Free ISO 27001 Assessment

Compliance Services

Real people. Backed by smart software.

Our certified experts build your GDPR or ISO 27001 program with you — and run it in GRCTrail, so everything is documented, owned by your team and ready for the audit.

  • 30-minute consultation
  • No commitment
  • 30-day money-back guarantee

Trusted Delivery

Delivered by certified experts

ISO 27001 Lead Implementer

ISO 27001 Lead Implementer

Certified lead implementer with deep expertise in information security management systems (ISMS). Guides companies from gap analysis to certification readiness.

ISO 27001Information Security
Serhii Vats

Serhii Vats

Founder & CTO

10 years in software development and security. Hands-on in every engagement — from scoping and risk assessment to audit preparation.

EngineeringSecurityAudit prep

Every engagement is delivered by certified practitioners — an ISO 27001 lead implementer for security, with hands-on founder involvement throughout.

What you get

One engagement. GDPR, ISO 27001, or both.

We scope the work to your company on the consultation call, then build the whole program with your team. Request a quote and we'll reply within one business day.

Pick one framework or both. When you do both, we run a single risk assessment and map each control once — no duplicate work.

Request a quote

For GDPR

  • Privacy policies and notices tailored to your company — not generic templates
  • Records of Processing Activities (ROPA), ready for any DPA inquiry
  • Data subject request (DSAR) process designed and tested
  • Vendor and DPA register — no third-party blind spots
  • Every data activity mapped to a clear legal basis

For ISO 27001

  • Gap analysis and risk assessment — know exactly where you're exposed
  • Statement of Applicability completed and justified
  • Annex A controls mapped, assigned and owned
  • Core security policies drafted and review-ready
  • Stage 1 and Stage 2 audit preparation

Always included

  • Weekly working sessions with your consultant or lead implementer
  • Async support throughout the engagement
  • An organised evidence pack that you own
  • Handover and training for the people who will maintain it

Questions? Book a free 30-minute consultation — we'll recommend the right path to your certification.

Everything we produce is yours to keep — policies, registers, risk assessments and an organised evidence pack — ready to take into your certification audit.

The Process

What we do, and when

  1. 1

    Before you commit

    Free consultation

    A 30-minute call to review where you stand, agree the scope — GDPR, ISO 27001 or both — and send you a quote with a schedule.

  2. 2

    Week 1

    Kick-off and gap analysis

    We map your current posture against the framework, run the risk assessment and agree the plan with the people who own each area.

  3. 3

    The following weeks

    Build the program

    We write the policies, registers and Statement of Applicability, map and assign the controls, and organise the evidence — in weekly working sessions with your team.

  4. 4

    Before the audit

    Handover and audit prep

    We walk your team through everything, rehearse the auditor's questions and stay on call through Stage 1 and Stage 2.

How long it takes depends on your scope and how quickly your team can review and sign off. We agree the schedule on the consultation call, and it's written into your quote.

FAQ

Questions, answered

What do I get at the end?

A complete, audit-ready compliance program you own: policies, registers, risk assessments, a Statement of Applicability (for ISO 27001) and an organized evidence pack — everything you need to walk into your certification audit.

Do I need technical knowledge?

No. Our certified experts do the compliance work and explain everything in plain language. We train your team so you can maintain it after the engagement.

Which frameworks do you cover?

GDPR and ISO 27001 — separately or together. Most teams pursuing certification start with one and add the other.

How long does it take?

It depends on your scope and on how fast your team can review and approve what we produce. We agree a realistic schedule during the consultation and put it in your quote — no timeline you didn't sign up for.

What if I'm not satisfied?

We offer a 30-day money-back guarantee on every engagement. If you're not happy with the deliverables, you get a full refund.

Do you support companies outside the EU?

Yes. If your company processes EU personal data or serves EU customers, we can help — wherever you're headquartered.

Not sure where to start?

Book a free 30-minute consultation. We'll review your current compliance posture and recommend the right path to certification — no commitment, no pitch.