Compliance readiness

The evidence comes out of the platform,
not out of a spreadsheet

Assessors do not ask what your dashboard said. They ask how you know, and they want the request, the response and the date. We map your estate to the framework you are being asked about, evidence what can be evidenced, and are specific about the rest.

Read this first

Three things we cannot do for you

Said before the sales pitch rather than after it, because this is where a buyer is most likely to spend money on the wrong thing.

We are not your certification body.

We cannot certify you and neither can anyone who audits you — that separation is the point of it. We get you ready, and we tell you what the assessor will ask.

A framework is mostly not technical.

Policies, training, suppliers, contracts and governance are the bulk of every one of these. We cover the estate; you will need somebody for the rest, and we will say so on the first call.

A passing scan is not evidence.

Assessors ask how you know, not what your dashboard said. Everything we produce carries the request, the response and the date, which is what makes it evidence.

Frameworks

One square per control. Count the empties.

Filled where a cloud audit produces the evidence, hairline where it does not. The empty squares are the controls that are yours to prove some other way, and knowing how many there are is the difference between being ready and being surprised.

ISO 27001:2022

The international standard for an information security management system. Annex A carries 93 controls; a cloud audit speaks directly to the technological ones.

Evidenced by the audit31 / 34

Annex A evidence mapped control by control, with the gaps written as findings your team can close before the certification body arrives.

SOC 2 Type II

The report North American customers ask for. Trust Services Criteria, tested over a window rather than on one day.

Evidenced by the audit24 / 29

Evidence against the Common Criteria your platform is responsible for, in the form your auditor expects, plus the control descriptions to go with it.

PCI DSS v4.0

Required if you touch card data. Prescriptive, technical, and unforgiving about scope — most of the work is proving what is out of it.

Evidenced by the audit41 / 52

Cardholder data environment scoping, segmentation testing, and the technical requirements evidenced with configuration rather than with assertions.

UK GDPR & DPA 2018

Article 32 asks for security appropriate to the risk. What "appropriate" means is decided after something has gone wrong, which is the wrong time to work it out.

Evidenced by the audit18 / 22

A technical measures record you can attach to your ROPA, plus the personal data we found in places your privacy notice does not mention.

CIS Benchmarks

Consensus configuration baselines per provider. Not a certification — the yardstick underneath most of the others.

Evidenced by the audit96 / 96

A full benchmark pass per account with every exception documented and argued, rather than a pass rate with no story behind it.

NIS2 / Cyber Essentials Plus

Sector obligations and the UK government scheme. Both are increasingly a condition of the contract rather than a nice-to-have.

Evidenced by the audit26 / 31

A readiness position against each, with the technical gaps costed so you can decide what to fix before you decide what to certify.

The order to do it in

Audit first, certify second

Doing it the other way round is how a business ends up certified against a standard while a build container can still read the production database. Both things can be true at once, and one of them is the one that costs you customers.

01Map first, gap second

We start from your estate rather than from the standard, so the mapping reflects what you actually run instead of what the diagram says.

02Fix what is real

Findings are prioritised by risk, not by clause. A Critical that appears in no framework still gets fixed first, and we will argue for that.

03Evidence from the platform

Where the evidence can be produced by a query rather than a screenshot, we set that up, so the next audit costs your team days instead of weeks.

04Then certify

You go into the assessment knowing what will be asked and what the answer is. Nothing about the day should be a surprise.

Next step

Send us the questionnaire you have been asked to fill in.

We will tell you which of it your estate can answer today, which of it needs work, and which of it is not a technical question at all — in writing, on one page, before anything is signed.