.
What you walk away with
■ Gaps closed before the auditor arrives
■ Evidence ready whenever it is asked for
■ Compliance that holds all year
Who you work with
Auditors who have sat on both sides.
ISO/IEC 27001 Lead Auditors
Certified auditors lead every engagement.
Programmes delivered
PCI DSS and ISO 27001 for global security vendors.
Independent
We prepare you for the audit. We never sell it.
Related services
Is your next audit already booked?
Book a free 30-minute call. We will tell you honestly where you stand and what it will take to be ready.