Compliance
Compliance
Work out which framework actually applies to you before you spend anything.
Most organisations do not choose a compliance framework. A framework arrives — in a customer's procurement questionnaire, a contract clause, a regulator's scope, or an investor's diligence list. The question is rarely which one you would prefer. It is which one applies, what it actually requires, and how much of it you already meet.
How to tell which one applies to you
The frameworks below overlap considerably in their underlying controls but differ entirely in who mandates them and why. ISO 27001 is an international standard for an information security management system. Nobody legally requires it, but enterprise customers frequently do, and it travels well internationally. SOC 2 serves a similar purpose in US procurement, particularly for software and service companies, and results in a report rather than a certificate. Cyber Essentials is UK government-backed and often mandatory for central government and NHS supply chain work. CMMC is mandatory for US Department of Defense contractors handling federal contract information or controlled unclassified information. NIS2 and DORA are EU law, applying to essential and important entities, and to financial entities and their critical ICT providers respectively. A useful shortcut: if a specific customer or regulator named the framework, that is your answer and there is nothing to decide. If nobody named one and you are trying to demonstrate general credibility, ISO 27001 in the UK and Europe, or SOC 2 in the US, are the usual starting points. If you are guessing, it is worth an hour with someone before you commit to a programme that runs for months.
Who needs it
- Companies that received a customer security questionnaire and are not sure what is being asked of them
- Businesses told a contract requires certification, without being told which one or to what level
- Organisations expanding into a new market or sector with unfamiliar requirements
- Teams weighing two frameworks and wanting a view that is not from someone who sells only one of them
What you get
An answer to the scoping question first
Which framework applies, at what level, and how much of the requirement your existing controls already satisfy — before you commit budget to a programme.
Matching to consultants for the right framework
Consultants experienced in the specific framework and in organisations your size, rather than generalists working from a template.
Clarity on who does what
For every framework here, the consultant who prepares you is separate from the body that certifies or attests. We make that split explicit so you can budget for both.
Frequently asked questions
What is the difference between ISO 27001 and SOC 2?
ISO 27001 certifies a management system against an international standard and produces a certificate recognised globally. SOC 2 produces an audit report by a licensed CPA firm describing how your controls performed, and is predominantly a US procurement expectation. ISO is the more common ask in the UK and Europe, SOC 2 in the US. Companies selling into both markets often end up doing both, which is less duplicative than it sounds because the underlying controls substantially overlap.
Can we do more than one at once?
Yes, and it is often efficient. The control sets overlap heavily, so evidence gathered for one substantially serves another. The usual approach is to build the control environment once and then map it to each framework's requirements. Running two certification programmes in parallel from a standing start is harder, but sequencing them within twelve months is common.
How long does compliance take?
For an organisation starting with limited formal documentation, three to nine months to reach certification or audit readiness is a realistic range, depending on framework and scope. The variable is rarely the paperwork. It is how much of the underlying control environment genuinely exists versus needs building, which is what a gap analysis at the start is for.
Do we need a consultant, or can we do it ourselves?
It is possible to self-manage, particularly for a small organisation with a simple estate and someone who can dedicate real time to it. Where a consultant earns their fee is in knowing what auditors actually expect — which is often narrower and more specific than the standard's text suggests — and in avoiding the months lost to over-documenting things that were never in scope.