Governance, Risk & Compliance

Eight frameworks. One set of controls underneath.

Most organisations need one certification and two or three others satisfied contractually. The controls behind them overlap heavily, so we implement once and map to everything. This page is the map — each framework has its own page with the scope, the method and the deliverables in full.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
8Frameworks supported
31Mapped finding categories
LiveEvidence collection
0Spreadsheets required

Implement once. Map to everything.

Access control, change management, risk assessment, logging, incident response and vendor due diligence appear in almost every framework on this page. They are worded differently, evidenced differently and audited differently, but underneath they are the same controls doing the same job. Organisations that run a separate programme per framework end up building them three times, maintaining three sets of evidence, and discovering in year two that the three have quietly drifted apart.

So we start from the control set rather than the standard. One implementation, one risk register, one evidence trail, mapped outward to whichever frameworks you actually have to satisfy. Adding a second framework to an organisation that already has the controls operating is a mapping exercise and an audit, not another programme — which is why the order you take them in has a real effect on cost.

The other half is that evidence should be a by-product of controls operating, not a task somebody performs before an audit. SemperWise One™ maps controls to live signals across these frameworks, collects the evidence continuously, and flags a control the day it drifts rather than eleven months later. Our security testing feeds the same register, so a penetration test finding and a control failure are one object rather than two teams’ separate problems.

Coverage

Pick the standard that applies to you

Each summary below is the short version. The full approach, scope, method and deliverables live on the dedicated page — follow the link. If you are not sure which one you actually need, that is the first thing we work out on a scoping call, and the answer usually depends on who is asking you for it.

ISO 27001

The international standard for an information security management system, and the one most European, Indian and Middle Eastern buyers and tender processes ask for by name. We build the ISMS, run the risk treatment and prepare you for Stage 1 and Stage 2 — an accredited certification body issues the certificate, not us.

Read the full ISO 27001 approach →

SOC 2

The report North American technology buyers ask for before they will trust you with their data. Readiness against the Trust Services Criteria, control design and evidence collection for Type I or Type II — the attestation itself comes from a licensed CPA firm.

How SOC 2 readiness works →

DPDP Act 2023

India’s data protection law. The 2025 Rules turned it from a principle into a dated obligation, so it carries a commencement timeline, a penalty schedule and duties that now have deadlines attached to them.

India’s DPDP Act, in full →

GDPR

The EU regime, which reaches Indian companies through Article 3 whenever they serve or monitor people in the EU. Records of processing, lawful basis, DPIAs, subject rights and the transfer mechanism almost every Indian vendor is missing.

Check whether GDPR reaches you →

HIPAA

US healthcare data rules. If you process, host or support anything touching US patient data on behalf of a covered entity, you are a Business Associate — with obligations that attach whether or not anyone sent you a contract.

Business Associate readiness →

PCI DSS

Mandatory if you store, process or transmit cardholder data. We cut the scope first, because the cheapest control is the data you never touch, then close what genuinely remains at v4.0.1.

Start with PCI scope reduction →

NIST CSF

A maturity framework rather than a certification — there is no certificate and nobody can sell you one. The right tool when a board or an insurer wants a defensible score and a roadmap instead of a badge.

See the maturity assessment →

ISO 42001

The AI management system standard, and the first certifiable one. Increasingly requested by enterprise buyers before they will let an AI feature near their data.

AI management systems →

Approach

How a compliance programme runs

A first ISO 27001 certification typically takes four to nine months depending on starting position and how much of the organisation is in scope.

  1. 01 · Scope

    What is being certified, which entities and systems are included, and what can be legitimately excluded. Getting this right is the single largest lever on cost.

  2. 02 · Gap assessment

    Where you are against where you need to be, with each gap costed in effort rather than listed as a requirement.

  3. 03 · Risk assessment

    A risk register your management team can actually discuss, with treatment decisions recorded and owned.

  4. 04 · Implement

    Controls built and documented, policies written to match how the organisation works, and evidence collection automated wherever the platform can do it.

  5. 05 · Test and audit

    Independent technical testing for the controls that require it, then an internal audit and management review that a certification body will accept.

