Certifications that survive the second audit

Readiness and implementation work built for recertification, not just the first pass.

Overview

Certification and Attestation is readiness, implementation and audit support across ISO 27001, SOC 2, ISO 22301, PCI DSS and sector schemes like Cyber Essentials, HITRUST and TISAX.

The goal is a certification that holds up at surveillance audit and recertification, not just the day the certificate gets issued.

How it works

  1. Gap assess

    Current controls measured against the target framework.

  2. Implement

    Controls, evidence and internal audit program built to close the gaps.

  3. Certify

    Support through the certification audit itself.

  4. Sustain

    Surveillance audit and recertification support so the certificate stays valid.

What's included

  • ISO 27001 readiness, implementation and certification support
  • SOC 2 Type I and Type II readiness
  • ISO 22301 business continuity management certification
  • PCI DSS compliance readiness
  • Sector and regional schemes: Cyber Essentials, HITRUST, TISAX
  • Surveillance audit and recertification support
  • Internal audit program design and execution

Worried about surviving the next audit?

Talk to an advisor

FAQs

Can you run more than one framework at once, like ISO 27001 and SOC 2?

Yes. Overlapping controls are mapped once and reused across frameworks instead of duplicating the work.

What happens after we're certified?

Surveillance audit and recertification support, plus an internal audit program so gaps get caught before the external auditor does.

Get certified, and stay certified

Readiness and implementation across ISO 27001, SOC 2 and sector schemes, with recertification support built in.