Cybersecurity / Compliance Readiness
Cybersecurity · SOC 2 · ISO 27001 · HIPAA

Compliance Readiness

SOC 2, ISO 27001, and HIPAA preparation for organisations that need to pass a real audit — not just look compliant on paper.

Framework-specificSOC 2, ISO 27001, HIPAA, and sector-specific requirements
Gap-assessment firstWe tell you what's missing before we tell you what to buy
Audit-readyDocumentation built to survive a real audit, not a checklist
The problem

Most compliance work starts backwards.

The common pattern: buy a compliance tool, generate a stack of policy documents nobody reads, and hope the auditor does not look too closely. It rarely survives contact with a real audit, and it does little for actual risk reduction.

Done properly, compliance readiness starts with an honest gap assessment against the specific framework you actually need — driven by what your customers and regulators require, not by what is easiest to sell.

Get in touch
How it works
01

Framework selection & gap assessment.

An honest assessment of what your customers, regulators, and industry actually require — SOC 2, ISO 27001, HIPAA, or a combination — and exactly what's missing today.

02

Policy & control documentation.

Written to be genuinely usable by your team day-to-day, and structured to hold up under a real auditor's questions.

03

Evidence collection & audit preparation.

Getting the specific evidence an auditor will ask for organised and ready, well before the audit window opens.

04

Ongoing compliance maintenance.

Compliance is not a one-time project — a review cadence that keeps your posture current between audits, not just for the one you're preparing for.

FAQ
Which framework do we actually need?

It depends on who's asking. Enterprise customers in the US often require SOC 2, healthcare-adjacent data brings HIPAA obligations, and international enterprise buyers often require ISO 27001. We help you work out which applies before recommending a readiness project.

How long does readiness typically take?

A SOC 2 Type I readiness assessment through report is commonly two to four months; HIPAA and ISO 27001 timelines vary more depending on your existing documentation and controls.

Do you replace our external auditor?

No — these certifications require an independent, accredited auditor. We prepare you for that audit and support you through it; the audit itself is performed independently.

Not sure which framework you actually need?

We'll tell you honestly, based on what your customers and regulators require.

Get in touch