  6. 06 · Certify and sustain

    Support through the external audit, then continuous monitoring so the surveillance audit is a review rather than a rebuild.

Run against recognised standards

  • ISO/IEC 27001:2022ISMS certification
  • ISO/IEC 27701Privacy extension where required
  • SOC 2AICPA trust services criteria
  • DPDP Act 2023India data protection
  • GDPREU data protection
  • HIPAAUS healthcare
  • PCI DSSCard payments
  • NIST CSFMaturity and risk framework

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Gap assessment with costed remediation

Every gap with an effort estimate and an owner, so the programme can be planned rather than discovered.

Complete policy set

Written for your organisation, in language your staff will follow, not a renamed template pack.

Risk register and treatment plan

Live, owned and reviewable — the document auditors examine most closely and clients maintain worst.

Automated evidence collection

Controls monitored continuously in SemperWise One™, with evidence gathered as an artefact of operation.

Internal audit and management review

Run properly, documented properly, and accepted by certification bodies.

Audit support

We are in the room for Stage 1 and Stage 2, and we answer the technical questions so your team does not have to.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • A customer contract requires ISO 27001 or SOC 2 and there is a deadline attached.
  • You process personal data of Indian residents and have not addressed the DPDP Act.
  • You are certified but the surveillance audit is a fire drill every year.
  • You sell to healthcare, banking or government and are being audited by your customers.
  • You have policies nobody reads and controls nobody operates, and you know it.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Compliance & Audit — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

How long does ISO 27001 certification take?

Four to nine months for most organisations, driven by starting position and scope rather than by company size. A company with reasonable IT discipline, a clear scope and an internal owner who can give it real time can be audit-ready in about four months. A company starting from nothing, with a broad scope and no dedicated owner, should plan for nine. The certification body also needs Stage 1 and Stage 2 booked, with a gap between them, which adds calendar time you cannot compress.

What does ISO 27001 certification cost in India?

Two separate costs. The certification body charges its own audit fee, which depends on scope and headcount and is paid directly to them — we do not mark it up. Our implementation fee depends on how much of the work you can absorb internally: organisations with an existing IT function and an engaged owner pay considerably less than those needing the whole programme delivered. We scope it properly and quote a fixed price rather than an hourly rate that grows.

Can you be both our consultant and our auditor?

No, and nobody legitimate can. The certification audit must be performed by an accredited certification body that is independent of whoever implemented the ISMS. We implement, we run your internal audit, and we support you through the external audit — but the certificate is issued by an independent body, and any firm offering to do both is offering you a worthless certificate.

Do we need ISO 27001 or SOC 2?

It usually depends on who is asking. European, Indian and Middle Eastern enterprise buyers, and most tender processes, ask for ISO 27001. North American technology buyers ask for SOC 2. If you sell to both, start with ISO 27001 — it is a management system, so it gives you the structure — and add SOC 2 afterwards, which is considerably cheaper in that order than the reverse.

What is the DPDP Act and does it apply to us?

The Digital Personal Data Protection Act 2023 is India’s data protection law. It applies to any organisation processing the digital personal data of individuals in India, and to processing outside India where goods or services are offered to people in India. In practice that is almost every business with Indian customers or Indian employees. The obligations centre on consent and notice, data-principal rights, security safeguards, breach notification and additional duties for organisations designated as Significant Data Fiduciaries. The DPDP Rules 2025 attached dates to all of it, so we cover the timeline, the penalty schedule and what readiness actually looks like on our DPDP Act Compliance page at /dpdp-act-compliance.

We already have policies. Can you just review them?

Yes, and it is a sensible first step — a gap assessment against your existing documentation costs a fraction of a full programme and tells you honestly how far you are. Be prepared for the common finding: the policies are fine, and nothing described in them is happening. Auditors test the operation of controls, not the existence of documents.

Does compliance make us secure?

No. It makes you consistent, and consistency is a precondition for security, not a substitute for it. A compliant organisation has decided what its controls are and can show they operate. Whether those controls stop a competent attacker is a separate question, which is what testing answers. This is exactly why we do both, and why our testing findings feed the same risk register the compliance programme runs on.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.