Skip to content
The European Parliament chamber in Strasbourg, seats curving in tiers around the rostrum.

Services

Governance, Risk & Compliance

Prove it once. Use the proof everywhere.

Prove it once. Use the proof everywhere.

Compliance becomes expensive at the moment it fragments. A NIS2 programme run by one team, an ISO 27001 project run by another, a SOC 2 audit answered by a third, and a GDPR register nobody has opened since it was written. The same control gets implemented three times, evidenced three ways, and maintained by nobody.

We work the other way round. One unified control framework, mapped across NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act. A control is designed once, implemented once, and its evidence is produced once — then reused by every audit that asks for it. In practice the overlap is around seventy per cent.

The other half of this practice is the calendar. Certificates need maintaining, registers need updating, and regulations change. That work is better done continuously at a known monthly cost than rediscovered eight weeks before a surveillance audit.

Governance, Risk & Compliance

Cybersecurity and compliance assessment

Where you stand — against a standard, a regulation, a risk model or an authorisation scheme — before anyone commits to a programme.

  • Information security assessmentTypical duration: 3–5 weeks

    A structured review of your security organisation, controls and practices against ISO 27001 or NIST CSF, scored by domain and ranked by exposure.

    You receive

    • Scored assessment by domain
    • Ranked gap register with owners
    • Executive summary
  • NIS2, DORA and CRA applicability assessmentTypical duration: 2–4 days

    A short, decisive answer to the question that blocks everything else: which regulations apply to which of your entities, in which member states, and from when.

    You receive

    • Entity-by-entity applicability analysis
    • Classification as essential, important or out of scope
    • Registration and notification obligations
    • Deadline calendar per jurisdiction
  • Standards compliance assessmentTypical duration: 2–4 weeks

    Where you stand against a named standard — ISO 27001, 27701, 22301 or 42001 — clause by clause, before you commit to certification.

    You receive

    • Clause-by-clause conformity matrix
    • Effort estimate to certification
    • Recommended sequence of work
  • Risk analysis (EBIOS RM / ISO 27005)Typical duration: 8–20 days

    A risk analysis built on your real business scenarios: what an attacker would want, the paths available, and the treatment decisions that follow.

    You receive

    • Business and technical asset inventory
    • Strategic and operational attack scenarios
    • Risk register with treatment decisions
    • Residual risk statement for management
  • Authorisation and accreditation assessmentTypical duration: 2–4 weeks

    The evidence pack and gap review for a system that needs a formal authorisation to operate — public-sector, health or critical-infrastructure schemes included.

    You receive

    • Control mapping to the scheme
    • Evidence pack ready for the authority
    • Residual-risk statement

European cybersecurity regulation

NIS2, DORA and the CRA, translated from legal text into a plan with dates and owners.

  • NIS2 gap analysis and compliance programmeTypical duration: 10–30 days

    Assessment against the ten measures of Article 21 and the governance duties of Article 20, followed by a programme that closes the gaps in the order a regulator would expect.

    You receive

    • Gap analysis against Articles 20 and 21
    • Management body training and accountability record
    • Incident notification procedure (24h, 72h, one month)
    • Compliance programme with owners and dates
  • DORA compliance programmeTypical duration: 20–60 days

    The full DORA scope for financial entities and their ICT providers: ICT risk management, incident classification and reporting, the register of information, and preparation for threat-led penetration testing.

    You receive

    • ICT risk management framework
    • Register of information, ready for submission
    • Incident classification and reporting procedure
    • Third-party contract remediation plan and TLPT readiness
  • Cyber Resilience Act complianceTypical duration: 15–40 days

    For manufacturers and software vendors placing products on the EU market: security by design, vulnerability handling, SBOM, and the technical documentation the CRA requires you to keep.

