compliance & grc

Compliance readiness,
without the last-minute chaos.

From unclear client requirements to audit-ready evidence. I handle gap assessment, remediation, policy and evidence prep, and coordination with your auditor, across the standards below.

Note: certificates and formal attestations are issued by accredited certification bodies and authorized assessors. I provide readiness, advisory, implementation support and audit coordination.

the path

How readiness works.

A clear journey from "we have no idea where we stand" to "here's our evidence."

01

Select

Pick the framework your clients or regulators require.

02

Gap Assessment

Measure where you are against the controls today.

03

Roadmap

A prioritised plan to close the gaps efficiently.

04

Evidence & Policy

Policies, controls and the evidence auditors expect.

05

Audit Coordination

Support through the audit and into maintenance.

framework catalog

The standards I help you prepare for.

Grouped by the market and the client requirement they map to.

Global Security Management
For information security, privacy and risk management readiness.
ISO 27001ISO 27002ISO 27701ISO 27017ISO 27018
US / SaaS / Cloud Trust
For SaaS vendors, cloud providers and US customer assurance.
SOC 2SOC 1NIST CSF 2.0NIST 800-53NIST 800-171
Payments & Financial
For fintechs, payment processors and e-commerce.
PCI DSS v4.0PCI SAQCyber Insurance Readiness
Healthcare & Pharma
For organisations handling protected health data.
HIPAA Security RuleHITRUST ReadinessHITECH
EU / UK Privacy & Security
For data processors and privacy-sensitive organisations.
GDPRUK GDPRNIS2Cyber Essentials Plus
Regional & Operational
For GCC/UAE markets and practical security baselines.
UAE / NESASaudi NCA ECCCIS Controls v8OWASP ASVS

// frameworks

Standards we prepare you for

ISO 27001

ISMS certification readiness and gap analysis.

SOC 2 Type II

Trust Service Criteria audit readiness.

PCI DSS v4

Payment card industry compliance advisory.

GDPR

Data protection compliance and advisory.

NIST CSF

Cybersecurity framework alignment and maturity.

Cyber Essentials

Certification preparation and controls.

Not sure which standard you need?

Tell me who's asking for proof, a client, an auditor, a regulator, and I'll tell you the shortest path to ready.