Skip to content

Compliance readiness

Pass the questionnaire that is holding up the deal.

The evidence enterprise buyers and regulators ask for, gathered without stopping delivery. SOC 2 and ISO 27001 preparation, NDPR and GDPR handling, written policies, access reviews and the audit trail behind them. We get you ready for the audit; the auditor is someone else, and should be.

You are probably here because

  • A deal is blocked on a certification you do not hold.
  • You handle personal data and have never mapped where it goes.
  • Your policies exist in a document nobody has read since it was written.

If none of that sounds like you, this probably is not the service you need, and we would rather say so.

What it does for you

Compliance readiness helps you:

  • Win enterprise deals

    Clear the security review and the procurement questionnaire that stall most vendors.

  • Reduce risk

    Naming what can go wrong in week one costs far less than finding out in month six.

  • Keep your users' trust

    The breach you avoid is the one nobody writes about.

  • Ship sooner

    A quarter saved getting to market is a quarter spent in it instead.

How it runs

Four phases, no dark period.

Built from the bottom
  1. 01

    Gap assessment

  2. 02

    Policies

  3. 03

    Evidence

  4. 04

    Audit readiness

each rung holds the one above

Evidence means nothing without the policy behind it, and policy means nothing without the gap it closes. The ladder is built from the bottom so the audit has somewhere to stand.
  1. 01

    Gap assessment

    Measured against the framework you are being asked for, so effort goes where the gaps are.

  2. 02

    Policies

    Written to be followed rather than filed. If your team cannot follow it, it will not survive the audit either.

  3. 03

    Evidence

    Logging, access reviews and change records collected as a by-product of working, not assembled the week before.

  4. 04

    Audit readiness

    A dry run against the real criteria, so the audit holds no surprises.

Shape
Gap assessment, then evidence and policy work in parallel with the build.
Typical length
8 to 16 weeks to audit-ready
Starts with
The questionnaire or framework you are being measured against.

Deliverables

What actually lands.

Concrete things, in your accounts and your repository, that keep working after we have gone.

  • Gap assessment against your framework
  • Written policies your team will follow
  • Evidence collected and organised
  • Access reviews on a schedule

Before you commit

The questions we get asked.

Do you certify us?
No, and anyone who says they do both is worth a second look. We prepare you; an independent auditor certifies.
How long does it take?
Eight to sixteen weeks to audit-ready for most teams, depending on how much exists already.
Which frameworks?
SOC 2 and ISO 27001 most often, plus NDPR and GDPR handling where personal data is involved.

Not quite what you need?

These sit closest to it. If none of them fit either, say so and we will tell you honestly whether we are the right people.

Next step

Tell us what you're building.

A few lines is enough. What it is, who it's for, when you need it live. Or put half an hour in the calendar and talk it through instead.