Compliance Readiness
SOC 2, ISO 27001, and HIPAA preparation for organisations that need to pass a real audit — not just look compliant on paper.
Most compliance work starts backwards.
The common pattern: buy a compliance tool, generate a stack of policy documents nobody reads, and hope the auditor does not look too closely. It rarely survives contact with a real audit, and it does little for actual risk reduction.
Done properly, compliance readiness starts with an honest gap assessment against the specific framework you actually need — driven by what your customers and regulators require, not by what is easiest to sell.
Get in touchFramework selection & gap assessment.
An honest assessment of what your customers, regulators, and industry actually require — SOC 2, ISO 27001, HIPAA, or a combination — and exactly what's missing today.
Policy & control documentation.
Written to be genuinely usable by your team day-to-day, and structured to hold up under a real auditor's questions.
Evidence collection & audit preparation.
Getting the specific evidence an auditor will ask for organised and ready, well before the audit window opens.
Ongoing compliance maintenance.
Compliance is not a one-time project — a review cadence that keeps your posture current between audits, not just for the one you're preparing for.
Which framework do we actually need?
It depends on who's asking. Enterprise customers in the US often require SOC 2, healthcare-adjacent data brings HIPAA obligations, and international enterprise buyers often require ISO 27001. We help you work out which applies before recommending a readiness project.
How long does readiness typically take?
A SOC 2 Type I readiness assessment through report is commonly two to four months; HIPAA and ISO 27001 timelines vary more depending on your existing documentation and controls.
Do you replace our external auditor?
No — these certifications require an independent, accredited auditor. We prepare you for that audit and support you through it; the audit itself is performed independently.
Not sure which framework you actually need?
We'll tell you honestly, based on what your customers and regulators require.
Get in touch