Compliance

Cybersecurity compliance consulting, made into a business advantage.

EU regulatory expertise — NIS2, DORA, GDPR, ISO 27001, PCI DSS — turned into the evidence your customers, auditors, and insurers keep asking you for. Sized for SMBs, run end-to-end.

The landscape

Four EU regulations. Two years. Most SMBs left behind.

Since 2023 the EU has pushed an unusually heavy regulatory wave: NIS2 enforceable from October 2024, DORA from January 2025, the EU Data Governance Act in force, and active GDPR enforcement intensifying in parallel. For SMBs the question isn't whether to comply — the obligations are legal, the deadlines are past — but knowing which apply, what they actually require, and how to build a defensible program without enterprise overhead.

Under NIS2, senior management can be held personally liable for cybersecurity failures. Compliance has stopped being an IT problem.

And the cost of getting it wrong is rarely the fine. It's the enterprise contract that quietly goes elsewhere after a security questionnaire you couldn't answer — a loss most SMBs never find out they took.

What we deliver

Compliance, end-to-end.

Scoping & applicability

A clear answer to the first question every SMB asks: which frameworks apply to us, at what tier, and what is actually mandatory? Often resolved in an hour.

Gap analysis

A structured assessment of your current controls, policies, and processes against the target framework. Output: a prioritised gap register with a costed action plan.

Policy & control implementation

We write or update the policies and procedures, and supervise the deployment of technical controls — alongside your team, in language your team will actually use.

Audit & certification preparation

Internal audit leadership, document review, management review meetings, and direct coordination with your certification body or regulator. Led by PECB ISO 27001 Lead Auditor practitioners.

Ongoing compliance management

Compliance is not a project. We provide continuous monitoring, regular reviews, and updates as regulations evolve — so your status holds long after the initial certificate is issued.

Personal-liability defence

Documented decisions, board-grade risk reporting, and management review records — the evidence trail that protects directors and officers under NIS2's personal liability clauses.

How we work

Four phases, mapped to your audit timeline.

  1. 01

    Gap analysis

    Weeks 1–3

    We assess your current state against the specific requirements of the target framework. You receive a prioritised gap register with a clear, costed action plan — and a realistic timeline to certification or compliance.

  2. 02

    Policy & control implementation

    Weeks 3 onwards

    We write or update your policies and procedures, and oversee your team's deployment of the technical controls that close the gaps. The governance work is ours; the technical roll-out remains with your IT function (or its provider), under our supervision.

  3. 03

    Audit & certification preparation

    Pre-audit window

    We lead your internal audit, prepare documentation, run management reviews, and coordinate with your certification body or regulator — so nothing is left to chance on audit day.

  4. 04

    Ongoing compliance management

    Continuous

    Continuous monitoring, scheduled reviews, regulatory horizon scanning, and updates as the legal landscape evolves. The certificate or compliance status holds — and stays current.

Who this is for

Some signal you're in scope.

EU SMBs of 10–500 employees in regulated sectors or handling sensitive data. The signals below tend to come up in our scoping calls.

  • You are a medium or large entity in one of the 18 critical sectors covered by NIS2 (50+ employees or €10M+ turnover).
  • You are an EU financial entity — bank, insurer, fund, payment institution, e-money issuer, crypto-asset provider — or a critical ICT third party serving one. DORA applies.
  • You handle personal data of EU residents in any meaningful volume. GDPR applies.
  • You accept card payments and process more than a handful of transactions a year. PCI DSS applies in some form.
  • You are pursuing ISO 27001 certification — for a tender, a customer requirement, or as a strategic differentiator.
  • You are legally required to appoint a DPO and need to fill the role without a full-time hire.
  • Your enterprise customers, public-sector buyers, or insurers are asking for compliance evidence as a condition of the relationship.
  • Your senior management isn't comfortable signing off on cyber risk because no one can show what's actually in place.

Frameworks covered

Every major EU regulation and certification, in one engagement.

