Skip to content
Service

Compliance & Consulting

Full GRC lifecycle: ISO 27001:2022, ISO 27002 internal audit, PCI DSS v4.0.1, SWIFT CSCF 2026, NCA ECC:2024, SOC 2 Type 1 & 2. Gap analysis through audit support.

Quoted on scope, fixed price.

Teams who have had us test their systems

  • Riverbed
  • Dynasend
  • Melp
  • Code Avengers
  • AVLOAI
  • Ames d.o.o.
  • Logicdialog
  • Selip & Stylianou, LLP

What this covers

Compliance doesn't have to be a soul-crushing exercise in spreadsheet management. We help startups build security programs that actually work - policies you'll follow, controls you'll maintain, and evidence you can produce in hours, not weeks. Our consultants are former startup CTOs, security engineers, and compliance auditors who have been on both sides of the table. We don't hand you a template library and disappear. We work with your team to understand how you actually operate, then build a compliance program that fits your reality - not a Fortune 500 framework shoehorned into a 20-person startup. We specialize in ISO 27001, SOC 2 Type II, PCI-DSS, HIPAA, and GDPR readiness. Most engagements start with a gap analysis, move through control implementation, and end with audit support - we're in the room (virtually) with your auditors.

  • Pass your certification audit on the first attempt
  • Close enterprise deals with compliance-ready documentation
  • Build a security program that satisfies auditors without slowing your team
  • Stay compliant with continuous monitoring and quarterly reviews

Scope

What gets tested

Ten areas, agreed on the scoping call and written into the rules of engagement before anything starts.

  • ISO/IEC 27001:2022

    Full ISMS implementation - 93 controls, gap analysis, internal mock audit.

  • ISO 27002 Internal Audit

    Independent Annex A control testing, NCRs, corrective action planning.

  • PCI DSS v4.0.1

    CDE scoping, 12 requirements, customized approach, RoC/SAQ readiness.

  • SWIFT CSP CSCF 2026

    Architecture assessment, CSCF gap analysis, independent assessment readiness.

  • NCA ECC:2024

    5 domains, 29 subdomains, 114 controls - national regulatory compliance.

  • SOC 2 Type 1 & Type 2

    TSC determination, system description, control matrix, CPA preparation.

  • Policy & Control Build-Out

    Custom policies, evidence collection workflows, continuous compliance.

  • Audit Support

    In-room (virtual) audit assistance, auditor liaison, finding resolution.

  • Awareness Training

    Role-based and general security awareness aligned to each framework.

  • Continuous Compliance

    Maintenance planning, quarterly reviews, board/investor reporting.

Methodology

How the work is done

Repeatable, documented, and recorded step by step so you can see what has been looked at.

  1. 01

    Gap Analysis

    Review current policies, controls, and infrastructure against your target framework. Deliver prioritized gap list with effort estimates.

  2. 02

    Control Build-Out

    Work with your team to implement missing controls, write policies, and set up evidence collection. Hands-on, not advisory-only.

  3. 03

    Pre-Audit Readiness

    Internal mock audit to verify everything is working. Fix last gaps before the real thing. Brief your team on what auditors will ask.

  4. 04

    Audit Support & Beyond

    In the room (virtually) during your audit. Help answer auditor questions. Post-audit: maintain compliance with minimal overhead.

Why it matters

What you get out of it

  • Gap Analysis First

    We audit your current state against your target framework and give you a prioritized gap list - so you know exactly what to fix and in what order.

  • Controls That Stick

    We don't write policies you'll never read. We build controls that integrate with your existing tools (Jira, GitHub, Slack, AWS) and workflows.

  • Audit-Ready Evidence

    We help you set up continuous evidence collection so when audit time comes, you produce evidence in hours - not frantic weeks.

  • Startup-Focused

    We understand 20-person startups don't need the same controls as 5,000-person banks. Right-sized compliance that satisfies auditors and customers.

What you receive

Delivered as documents at the end of the engagement, with a call to walk your team through them.

  • Gap analysis report - prioritized by risk, effort, and audit criticality
  • Policy library - customized for your organization, not generic templates
  • Control implementation - evidence collection, tool configuration, and process documentation
  • Audit support - in-room (virtual) support during your certification audit
  • Continuous compliance plan - how to stay compliant without a dedicated compliance team

Standards we test against

Coverage is recorded against these control by control, so “what did you actually check” has an answer.

  • ISO 27001:2022
  • ISO 27002
  • PCI DSS v4.0.1
  • SWIFT CSCF
  • NCA ECC:2024
  • SOC 2
  • HIPAA
  • GDPR
  • NIST CSF
  • CIS Controls

Pricing

What changes the price

Every engagement is quoted on scope rather than hours. These are the four things that move it, and they are what we work through on the call.

  • Framework

    Which standard applies

  • Boundary

    Systems inside the scope

  • Current state

    What already exists

  • Support

    Advice, or documents produced

FAQ

Questions about compliance & consulting

We're a 15-person startup - do we really need SOC 2?

If you sell to US enterprises, yes - SOC 2 is the most-requested security document in enterprise sales. It's not about your size; it's about your customers' requirements. A small team can achieve SOC 2 Type II by right-sizing the controls. A 15-person startup does not need the same control set as a bank - and auditors agree. We make sure you implement only what's required and nothing more.

How long does ISO 27001 / SOC 2 certification take?

Typical timeline is 3-6 months from kickoff to certification, depending on your starting point. Gap analysis takes 2-3 weeks. Control build-out takes 6-12 weeks depending on gaps. The audit itself takes 4-8 weeks (SOC 2 Type II requires a monitoring period). A team that already has strong engineering practices will sit at the shorter end of that range.

Do you work with our existing auditors, or do you provide auditors?

We work with your existing auditors - we're not an audit firm and don't provide audit services (that would be a conflict of interest). We prepare you for the audit, build your controls, and sit alongside you during the audit to answer questions. We can recommend audit firms if you don't have one, but we don't take referral fees for those recommendations.