Report an Incident Become a Partner Careers Contact
Book a Demo
Risk & compliance · frameworks

Map it once.
Answer every framework.

Most organisations run the same programme three times, because ISO, SOC 2 and the regulator each get treated as a separate project. They are largely the same controls in different words, and doing them once is the difference between a quarter of work and a year of it.

One control set · many frameworksmapped
CTRLAccess, logging, IR, suppliersbuilt once
NIS2Mapped to essential entity obligationscovered
SOC2Mapped to trust services criteriacovered
27001Mapped to Annex A controlscovered
GAPControl designed, no operating evidenceflagged
SOCEvidence produced as the service runscontinuous
Why this is cheaper than it looks

The second framework
is mostly the first one again.

Access control, logging, incident response, supplier management, change control, encryption. Every standard asks for them. They just ask in different language, in a different order, with different evidence.

Treated as separate projects, that redundancy is invisible and you pay for it every time. A team assesses against ISO, writes the policies, gathers the evidence and signs off. Eighteen months later a large customer asks for SOC 2 and most of the same work happens again, by different people, in a different format.

Mapped properly, one control satisfies its equivalents across every framework you are held to, and the evidence is gathered once. Adding a second standard becomes a gap exercise against what already exists rather than a fresh programme. That mapping is carried by the platform we run for you, which is why this does not cost what a consultancy would charge to do it by hand.

  • One control set, mapped across every framework in scope.
  • Evidence gathered once and reused, rather than re-collected per standard.
  • A second framework scoped as a gap exercise, not a new programme.
  • Operational proof produced by the SOC as it runs, not assembled before an audit.
  • Continuous status rather than a point-in-time snapshot that decays.
What we work to

The standards
somebody is holding you to.

Mapped across a single control set. Which ones apply depends on your sector, your customers and where you operate, and working that out is the first conversation rather than a form.

NIS2

EU · in forceNow binding on essential and important entities across the EU, with management personally accountable and supplier oversight written into it explicitly. The most common reason organisations start this conversation in 2026.

SOC 2

US · customer-drivenThe report your US customers ask for before they will sign. Type I proves the controls are designed; Type II proves they ran over a period, which is where continuous operational evidence stops being a nice-to-have. SOC 2 in full

DORA

EU · financial servicesDigital operational resilience for financial entities and their critical ICT providers. Heavy on incident reporting timelines and third-party risk, which is why it usually arrives alongside a supplier programme.

ISO 27001

InternationalThe information security management standard most procurement teams recognise. We do the readiness, the control build and the evidence; the certificate comes from an accredited certification body. ISO 27001 in full

NIST CSF

US · widely adoptedIncreasingly the common language for describing security posture to a US board or insurer, and a useful spine to map everything else onto even where nobody is formally requiring it.

CIS Controls

Practical baselinePrioritised and genuinely actionable, which makes it a good starting point for an organisation that needs to improve before it needs to prove anything to anyone.

GDPR and UK GDPR

Data protectionThe security obligations rather than the whole regime: the technical and organisational measures, breach notification timelines and the evidence that they work.

Sector frameworks

As requiredPCI DSS, HIPAA, the NCSC frameworks, CMMC and others as they apply. If yours is not here it is probably still mapped; ask.

ISO 42001 for AI management systems is the one being asked about most often right now, and it maps onto the AI governance work rather than sitting apart from it.

How it runs

Assessed, mapped,
evidenced, defended.

A programme with a defined shape rather than an open-ended engagement that bills by the month.

  1. 01

    Assess

    Where you actually are against the frameworks in scope, run on the platform rather than through weeks of workshops. The output is a gap list with a real order of work.

  2. 02

    Map

    One control set built and mapped across every framework you are held to, so the overlap is captured once instead of paid for repeatedly.

  3. 03

    Close

    The gaps worked through in order of consequence, with our consultants on the judgement calls and your team on the things only you can decide.

  4. 04

    Evidence

    Proof collected continuously. Where we run your SOC, most of the operational evidence is a by-product of the service rather than a separate collection exercise.

  5. 05

    Defend it

    We sit with you through the audit or the assessment, answer the questions and produce the artefacts. The certificate or the report comes from whoever is independent.

The part most programmes fail on

Designed controls pass.
Operating ones need proof.

Anybody can write a policy that satisfies a control on paper. Showing it actually ran, every day, for twelve months, is the part that catches people out.

Third-party risk management

SOC 2 Type II needs a period
It is not a snapshot. The assessor wants evidence the controls operated across a defined window, which means the collection has to have been running before you started thinking about the report.
Incident evidence comes from incidents
Investigation records, timelines, response actions and closure statements are produced by a SOC doing its job. If nobody is operating anything, that evidence has to be manufactured, which auditors notice.
Detection coverage is measurable
What is monitored, what fires, what was tuned and when. That answers a whole family of controls about whether monitoring is real, and it is a record rather than an assertion.
Supplier oversight is evidence too
The register, the tiering rationale, the assessments and the monitoring history answer the supplier-management controls in ISO 27001, NIS2 and DORA directly.
Continuous beats point-in-time
A status that updates as controls change means the pre-audit scramble is an export rather than a project, and you find out about drift when it happens.
Questions

Frameworks, answered.

Can you certify us to ISO 27001?

No. Certification is awarded by an accredited certification body, and the supplier who builds your controls should not be the one certifying them. We do the readiness, the control build and the evidence, and we sit with you through the audit. The certificate comes from someone independent.

Can you do our SOC 2 report?

We get you ready for it and hold the evidence. The report itself is issued by a licensed CPA firm, which is a deliberate separation rather than a limitation. Type II is where we add most, because it requires proof the controls operated over a period.

We need NIS2. Where do we start?

With scope and a gap assessment: whether you are an essential or important entity, which obligations bite, and where you actually stand. Supplier oversight and incident reporting timelines are the two that catch people out, and both need work before a deadline rather than at one.

We already have ISO 27001 and now a customer wants SOC 2.

Then most of the work is done. The control sets overlap heavily, so it becomes a gap exercise against what you already hold rather than a second programme. The difference is usually the evidence: SOC 2 Type II wants proof of operation over a period.

How long does it take?

Readiness for a first framework is commonly three to six months depending on the starting point and how much has to change. A second framework mapped onto an existing control set is considerably faster. We scope it after the assessment rather than guessing beforehand.

Do we need your SOC for this?

No, and the programme stands on its own. It is materially easier where we run detection and response, because the operational evidence is then produced by the service rather than collected by you. We will be clear about which version you are buying.

What about ISO 42001 for AI?

It is the one we are asked about most often at the moment. It maps onto the AI governance work rather than standing apart from it, so if you are already assessing AI usage and agent activity, a good deal of the groundwork exists.

Do you do Cyber Essentials?

No. It is a UK-only, fixed-fee certification sold at volume by accredited bodies, and they will do it better and cheaper than we would. We would rather point you at one than take work we are not the right home for.

Where to start

Tell us who is asking
and which standard they named.

A regulator, a customer contract and an insurer want different evidence on different timelines. Knowing which one started this makes the assessment considerably shorter.