MANDATORY · EU
NIS2
Risk management, incident reporting, governance, and supply-chain security for essential and important entities across 18 critical sectors.
Read more
MANDATORY · FINANCIAL
DORA
ICT risk management, operational resilience testing, and third-party oversight for EU financial entities and their critical ICT providers.
Read more
MANDATORY · EU
EU GDPR
Data protection governance, breach response, DPIA oversight, and DPO coordination for any organisation handling EU personal data.
Read more
MANDATORY · EU
EU AI Act
Risk-tier classification, provider vs deployer roles, Annex III high-risk obligations, and Article 99 fines — the AI regulation deep-dive, delivered through AI Governance & Security.
Read more
MANDATORY · PRODUCTS
Cyber Resilience Act
Cybersecurity inside CE marking for products with digital elements — manufacturer scoping, Annex I requirements, the 24-hour reporting clock, and conformity assessment.
Read more
CERTIFICATION
ISO 27001
ISMS design, implementation, internal audit leadership, and certification preparation. Led by PECB-accredited Lead Auditors.
Read more
CERTIFICATION · AI
ISO 42001
AI Management System (AIMS) implementation and certification — the certifiable wrapper for AI Act-compliant AI governance and security.
Read more
PRIVACY · CERTIFICATION
ISO 27701
Privacy Information Management System — extending ISO 27001 to cover GDPR and global privacy frameworks.
Read more
PAYMENTS
PCI DSS
Cardholder data environment scoping, SAQ guidance, gap remediation, and ongoing compliance monitoring.
Read more
PRIVACY
DPO as a Service
Outsourced Data Protection Officer under GDPR Article 37 — independent, certified, proportionate to your organisation.
Read more
CERTIFICATION
EU Cybersecurity Act
ENISA-led certification regime for ICT products, services, and processes. Required for some public-sector procurement.
Read more
EU
Data Governance Act
Compliance for organisations re-using public-sector data, intermediating data sharing, or operating as data altruism organisations.
Read more

FAQ

Common questions.

How do I know which regulations actually apply to my business?
It depends on your sector, size, and what data and money flows through your business. NIS2 typically applies to organisations of 50+ employees or €10M+ turnover in one of 18 critical sectors. DORA applies to all EU financial entities and their critical ICT providers. GDPR applies to almost everyone handling EU personal data. PCI DSS applies if you accept card payments. The fastest route to a clear answer is the discovery call — we usually have a defensible scoping decision within an hour.
How long does compliance actually take?
It depends on your starting point and the framework. For an SMB starting from a low baseline: ISO 27001 certification typically takes 6–12 months from gap analysis to certification audit; NIS2 compliance for an organisation with limited existing security controls typically reaches a defensible position in 3–6 months. DORA timelines depend heavily on third-party ICT contract complexity. We give you a realistic timeline — not a sales-pitch one — at the end of the gap analysis.
What's the difference between a gap analysis and a security audit?
A gap analysis is forward-looking and prescriptive: where are you today versus where the framework requires you to be, and what's the shortest path to close that gap. A security audit is backward-looking and evaluative: how effective are the controls you already have in place. Different tools for different stages — gap analysis when starting a compliance program, audit when verifying an existing one.
Can you handle multiple frameworks at once?
Yes — and most engagements do. ISO 27001 and NIS2 share a substantial control overlap; ISO 27001 and ISO 27701 are designed to integrate; GDPR controls underpin most NIS2 governance requirements. Running them together is faster, cheaper, and produces less internal disruption than sequencing them. We map the overlap during the gap analysis so you only build each control once.
Does my business need a DPO?
You are legally required to appoint a Data Protection Officer under GDPR Article 37 if you are a public authority, your core activities involve large-scale systematic monitoring of data subjects, or your core activities involve large-scale processing of special-category data. If yes and you are not large enough to justify a full-time hire, our DPO as a Service offers the role on a fractional, certified basis.
What happens after the certificate is issued?
A certificate is a snapshot — your real obligation is continuous compliance, plus surveillance audits (ISO 27001), regulatory reporting (NIS2/DORA), and the inevitable evolution of the regulations themselves. Our ongoing compliance management covers all of that: monthly reviews, regulatory horizon scanning, evidence maintenance, and management briefings — so the certificate keeps holding and the regulator stays satisfied.
How is the engagement priced?
A fixed fee for the compliance project itself (phases 01–03: gap analysis, policy & control implementation, and audit/certification preparation), invoiced milestone by milestone as each phase completes. Optionally followed by a monthly compliance maintenance retainer (phase 04) — ongoing posture review, regulatory horizon scanning, and surveillance audit support — which most clients keep in place to hold their certification or compliance status through year two and beyond. All numbers fixed and shared in the proposal after the discovery call. No surprise bills, no hourly tracking.