Under ISO/IEC 17021 and the AICPA independence code, the body that certifies you is barred from having consulted you. That wall is permanent — and it means the readiness, implementation and remediation half of your compliance spend is work your auditor is legally forbidden to touch. We live on that side of the wall.
Why teams choose us.
Fixed Fee, Fixed Scope
$12,500 for a single framework up to 150 people. You know the number before we start, and it does not move because we found more work.
Every Gap Priced
Findings without effort estimates are just anxiety. Each one comes back with engineer-days attached so you can fund it, sequence it, or decide it can wait.
Credited Against The Fix
The full assessment fee is credited against any remediation engagement. If you'd rather fix it yourself or use your incumbent, the register is yours to take.
No Auditor Kickbacks
We take no fee, commission or rebate from any auditor or certification body we introduce you to, and we confirm that in writing to you and to them.
The full menu.
Control-By-Control Gap Register
- Every control assessed, not sampled
- Evidence pointers, not assertions
- Severity and audit-blocking flags
- Machine-readable export, yours to keep
Costed Remediation Plan
- Every gap priced in engineer-days
- Sequenced by audit-blocking impact
- Build-vs-buy called on each item
- Fundable as a budget line
Documentation Set
- Statement of Applicability draft (ISO 27001)
- System description draft (SOC 2)
- Risk treatment plan
- Scope boundary and asset inventory
Platform Configuration
- Vanta or Drata configured to your scope
- Policies mapped to controls
- Integrations wired to real evidence
- Dashboard that reflects reality, not defaults
Auditor Introduction
- Shortlist matched to your buyer's expectations
- Scope and fee pre-negotiated
- Timeline aligned to your deal calendar
- We brief them; you sign with them directly
Our process.
Scope & Evidence Request
We agree the framework, the system boundary and the trust criteria in a 60-minute call, then send one consolidated evidence request. No drip-feed.
Control Assessment
Control-by-control review against the actual standard text, with your cloud configuration, IAM, logging and SDLC inspected rather than surveyed.
Costing & Sequencing
Every gap sized in engineer-days and ordered by what blocks the audit. You get the plan you can take to your board or your investor.
Walkthrough & Handover
Sixty-minute walkthrough, the register in machine-readable form, and warm introductions to two auditors with scope and fee already agreed.
What we build with.
What sits on each side of the independence wall
Which framework applies where
A readiness assessment is artefact delivery — the output is a document. Scoped to zero personal data, it is the most portable thing we sell.
The best fit for this service anywhere. SOC 2 is a binary sales gate, 15,000–20,000 reports are issued a year, and California's CPPA cybersecurity audit and risk-assessment regulations took effect 1 January 2026 — with pre-2026 risk assessments due 31 December 2027 and the first audit certifications 1 April 2028.
The CPPA regime carries the same independence structure as SOC 2: the auditor cannot perform the remediation. NYDFS Part 500 fully phased in November 2025.
ISO 27001:2022 is the usual target, and the 2013 certificates expired on 31 October 2025 — which has pushed a re-certification wave through 2026. Cyber Essentials readiness is a separate service, because the Danzell question set is a different scope.
We are not an IASME-licensed certification body and cannot issue a Cyber Essentials certificate. We do not take UK public-sector work: it requires contractual UK data residency, SC clearance and CE Plus under G-Cloud 15, none of which offshore delivery can satisfy.
NIS2 has no certification and no accredited auditor, so ISO 27001 is the de facto evidence artefact — and there is no independence barrier on any of the work. That makes a NIS2 conversation convert cleanly into a readiness engagement.
Twenty-seven national regimes, fragmented: the Commission referred Ireland, Spain, France and the Netherlands to the CJEU on 8 July 2026 for failure to transpose. We deliver in English only, and NIS2 buying often happens in German, French, Italian, Dutch or Spanish.
Strong fit. The National Cyber Security Strategy moved the UAE from voluntary guidance to mandatory resilience, and NESA / UAE IA's 188 controls plus DESC ISR v3 create real assessment demand that local supply has not caught up with. UAE and South Africa account for roughly 45% of all Middle East and Africa ISO certifications.
Where the client is a DIFC or ADGM entity, the free zones are as strict as the EU on transfers and neither lists India as adequate. Saudi Arabia we take only as pull-through from a UAE client, under the UAE contract — NCA ECC-2 effectively requires an in-Kingdom presence.
Every market position we hold, with the legal reason and the transfer mechanism, is on where we work.
Choose this if...
Honest about who this is for.
This will be a fit.
- You want to know the real number before you commit a budget
- You would rather hear 'this control is fine, skip it' than be sold a full programme
- You have a compelling event with a date attached
- You want the findings register in a form you can take anywhere
Honestly — not our zone.
- —You want us to be your auditor — we cannot be, and neither can any firm that helps you implement
- —You want a certificate at the end of this. This produces a plan, not a certificate
- —You have no compelling event and no budget — a readiness assessment will sit on a shelf
- —You are a healthcare company needing us inside the PHI estate. We currently scope those engagements as no-PHI-in-scope, which usually removes most of the value