    You receive

    • Product classification and conformity route
    • Secure development and vulnerability handling process
    • SBOM generation and maintenance
    • Technical documentation and declaration of conformity
  • Supplier compliance and security assurance plansTypical duration: 3–8 days

    The security annexes, assurance plans and audit rights that make your contracts defensible, whether you are the client asking or the supplier answering.

    You receive

    • Security assurance plan template
    • Contractual security annex
    • Supplier evidence review
    • Audit and exit clauses

Regulatory compliance and certification

ISO 27001, 27701, 22301 and 42001, SOC 2, SWIFT CSP and the sector schemes, taken through to the certificate or the attestation.

  • ISO/IEC 27001:2022 certification supportTypical duration: 6–14 months

    From scoping to the certification audit: statement of applicability, risk treatment, documented information, internal audit and management review, with the certification body chosen early.

    You receive

    • Scope, SoA and risk treatment plan
    • Complete documented ISMS
    • Internal audit and management review
    • Stage 1 and Stage 2 audit support
  • ISO 27001 internal audit and maintenanceTypical duration: Recurring

    The annual cycle that keeps the certificate: internal audit programme, management review, corrective actions and surveillance audit preparation, run without consuming your team.

    You receive

    • Annual internal audit programme
    • Audit reports and non-conformities
    • Management review pack
    • Surveillance audit preparation
  • ISO 22301 certification supportTypical duration: 4–8 months

    A business continuity management system built to the standard and taken through certification: analysis, strategies, plans, exercises, audit.

    You receive

    • Business impact analysis and continuity strategies
    • Documented BCMS ready for audit
    • Exercise record and management review
  • ISO 27017, 27018, 27701 and 22301 extensionsTypical duration: 10–30 days

    Extensions built on an existing ISO 27001 system: cloud controls, personal data in the cloud, a privacy information management system, or business continuity.

    You receive

    • Extension scoping and delta analysis
    • Additional controls and documentation
    • Integration with the existing ISMS
    • Audit preparation
  • SOC 2 Type I and Type IITypical duration: 4–12 months

    Trust services criteria selected for what your customers actually ask about, controls designed to be evidenced automatically, and an auditor engaged at the right moment.

    You receive

    • Criteria selection and control matrix
    • Control design and evidence automation
    • Readiness assessment before the audit
    • Audit coordination through to report
  • SWIFT CSP complianceTypical duration: 4–8 weeks

    The annual Customer Security Programme attestation: control assessment against the current CSCF, remediation, and the independent assessment SWIFT requires.

    You receive

    • CSCF control assessment
    • Remediation plan for open controls
    • Attestation support in the KYC-SA portal
  • HDS, SecNumCloud, PCI DSS and TISAXTypical duration: Scoped per engagementDelivered with a qualified partner

    Sector and national qualifications prepared with qualified partners, so the scheme-specific requirements are handled by people who hold the qualification themselves.

    You receive

    • Scheme applicability and scoping
    • Gap analysis against the reference framework
    • Remediation plan with partner support
    • Assessment coordination

Personal data

GDPR and the local laws that apply wherever your data actually sits.

  • GDPR audit and complianceTypical duration: 8–20 days

    Records of processing that reflect reality, lawful bases that hold, retention actually enforced, and a data subject request process that meets the one-month clock.

    You receive

    • Record of processing activities
    • Lawful basis and retention analysis
    • Data subject rights procedure
    • Remediation plan with priorities
  • Outsourced data protection officerTypical duration: Recurring

    A designated DPO with the independence the regulation requires, handling the register, the impact assessments, the requests and the relationship with the supervisory authority.

    You receive

    • DPO designation and authority notification
    • Register and DPIA maintenance
    • Data subject request handling
    • Annual DPO report to management
  • DPIA and privacy by designTypical duration: 3–10 days

    Impact assessments for the processing that needs one, and design reviews early enough that the answer can still change the architecture.

