Security & Compliance
ISO 27001 implementation
The information-security certification European RFPs treat as table stakes.
Who it is for
Anyone selling into the EU or to enterprise.
Everything below is in the scope document, written and priced before anything starts. If something you need is not on this list, say so and it goes in the quote — or we tell you it does not belong in this engagement.
- Scope definition — the decision that most affects cost and nobody thinks about
- Risk assessment and treatment plan, plus the full policy set
- Control implementation with evidence collection designed in from the start
- Internal audit and management review run before the certification body arrives
- Support through Stage 1 and Stage 2 audits
Also in Security & Compliance
SOC 2 readinessFor material US enterprise deals. Roughly 70–80% of the controls overlap with ISO 27001.9–14 months including observationDPDP Act complianceIndia's Digital Personal Data Protection Act, applied to systems you already run.3–8 weeksGDPR & data-protection advisoryFor EU customers and EU data, including the transfer mechanism question.3–8 weeksvCISO retainerPart-time security leadership for companies that need the function but not the salary.Monthly
Next step
Thirty minutes on whether this is the right engagement.
If a different service on this list fits better, or if you do not need us at all, that is what the call will conclude.