Overview
Certification and Attestation is readiness, implementation and audit support across ISO 27001, SOC 2, ISO 22301, PCI DSS and sector schemes like Cyber Essentials, HITRUST and TISAX.
The goal is a certification that holds up at surveillance audit and recertification, not just the day the certificate gets issued.
How it works
-
Gap assess
Current controls measured against the target framework.
-
Implement
Controls, evidence and internal audit program built to close the gaps.
-
Certify
Support through the certification audit itself.
-
Sustain
Surveillance audit and recertification support so the certificate stays valid.
What's included
- ISO 27001 readiness, implementation and certification support
- SOC 2 Type I and Type II readiness
- ISO 22301 business continuity management certification
- PCI DSS compliance readiness
- Sector and regional schemes: Cyber Essentials, HITRUST, TISAX
- Surveillance audit and recertification support
- Internal audit program design and execution
Worried about surviving the next audit?
Talk to an advisorFAQs
Can you run more than one framework at once, like ISO 27001 and SOC 2?
Yes. Overlapping controls are mapped once and reused across frameworks instead of duplicating the work.
What happens after we're certified?
Surveillance audit and recertification support, plus an internal audit program so gaps get caught before the external auditor does.
Get certified, and stay certified
Readiness and implementation across ISO 27001, SOC 2 and sector schemes, with recertification support built in.
