Skip to content
Red Vault
Blank papers held in a graphite frame with a metal clip and red index tab

Enable

Compliance and Regulations.

Defensible compliance, not just paperwork.

Turn a compliance requirement into a practical plan.

A customer asks for assurance. An audit is approaching. Your business needs to meet a security standard, but the work behind it is not yet clear. We help you understand the requirement, find the gaps and prepare the policies, controls and evidence your organisation needs.

Prepare for a first review
Establish the scope, understand what is already in place and organise the work needed before approaching your chosen auditor or certification body.
Resolve an existing gap
Address a finding, refresh outdated policies or improve an evidence process that is slowing down your next audit or customer review.
Coordinate several requirements
Connect overlapping controls across frameworks while keeping their specific requirements and evidence needs visible.

We provide preparation and practical support. Formal certification, attestation and specialist assessments remain with the appropriate independent provider.

Start with the requirement you need to meet.

Different frameworks lead to different kinds of review. Choose a direction to see how we can help with preparation and who carries out the formal assessment.

Prepare your ISMS for certification.

Build an information security management system around your actual business: its risks, responsibilities and working practices. We support the preparation needed for your chosen certification scope.

How we help you prepare

  • Define the ISMS boundaries and review the current position.
  • Develop risk assessment, treatment and Statement of Applicability documentation.
  • Prepare policies, control ownership and supporting evidence.
  • Plan readiness checks and the work needed for internal audit and management review.

The review route

An independent certification body conducts the certification audit. Your organisation owns the ISMS, operates its controls and makes the management decisions.

Build the evidence behind your next review.

Preparation should leave you with more than completed templates. We help create a record that connects your requirements, the work your team does and the evidence a reviewer can examine.

Illustrative photograph of a carmine red document folder on a charcoal folder, set back on a pale meeting table.
A clear gap and action register
Requirements linked to current evidence, missing work, priorities and responsible owners. Open questions stay visible so a document cannot be mistaken for a control that is already operating.
Policies connected to practice
Policies and procedures tailored to your organisation, with approval, ownership and review arrangements. We connect what the documents say to how your people actually work.
An organised evidence pack
An index of records, their locations and the requirements they support. Access reviews, change records, supplier checks and recovery tests can become evidence where relevant to your scope.
A readiness review and next actions
A walkthrough of the agreed requirements and evidence, with remaining gaps and follow-up work recorded. Your team receives a clear handover for maintaining the programme.

Reuse evidence where it fits.

A documented access review may support several requirements. We connect those requirements to the same underlying record, then identify any extra scope, detail or operating history each reviewer needs. Shared evidence reduces duplication; it does not make the frameworks interchangeable.

From requirements to a prepared team.

We agree a focused project or a broader preparation programme around your target, current position and available people. Each stage leaves your team with work it can understand and maintain.

  1. Define the requirement

    Review the request, target framework, systems and business boundaries. Agree deliverables, responsibilities and any assessor or specialist input before setting the fee and schedule.

  2. Build the action plan

    Compare the requirements with your policies, working practices and available evidence. Identify gaps, prioritise actions and agree who will own each change.

  3. Prepare and review

    Work with your team on policy updates, control documentation and evidence collection. Review progress and run an agreed readiness walkthrough to expose unresolved issues.

  4. Support the formal review

    Help organise the evidence, prepare the people involved and answer questions about our work during the review. Record follow-up actions and hand over the maintenance routine.

Before you book.

Do you certify us or carry out the official audit?

We help you prepare and can support the review within the agreed scope. ISO certification is issued by a certification body; SOC 2 examinations and reports are provided by an appropriately licensed CPA firm. Cyber Essentials certification goes through the scheme’s certification process. These external services are separate from our preparation work. We do not issue certificates or guarantee an audit outcome.

How can you help with PCI DSS?

We can help document payment flows, organise existing evidence, identify preparation gaps and coordinate remediation with your team. Your acquirer or payment brand confirms the required validation and reporting route, including whether a Self-Assessment Questionnaire is appropriate. We are not a Qualified Security Assessor. Where a QSA, Approved Scanning Vendor or other specialist is required, their work is separately arranged and scoped; our preparation does not replace it.

What does the engagement cost, and how long does it take?

The scope depends on your target, number of systems and entities, existing documentation, evidence quality and the work your team can take on. We agree a fee, deliverables and schedule after scoping. External assessor fees, technical testing and any additional implementation are identified separately. A target date also needs to allow for the chosen assessor’s availability and any required period of operating evidence.

Can you work with our auditor or compliance platform?

Yes. We can organise the preparation around your chosen reviewer’s evidence requests and use the tools you already have. We agree access, evidence locations and responsibilities first. Automation is considered where it is useful and feasible; it does not replace policy decisions, control ownership or an assessor’s judgement.

Can one programme cover several frameworks?

Yes. We can map common controls and reuse relevant evidence to reduce duplicate work. Each framework still has its own scope, criteria and review requirements. Evidence accepted for one purpose is not automatically sufficient for another, so framework-specific gaps remain part of the plan.

Can you help with supplier risk, data protection and AI governance?

These can be included when they are relevant to the requirement. Work may cover supplier inventories and due-diligence records, data inventories and retention, privacy-impact assessment inputs, or AI inventories and responsibilities. We work with your legal and data-protection advisers where interpretation, contracts or formal advice are needed. This is scoped preparation support, not a blanket claim to resolve every regulatory obligation.

What about sector-specific requirements or post-quantum readiness?

Tell us the requirement at the first conversation. Financial-services resilience, NHS DSPT preparation and other sector evidence can be considered after confirming scope and any specialist input. Cryptographic inventories and migration planning may also form part of a longer-term programme where relevant. These are agreed workstreams, not automatically included in every engagement.

Who owns compliance after the engagement?

Your organisation retains accountability, control ownership, approvals and ongoing operation. We document responsibilities and the evidence review routine during the handover. Internal audit and management review requirements must still be met; a readiness walkthrough is not a substitute. Any continuing support from Red Vault has its own agreed scope.

What access and documents do you need?

Start with the requirement or customer request, your target date, existing policies and a simple outline of the systems involved. We agree the evidence needed, confidentiality, storage and retention during scoping. Access is limited to the work, with read-only access where possible; production changes require a separate agreement.

Should we start with a cybersecurity assessment?

Start here when you have a defined compliance, audit or customer-assurance requirement. If you first need to understand your wider security position and priorities, a Cybersecurity Assessment provides that starting point. Any compliance preparation that follows is scoped and priced separately.

Let’s prepare for your next review.

Tell us which requirement you need to meet, your target date and what is already in place. We’ll help define a practical scope for the preparation.

contact@redvault.co.uk

How we handle your details: Privacy policy.