
Enable
Compliance and Regulations.
Defensible compliance, not just paperwork.
Turn a compliance requirement into a practical plan.
A customer asks for assurance. An audit is approaching. Your business needs to meet a security standard, but the work behind it is not yet clear. We help you understand the requirement, find the gaps and prepare the policies, controls and evidence your organisation needs.
- Prepare for a first review
- Establish the scope, understand what is already in place and organise the work needed before approaching your chosen auditor or certification body.
- Resolve an existing gap
- Address a finding, refresh outdated policies or improve an evidence process that is slowing down your next audit or customer review.
- Coordinate several requirements
- Connect overlapping controls across frameworks while keeping their specific requirements and evidence needs visible.
We provide preparation and practical support. Formal certification, attestation and specialist assessments remain with the appropriate independent provider.
Start with the requirement you need to meet.
Different frameworks lead to different kinds of review. Choose a direction to see how we can help with preparation and who carries out the formal assessment.
Prepare your ISMS for certification.
Build an information security management system around your actual business: its risks, responsibilities and working practices. We support the preparation needed for your chosen certification scope.
How we help you prepare
- Define the ISMS boundaries and review the current position.
- Develop risk assessment, treatment and Statement of Applicability documentation.
- Prepare policies, control ownership and supporting evidence.
- Plan readiness checks and the work needed for internal audit and management review.
The review route
An independent certification body conducts the certification audit. Your organisation owns the ISMS, operates its controls and makes the management decisions.
Prepare for a SOC 2 examination.
Connect the service you provide to the controls and evidence your customers need to understand. We help prepare the documentation and operating records for the scope agreed with your CPA firm.
How we help you prepare
- Clarify the service boundaries and relevant Trust Services Criteria.
- Map controls, responsibilities and evidence requests.
- Help prepare the system description and resolve documentation gaps.
- Organise readiness checks and evidence for the agreed examination period.
The review route
An appropriately licensed CPA firm performs the examination and issues the SOC 2 report. Type I addresses a specified date; Type II also examines operating effectiveness over a period.
Get the essentials ready for assessment.
Understand the scheme’s requirements and organise the changes your systems need. We can help with Cyber Essentials preparation and readiness for the additional technical assessment in Cyber Essentials Plus.
How we help you prepare
- Review the proposed scope and device inventory.
- Check preparation across firewalls, secure configuration, access control, malware protection and security updates.
- Work through questionnaire evidence with your IT team.
- Track the changes and remaining issues before submission or testing.
The review route
Certification is handled through the scheme’s certification process. Cyber Essentials Plus includes a technical assessment by a licensed certification body; our readiness work does not replace that assessment.
Prepare for your PCI DSS validation route.
Start with how payment data moves through your business and what your acquirer or payment brand requires. We help organise the preparation before the appropriate validation or specialist assessment.
How we help you prepare
- Document payment flows, systems and service-provider responsibilities.
- Help prepare evidence for the validation route confirmed by your acquirer.
- Track gaps and remediation with your technical team.
- Prepare the scope and evidence briefing for a QSA or specialist where required.
The review route
Your acquirer or payment brand determines validation and reporting requirements. We do not act as a QSA or provide ASV scans. Required assessor and testing services are separately arranged.
Make data-protection practice easier to demonstrate.
Bring together the security measures, responsibilities and records behind your handling of personal data. We support the practical evidence work alongside your data-protection and legal advisers.
How we help you prepare
- Review data inventories, responsibilities and relevant security policies.
- Document access, retention and security arrangements.
- Prepare security and data-flow inputs for DPIAs and supplier reviews.
- Organise evidence of decisions, reviews and agreed improvements.
The review route
Your organisation remains accountable for its data protection. We provide security and evidence support; legal interpretation and advice are handled with your responsible advisers.
Translate the applicable obligations into security work.
For organisations with an identified regulatory requirement, we help organise the security controls and supporting records. Applicability depends on the entity, sector, services and jurisdiction.
How we help you prepare
- Use the scope established with your responsible legal or regulatory advisers.
- Review evidence of ICT risk management and incident arrangements.
- Organise supplier, resilience and governance records.
- Build a prioritised action plan for the agreed security requirements.
The review route
DORA and NIS2 are regulatory obligations, not certification schemes. NIS2 requirements also depend on national implementation. Specialist interpretation and formal regulatory submissions are agreed separately.
Build the evidence behind your next review.
Preparation should leave you with more than completed templates. We help create a record that connects your requirements, the work your team does and the evidence a reviewer can examine.

- A clear gap and action register
- Requirements linked to current evidence, missing work, priorities and responsible owners. Open questions stay visible so a document cannot be mistaken for a control that is already operating.
