ISO 27001 · GDPR · PCI-DSS

Compliance Readiness

Offensive mindset. Defensive results.

Assessments aligned with the frameworks your customers and regulators ask about. We find the gaps and help you close them before audit day.

Frameworks

What we cover

ISO 27001

Information security management system (ISMS) assessment. Control mapping, risk assessment, and Statement of Applicability preparation.

GDPR

Data protection impact assessments, privacy by design review, data processing agreements, and breach notification readiness.

PCI-DSS

Payment card data security assessment, scope reduction strategies, and self-assessment questionnaire preparation.

SOC 2

Trust services criteria assessment across security, availability, confidentiality, processing integrity, and privacy.

HIPAA

Healthcare data security assessment, administrative and technical safeguard review, and risk analysis documentation.

NIST CSF

Cybersecurity framework maturity assessment across Identify, Protect, Detect, Respond, and Recover functions.

Methodology

The compliance journey

Certification is an evidence exercise, and the expensive way to do it is to discover that at the audit. These five phases front-load the discovery so the audit itself is uneventful.

  1. 01

    Scope & Framework Selection

    First we work out what you actually need, which is often less than you have been told. SOC 2 because an enterprise customer asked, ISO 27001 because you sell in Europe, and DPDP or GDPR because of where your users are, each imply different work. Chasing all of them at once is the usual reason a compliance programme stalls.

    Then we define scope, which is the single biggest lever on cost and timeline: which systems, which teams, which data, which locations are in the boundary. A tight, defensible scope that covers what customers care about beats an ambitious one you cannot evidence.

    You provide
    Your customer or regulatory drivers, target dates, and a picture of your systems and data flows.
    We do
    Map drivers to frameworks and controls, define and document the audit boundary, sequence the work.
    You get
    A framework decision with the reasoning, a defined scope statement, and a realistic timeline.
    Typical time
    3–5 days
  2. 02

    Gap Assessment

    Every control in scope is assessed against what you are doing today and rated compliant, partially compliant or non-compliant — with the evidence, or the absence of it, recorded against each. We test rather than take assurances: if the policy says access is reviewed quarterly, we ask to see the last two reviews.

    This is deliberately uncomfortable reading. An honest gap assessment is worth considerably more than a flattering one, because the auditor will not be generous about the same gaps six months from now.

    You provide
    Access to policies, system configuration, ticket history, and the people who run each process.
    We do
    Control-by-control assessment with evidence sampling and process walkthroughs.
    You get
    A rated gap register with evidence references and an honest readiness percentage.
    Typical time
    1–2 weeks
  3. 03

    Remediation Roadmap

    Gaps are turned into a sequenced plan: what must be fixed before audit, what can be accepted with a documented rationale, and what is a genuine quick win. Each item carries an owner, an effort estimate and a due date, mapped to the tools you already run rather than assuming new purchases.

    We are explicit about which gaps are policy-and-evidence problems and which need engineering work, because the first kind can often be closed in days and the second may define your timeline.

    You provide
    Owners for each area, and a view of your engineering capacity over the period.
    We do
    Prioritise and sequence remediation, estimate effort, assign owners, and identify quick wins.
    You get
    A roadmap with owners and dates that your team can run as a project, and a defensible list of accepted risks.
    Typical time
    3–5 days
  4. 04

    Implementation Support

    We work alongside your team through remediation: drafting the policies auditors expect (and that your team can realistically follow), setting up the evidence collection so it is generated as a by-product of normal work rather than assembled in a panic, and advising on control implementation as questions come up.

    Evidence automation gets particular attention. Controls that produce their own evidence — access reviews that leave a ticket, deployments that record an approval — are the difference between a routine annual audit and a fortnight of screenshotting.

    You provide
    Team time to implement, review and adopt the policies and processes.
    We do
    Draft policies and procedures, set up evidence collection, advise on control implementation, review artefacts.
    You get
    An implemented control set with evidence flowing automatically, and adopted documentation.
    Typical time
    4–12 weeks, alongside your team
  5. 05

    Audit Preparation

    Before the real audit we run a mock one: we sample controls the way your auditor will, ask the questions they will ask, and check that the evidence can actually be produced on request. Whoever will face the auditor gets to practise answering, which is worth more than it sounds.

    We then support you through the audit itself — interpreting requests, preparing responses, and handling findings as they arise. You go in knowing what the auditor will find, which is the entire point of the exercise.

    You provide
    Your audit dates, auditor requests, and availability of control owners for the mock sessions.
    We do
    Mock audit against the real control set, evidence-package review, interview preparation, audit support.
    You get
    A pre-audit readiness report, an organised evidence package, and support through the audit.
    Typical time
    1–2 weeks, plus the audit
FAQ

Common questions

What is compliance readiness?

Compliance readiness is the process of assessing your current security controls against a regulatory framework, identifying gaps, and implementing the controls needed to pass a formal audit or certification.

Which compliance frameworks does Secracy cover?

We help with ISO 27001, GDPR, PCI-DSS, SOC 2, HIPAA, and NIST Cybersecurity Framework. We can also map controls across multiple frameworks simultaneously to reduce duplication of effort.

How long does compliance preparation take?

Initial gap assessment typically takes 2-4 weeks. The remediation phase depends on the number of gaps and your team's capacity, but most organisations achieve readiness within 3-6 months with focused effort.

Get audit-ready with confidence.

Start with a gap assessment and know exactly where you stand before your next audit.