Compliance Support

Meet the frameworks your customers and regulators expect, and stay there. Gap analysis, policies, evidence packs, audit preparation and control monitoring across overlapping standards.

Service Details

Compliance support gives you ongoing, hands-on help to meet the security and data protection frameworks your customers and regulators expect, and to keep meeting them. You get a clear picture of your gaps, the policies and controls to close them, and evidence packs ready for auditors and customer questionnaires.

It is part of our strategy and advisory services, which cover the advice, planning and assurance behind your security decisions. Here, that means working with your teams across ISO 27001, Cyber Essentials, UK GDPR, PCI DSS, DORA, NIS2 and more, from first gap analysis to audit day and beyond.

INFO

We prepare you for audits and assessments. We are not a certification body, a PCI Qualified Security Assessor (QSA) or a law firm, so the formal assessment is carried out by an accredited body, and legal opinions come from your legal advisers.


Who compliance support is for

It suits organisations that have to prove their security to someone else, but have no dedicated compliance team to do it. That is often a growing business facing its first ISO 27001 audit, or a regulated firm juggling several frameworks at once.

It also helps when security questionnaires from customers keep landing on your IT team. Rather than answering each one from scratch, you build the evidence once and reuse it.


What's included

Practical help across the whole compliance cycle:

Gap Analysis

Your current controls measured against each framework you need, with gaps ranked by risk and effort.

Policies and Procedures

Policies written for how your organisation actually works, short enough for staff to read and follow.

Multi-Framework Mapping

One set of controls mapped to every framework you answer to, so each piece of work counts more than once.

Evidence Collection

Records gathered from your systems and teams, organised by requirement and kept current.

Audit Preparation

Readiness checks, mock interviews and a document trail your auditor can follow without chasing.

Control Monitoring

Regular checks that controls still operate as described, with drift flagged before it becomes a finding.


One set of controls across overlapping frameworks

Most organisations now answer to several frameworks at once, some set by their sector and some by where they trade. Many requirements overlap, such as access control, incident response and supplier management.

Sector requirements

Rules that come with what you do, such as card payments or financial services.

For example PCI DSS, DORA and FCA rules.

Regional and baseline requirements

Rules that come with where you operate, plus the standards customers ask for.

For example UK GDPR, NIS2, ISO 27001 and Cyber Essentials.

Mapping these together means you build a control once and evidence it once, instead of running a separate project for each framework.

Each framework has its own page with the detail: ISO 27001, Cyber Essentials, UK GDPR, PCI DSS, DORA, NIS2, FCA, NIST and CIS Controls. Compliance support is the ongoing help that ties them together.


Hands reviewing compliance paperwork with a pen on a bright desk

How we work

You get a programme paced to your audit dates and your team's capacity, not a report that sits on a shelf.

  • Scope — We agree which frameworks apply, which parts of the business are in scope and when your audits or questionnaires are due.
  • Gap analysis — We review your policies, systems and records against each requirement and rank the gaps.
  • Remediation plan — You get a prioritised plan, with owners, covering policy changes and technical fixes.
  • Build and evidence — We write policies with you, work with your engineers or ours on technical changes, and collect evidence as each control goes live.
  • Audit readiness — We run a readiness check, prepare your people for interviews and support you through the audit itself.
  • Keep it current — Controls are monitored and evidence refreshed, so the next audit starts from a strong position.

Evidence packs for auditors, customers and boards

Much of the evidence you need already exists in your systems: patch records, access reviews, backup logs, training records and configuration exports. The work is finding it, checking it and presenting it so the reader can match each claim to its proof.

We turn that raw material into packs for the people who ask for it.

Auditor Pack

Evidence indexed against each framework requirement

Questionnaire Answers

Reusable answers and proof for customer due diligence

Board Summary

Compliance status, open gaps and risks in plain terms


Suppliers and partners in scope

Many frameworks hold you responsible for your suppliers as well as your own controls. DORA, NIS2 and ISO 27001 all expect you to manage third-party risk.

We help you decide which suppliers matter most, what to ask them before you sign and how to review them afterwards. Where a supplier’s gaps become your risk, you get practical options: further assurances, contract requirements to raise with your legal advisers, or a change of supplier.

Three colleagues discussing vendor compliance around a laptop in a bright office

Assurance is an independent test of whether your controls work. Compliance support builds the programme that assurance then tests, so the two work well in sequence. A security posture review gives you a broad maturity baseline, which is often a useful starting point before a gap analysis.

The framework pages under governance explain what each standard requires and how we help with it specifically. Compliance support is the shared, ongoing work across them. If you want everything brought together as one programme, see our end-to-end compliance programme.

Evidence produced by the controls

Sensitivity labels and data loss prevention across Microsoft 365 gave one client visibility of where sensitive information lives, with confidential content kept away from AI assistants such as Copilot. Controls like these record their own activity, so evidence builds up as the work runs rather than being assembled before each review.


Services that work alongside

Compliance support draws on evidence from the rest of our work. Managed services, Microsoft 365 administration and identity and access produce many of the records auditors ask for. User awareness training covers the staff training most frameworks require.

On the assessment side, risk management gives you the risk register ISO 27001 and DORA expect, and penetration testing supplies the technical testing PCI DSS and many customers require. For board-level reporting, see board advisory, and if you need someone to own the programme, a fractional CxO can lead it.


Frequently asked questions

Get ready for your next audit

Tell us which frameworks you need to meet and when your next audit or questionnaire is due. You get a clear view of your gaps and a plan to close them.