    You receive

    • DPIA screening and full assessments
    • Design review with privacy requirements
    • Mitigation measures and residual risk
    • Consultation file if required
  • International transfers and local lawsTypical duration: 5–15 days

    Transfer mechanisms, impact assessments and local registration duties across the jurisdictions we cover: Tunisia, Morocco, Senegal, Ivory Coast, Brazil (LGPD), Argentina and Colombia.

    You receive

    • Transfer mapping and mechanism selection
    • Transfer impact assessments
    • Local law gap analysis per country
    • Local registration and filing support

Artificial intelligence

The AI Act and ISO 42001, applied to the systems you are already deploying.

  • AI Act qualificationTypical duration: 3–8 days

    For each AI system: are you a provider or a deployer, is it prohibited, high risk, limited risk or minimal, and which obligations start on which date.

    You receive

    • AI system inventory
    • Role and risk classification per system
    • Obligation matrix with dates
    • Decision record for the file
  • AI Act high-risk complianceTypical duration: 15–40 days

    The full obligation set for high-risk systems: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment.

    You receive

    • AI risk management system
    • Data governance and quality measures
    • Technical documentation file
    • Human oversight design and conformity route
  • ISO/IEC 42001 AI management systemTypical duration: 20–40 days

    A management system for AI that carries much of the AI Act evidence with it, built on your existing ISO 27001 system rather than alongside it.

    You receive

    • Scope and AI policy
    • AI impact assessment process
    • Controls and documented information
    • Internal audit and certification preparation
  • Generative AI acceptable-use policyTypical duration: 3–6 days

    A short, usable policy that says which tools are approved, what may be pasted into them, who reviews the output, and what happens to shadow AI already in use.

    You receive

    • Acceptable-use policy
    • Approved tool list and approval route
    • Data classification rules for prompts
    • Staff communication pack

GRC advisory services

Policies, continuity plans, data classification, a virtual CISO or DPO, and the committee that keeps the risk register honest.

  • Policy frameworkTypical duration: 8–15 days

    An information security policy set your teams can actually follow, mapped to the frameworks you answer to, with the approval and review cycle already defined.

    You receive

    • Information security policy and charter
    • Topic-specific policies and standards
    • Control-to-policy mapping
    • Review and approval calendar
  • Business continuity and disaster recoveryTypical duration: 10–25 days

    Business impact analysis, continuity strategy and a recovery plan that has been tested, not just written, with the cyber scenario treated as a first-class case.

    You receive

    • Business impact analysis
    • Continuity and recovery strategy
    • Disaster recovery runbooks
    • Test plan and exercise results
  • Data classificationTypical duration: 3–6 weeks

    A classification scheme your staff can apply without a lawyer, the labels wired into Microsoft Purview or its equivalent, and the handling rules that follow from each level.

    You receive

    • Classification scheme and handling rules
    • Labels configured and rolled out
    • Adoption figures after sixty days
  • Virtual CISO and DPOTypical duration: Recurring

    A senior specialist at a fixed number of days a month who carries the security function, the data-protection function, or both, and answers for them to your board and your regulator.

    You receive

    • Named officer and monthly days
    • Roadmap ownership and committee attendance
    • Regulator and auditor point of contact
  • Governance and risk management supportTypical duration: Recurring

    The security committee run for you: agenda, risk register kept current, decisions recorded, actions chased, and the quarterly report your board reads.

    You receive

    • Committee cadence and minutes
    • Risk register maintained monthly
    • Quarterly board report
  • Unified control frameworkTypical duration: 5–12 days

    One set of controls mapped across NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act, so evidence is produced once and answers every audit that asks for it.

    You receive

    • Unified control catalogue
    • Cross-framework mapping matrix
    • Evidence plan per control
    • Audit response playbook
  • GRC toolingTypical duration: 5–15 days

    Selection and implementation of a compliance platform — Vanta, Drata, Secureframe or a European alternative — configured around your control framework rather than the vendor's default.

