Gap assessment and scope definition
What applies, what does not, and why. Getting the scope right is the single highest-leverage decision in any certification, and the one most often rushed.
Governance, Risk & Compliance
Most compliance engagements sell you readiness and then leave. You are ready, the audit is somebody else's problem, and six months later the evidence has gone stale. This is the whole thing, run for you, on a subscription.
A readiness engagement produces documents. A gap assessment, a risk register, a policy set, a Statement of Applicability, and a list of things to do. All of it correct, all of it delivered, and none of it self-maintaining. The consultant leaves, the client discovers that the evidence has to be collected by somebody every quarter, and by month nine the programme is a folder nobody has opened.
The second disappointment is the handover to the audit. Readiness and certification are usually bought separately, which means the moment of maximum confusion — the first contact with the certification body, the scope definition, the Stage 1 findings — is the moment nobody is accountable for. A great deal of the pain in a first certification is concentrated in exactly that gap.
So this is sold as one thing, on a subscription: the programme, the platform that keeps it alive, the testing evidence behind the technical controls, and the coordination through Stage 1 and Stage 2 to the certificate. It does not end when you are ready, because being ready is not the thing you wanted.
Coverage
The work, the platform and the audit coordination, as one subscription.
What applies, what does not, and why. Getting the scope right is the single highest-leverage decision in any certification, and the one most often rushed.
Working through the controls with the people who own them, in SemperWise One rather than in a spreadsheet, so state and evidence live in the same place as the work.
Adapted to how you actually operate. A policy set nobody has adapted reads exactly like a policy set nobody has adapted, and assessors notice.
Access records, policy register, audit trail, processors, consents — gathered automatically where the platform can, chased where it cannot, and dated either way.
Penetration testing and vulnerability management behind the technical controls, run by us, mapped to the clauses they evidence. Most compliance providers subcontract this.
Run properly, minuted, and tracked to closure — the parts of the standard that are easiest to do badly and most visible when you do.
Managing the process with the certification body you appoint, through Stage 1 and Stage 2, and handling findings to closure.
The programme keeps running. A certificate is maintained, not achieved — and the surveillance audit is where an unmaintained one falls over.
Approach
Typical first certification. The timeline depends on your starting point, which the gap assessment establishes.
What is in scope, where you stand against it, and a plan with owners and dates.
Controls, policies, risk treatment and the evidence routine — set up so it keeps running without us.
The standard requires evidence of controls operating over a period. This is that period, and it is why certification cannot be compressed indefinitely.
Before the external audit finds them, we do.
Coordinated with your certification body, with us in the room and findings closed against a plan.
Surveillance, re-certification, and the programme carrying on between them.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Controls, owners, test dates and dated evidence in SemperWise One — not a folder of documents.
Policies, Statement of Applicability, risk treatment plan, internal audit records and management review minutes.
Assessment reports behind the technical controls, with findings tracked to closure and retested.
Coordination with your certification body through both stages, and findings closed against a plan.
Set up so your team can run it. A dependency on your consultant is not a compliance programme.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No, and nobody selling you consultancy can. ISO 27001 certificates are issued by accredited certification bodies, a SOC 2 report is issued by a licensed CPA firm, and a PCI assessment is signed by a QSA. Those are independent parties and the independence is the entire point of the certificate. We run the programme, produce the evidence and manage the process with them — and we say this plainly because a provider who is vague about it is telling you something.
We coordinate with whichever body you appoint, and we can introduce you to accredited ones if you have not chosen. We do not resell audits or take a commission on them, and we would be cautious of anybody who does — a provider with a financial interest in which body assesses you has an interest that is not yours.
It depends almost entirely on where you start, which is what the gap assessment is for. The constraint that cannot be compressed is that the standard requires evidence of controls operating over a period, so an organisation starting from nothing should plan in months rather than weeks. Anybody quoting a fixed timeline before looking at your environment is quoting a sales number.
That is normal, and most engagements are. Some clients have a compliance lead and want the platform and the testing evidence. Others want the whole thing. The gap assessment is a sensible first step either way, because it tells both of us what is actually needed.
Yes, and it is much cheaper than doing them in sequence. The platform holds one normalised control set behind every framework, so a control implemented for ISO 27001 evidences the equivalent clause in SOC 2, DPDP, SEBI CSCRF or IRDAI without being implemented again. The second framework is a mapping exercise rather than a second programme.
The programme keeps running — that is the difference between this and a readiness project. Evidence keeps being collected and keeps expiring on schedule, controls keep being tested, and the surveillance audit finds a maintained programme rather than a reconstructed one. Reconstructing a year of evidence in the fortnight before surveillance is the single most common way a certificate becomes a problem.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.