- Policies connected to practice
- Policies and procedures tailored to your organisation, with approval, ownership and review arrangements. We connect what the documents say to how your people actually work.
- An organised evidence pack
- An index of records, their locations and the requirements they support. Access reviews, change records, supplier checks and recovery tests can become evidence where relevant to your scope.
- A readiness review and next actions
- A walkthrough of the agreed requirements and evidence, with remaining gaps and follow-up work recorded. Your team receives a clear handover for maintaining the programme.
Reuse evidence where it fits.
A documented access review may support several requirements. We connect those requirements to the same underlying record, then identify any extra scope, detail or operating history each reviewer needs. Shared evidence reduces duplication; it does not make the frameworks interchangeable.
From requirements to a prepared team.
We agree a focused project or a broader preparation programme around your target, current position and available people. Each stage leaves your team with work it can understand and maintain.
Define the requirement
Review the request, target framework, systems and business boundaries. Agree deliverables, responsibilities and any assessor or specialist input before setting the fee and schedule.
Build the action plan
Compare the requirements with your policies, working practices and available evidence. Identify gaps, prioritise actions and agree who will own each change.
Prepare and review
Work with your team on policy updates, control documentation and evidence collection. Review progress and run an agreed readiness walkthrough to expose unresolved issues.
Support the formal review
Help organise the evidence, prepare the people involved and answer questions about our work during the review. Record follow-up actions and hand over the maintenance routine.
Before you book.
Do you certify us or carry out the official audit?
We help you prepare and can support the review within the agreed scope. ISO certification is issued by a certification body; SOC 2 examinations and reports are provided by an appropriately licensed CPA firm. Cyber Essentials certification goes through the scheme’s certification process. These external services are separate from our preparation work. We do not issue certificates or guarantee an audit outcome.
How can you help with PCI DSS?
We can help document payment flows, organise existing evidence, identify preparation gaps and coordinate remediation with your team. Your acquirer or payment brand confirms the required validation and reporting route, including whether a Self-Assessment Questionnaire is appropriate. We are not a Qualified Security Assessor. Where a QSA, Approved Scanning Vendor or other specialist is required, their work is separately arranged and scoped; our preparation does not replace it.
What does the engagement cost, and how long does it take?
The scope depends on your target, number of systems and entities, existing documentation, evidence quality and the work your team can take on. We agree a fee, deliverables and schedule after scoping. External assessor fees, technical testing and any additional implementation are identified separately. A target date also needs to allow for the chosen assessor’s availability and any required period of operating evidence.
Can you work with our auditor or compliance platform?
Yes. We can organise the preparation around your chosen reviewer’s evidence requests and use the tools you already have. We agree access, evidence locations and responsibilities first. Automation is considered where it is useful and feasible; it does not replace policy decisions, control ownership or an assessor’s judgement.
Can one programme cover several frameworks?
Yes. We can map common controls and reuse relevant evidence to reduce duplicate work. Each framework still has its own scope, criteria and review requirements. Evidence accepted for one purpose is not automatically sufficient for another, so framework-specific gaps remain part of the plan.
Can you help with supplier risk, data protection and AI governance?
These can be included when they are relevant to the requirement. Work may cover supplier inventories and due-diligence records, data inventories and retention, privacy-impact assessment inputs, or AI inventories and responsibilities. We work with your legal and data-protection advisers where interpretation, contracts or formal advice are needed. This is scoped preparation support, not a blanket claim to resolve every regulatory obligation.
What about sector-specific requirements or post-quantum readiness?
Tell us the requirement at the first conversation. Financial-services resilience, NHS DSPT preparation and other sector evidence can be considered after confirming scope and any specialist input. Cryptographic inventories and migration planning may also form part of a longer-term programme where relevant. These are agreed workstreams, not automatically included in every engagement.
Who owns compliance after the engagement?
Your organisation retains accountability, control ownership, approvals and ongoing operation. We document responsibilities and the evidence review routine during the handover. Internal audit and management review requirements must still be met; a readiness walkthrough is not a substitute. Any continuing support from Red Vault has its own agreed scope.
What access and documents do you need?
Start with the requirement or customer request, your target date, existing policies and a simple outline of the systems involved. We agree the evidence needed, confidentiality, storage and retention during scoping. Access is limited to the work, with read-only access where possible; production changes require a separate agreement.
Should we start with a cybersecurity assessment?
Start here when you have a defined compliance, audit or customer-assurance requirement. If you first need to understand your wider security position and priorities, a Cybersecurity Assessment provides that starting point. Any compliance preparation that follows is scoped and priced separately.
Let’s prepare for your next review.
Tell us which requirement you need to meet, your target date and what is already in place. We’ll help define a practical scope for the preparation.
contact@redvault.co.uk