Scoping & applicability
A clear answer to the first question every SMB asks: which frameworks apply to us, at what tier, and what is actually mandatory? Often resolved in an hour.
Compliance
EU regulatory expertise — NIS2, DORA, GDPR, ISO 27001, PCI DSS — turned into the evidence your customers, auditors, and insurers keep asking you for. Sized for SMBs, run end-to-end.
The landscape
Since 2023 the EU has pushed an unusually heavy regulatory wave: NIS2 enforceable from October 2024, DORA from January 2025, the EU Data Governance Act in force, and active GDPR enforcement intensifying in parallel. For SMBs the question isn't whether to comply — the obligations are legal, the deadlines are past — but knowing which apply, what they actually require, and how to build a defensible program without enterprise overhead.
Under NIS2, senior management can be held personally liable for cybersecurity failures. Compliance has stopped being an IT problem.
And the cost of getting it wrong is rarely the fine. It's the enterprise contract that quietly goes elsewhere after a security questionnaire you couldn't answer — a loss most SMBs never find out they took.
What we deliver
A clear answer to the first question every SMB asks: which frameworks apply to us, at what tier, and what is actually mandatory? Often resolved in an hour.
A structured assessment of your current controls, policies, and processes against the target framework. Output: a prioritised gap register with a costed action plan.
We write or update the policies and procedures, and supervise the deployment of technical controls — alongside your team, in language your team will actually use.
Internal audit leadership, document review, management review meetings, and direct coordination with your certification body or regulator. Led by PECB ISO 27001 Lead Auditor practitioners.
Compliance is not a project. We provide continuous monitoring, regular reviews, and updates as regulations evolve — so your status holds long after the initial certificate is issued.
Documented decisions, board-grade risk reporting, and management review records — the evidence trail that protects directors and officers under NIS2's personal liability clauses.
How we work
Weeks 1–3
We assess your current state against the specific requirements of the target framework. You receive a prioritised gap register with a clear, costed action plan — and a realistic timeline to certification or compliance.
Weeks 3 onwards
We write or update your policies and procedures, and oversee your team's deployment of the technical controls that close the gaps. The governance work is ours; the technical roll-out remains with your IT function (or its provider), under our supervision.
Pre-audit window
We lead your internal audit, prepare documentation, run management reviews, and coordinate with your certification body or regulator — so nothing is left to chance on audit day.
Continuous
Continuous monitoring, scheduled reviews, regulatory horizon scanning, and updates as the legal landscape evolves. The certificate or compliance status holds — and stays current.
Who this is for
EU SMBs of 10–500 employees in regulated sectors or handling sensitive data. The signals below tend to come up in our scoping calls.
Frameworks covered
FAQ