    You receive

    • Requirements and tool selection
    • Platform configuration and integrations
    • Automated evidence collection
    • Team handover and runbook
  • Compliance-as-a-ServiceTypical duration: Recurring

    Compliance run as a subscription: the calendar, the evidence, the internal audits, the supplier reviews and the regulatory watch, handled continuously instead of in an annual panic.

    You receive

    • Annual compliance calendar
    • Continuous evidence collection
    • Quarterly compliance report
    • Regulatory change watch

Governance and risk

What you hold, what it is worth, who you depend on, and what would hurt if it fell.

  • Third-party and supply-chain securityTypical duration: 5–15 days

    Supplier risk handled as a process rather than a spreadsheet: tiering, due diligence, contractual security clauses and the evidence NIS2 and DORA expect you to hold.

    You receive

    • Supplier tiering model and register
    • Due-diligence questionnaires by tier
    • Contractual security and audit clauses
    • Monitoring and review process
  • Cyber insurance and M&A due diligenceTypical duration: 3–10 days

    The evidence an insurer or an acquirer will ask for, gathered and challenged before they ask, so the premium or the valuation reflects your real posture.

    You receive

    • Insurer questionnaire pack with evidence
    • Control gap analysis against policy conditions
    • Target posture assessment for M&A
    • Remediation plan with cost estimates

NIS2 Ready

From applicability to a defensible compliance position, with the governance duties covered.

Duration
8–12 weeks
Price
€18,000 to €35,000
excl. VAT, indicative

Discuss this pack — NIS2 Ready

DORA Essentials

The four DORA pillars covered, including the register of information ready for submission.

Duration
10–16 weeks
Price
€30,000 to €60,000
excl. VAT, indicative

Discuss this pack — DORA Essentials

ISO 27001 in 9 months

A certification project with a date, a fixed price and a certification body engaged early.

Duration
9 months
Price
€25,000 to €45,000
excl. VAT, indicative, excludes certification body fees

Discuss this pack — ISO 27001 in 9 months

SOC 2 Fast Track

Type I, then the observation window for Type II, with evidence collected automatically.

Duration
4–6 months
Price
€20,000 to €40,000
excl. VAT, indicative, excludes auditor fees

Discuss this pack — SOC 2 Fast Track

Compliance-as-a-Service

Your compliance obligations run continuously: evidence collected as it is produced, internal audits on schedule, regulatory changes watched, and the audit answered without a scramble.

What is included

  • Annual compliance calendar
  • Continuous evidence collection
  • Internal audit programme
  • Quarterly compliance report
  • Regulatory change watch

Available tiers

  • One framework
  • Two frameworks
  • Multi-framework
GRC

Discuss this service — Compliance-as-a-Service

Outsourced DPO

A designated data protection officer with the independence the GDPR requires, handling the register, impact assessments, data subject requests and the supervisory authority.

What is included

  • DPO designation and notification
  • Register and DPIA maintenance
  • Data subject request handling
  • Staff advice and training
  • Annual report to management
GRC

Discuss this service — Outsourced DPO

Multi-country regulatory support

One point of contact for regulatory questions across Europe, French-speaking Africa and South America, answered with local partners who practise in that jurisdiction.

What is included

  • Regulatory watch per country
  • Local filing and registration support
  • Cross-border transfer maintenance
  • Local partner coordination
  • Consolidated quarterly briefing
GRC

Discuss this service — Multi-country regulatory support

vCISO

A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.

What is included

  • Named senior consultant
  • Security roadmap and budget ownership
  • Board and executive reporting
  • Supplier and customer security reviews
  • Escalation availability during incidents

Available tiers

  • Essential · 2 days per month
  • Standard · 4 days per month
  • Extended · 8 days per month
AdvisoryGRC

Discuss this service — vCISO

Start with applicability

Two to four days settles which regulations apply to which entity, from when, and what has to be registered. Everything else is easier to plan afterwards.