| ISO 27001 |
Enterprise customers, international markets |
ISMS design and implementation, certification and surveillance audit ownership |
| SOC 2 |
US enterprise & SaaS buyers |
Control design, evidence automation, Type I → Type II programme leadership |
| GovRAMP / StateRAMP |
US state & local public-sector sales |
Full programme leadership: control register, policies, 3PAO assessment, authorisation |
| Cyber Essentials+ |
UK government & supply-chain requirements |
Gap assessment, remediation and certification |
| DORA |
EU financial services & their ICT suppliers |
Gap analysis, ICT risk framework, resilience testing and register of information |
| ISO 42001 |
Demonstrable AI governance |
AI management system design anchored to how your teams actually build and buy AI |
| NIST CSF 2.0 |
Board-level risk framing, US customers, maturity benchmarking |
Maturity assessment against the six functions, target profile, prioritised roadmap |
| NIST SP 800-53 |
Federal, state and regulated US environments; underpins FedRAMP and GovRAMP |
Control selection and tailoring, System Security Plan authoring, control implementation evidence |
| HIPAA |
Handling protected health information for US healthcare clients |
Security Rule risk analysis, safeguards assessment, BAA readiness and remediation |
| HITRUST CSF |
US healthcare buyers demanding a certified assurance |
Scoping, readiness assessment, control mapping and route to validated assessment |
| NCSC CAF |
UK critical national infrastructure, NIS Regulations, public-sector operators |
Self-assessment against the four objectives and contributing outcomes, gap analysis and improvement plan for regulator review |
| Enhanced CAF (eCAF) |
Operators of essential services in higher-risk sectors requiring deeper assurance |
Assessment against the enhanced profile, evidence pack and remediation roadmap aligned to your competent authority's expectations |
| GDPR / UK GDPR / DPA 2018 |
Baseline UK/EU obligation for any organisation processing personal data |
Compliance assessment, DPIAs, records of processing, privacy-by-design integration and remediation |
| Global data privacy |
Multinational operations across 33 jurisdictions — CCPA/CPRA, PIPEDA, LGPD, PDPA, POPIA, PIPL and others |
Multi-jurisdiction gap analysis, harmonised control framework, cross-border transfer mechanisms and local-law overlays |