Compliance & certification
We help organisations shape good policy and implement it — right through to certification. Using tools your organisation already has, or the best tools on the market.
Standards we work with
- GDPR — privacy policy, processing register and data breach procedures.
- ISO 9001 — quality management.
- ISO 14001 — environmental management.
- ISO 27001 / 27002 — information security, including ISMS setup.
From policy to certificate
Assessment
Where do you stand now? A baseline measurement of processes, risks and existing documentation.
Policy and processes
Practical policy that fits your organisation — no paper tiger.
Implementation
Rolling out processes and measures, with buy-in from staff.
Certification
Guidance through the external audit, until the certificate is in hand — and afterwards.
Looking for ongoing coverage of the security role? Take a look at (CI)SO as a Service.
Our approach: pragmatic steps to the certificate
Risk-driven
No tick-box exercises: the risk analysis determines which measures get priority. That way you meet the standard and become genuinely more secure.
Policy that's actually lived
Documentation that fits your organisation: concise, understandable and workable. Policy that sits in a drawer protects no one.
Continuous improvement
With a plan-do-check-act cycle and guidance through internal and external audits, your management system stays current — even after the certificate is achieved.