Compliance
We help businesses meet requirements within GDPR, NIS2, ISO/IEC 27001 — and assess risks with cloud services and AI
The challenge
GDPR, the NIS2 directive and ISO/IEC 27001 all set different but overlapping requirements — and the consequences of non-compliance are significant. Cloud services and subcontractors create risks outside your control. Many businesses lack the internal expertise to interpret the requirements and build the processes needed.
What we do
We start with a gap analysis against the regulations that apply to you. Then we build documentation, policies and processes — from data protection and incident management to risk assessment and certification preparation. We assess your cloud services and suppliers. You get ongoing support so compliance holds over time.
What you get
Gap analysis and mapping
We map your current compliance against GDPR, NIS2 and ISO/IEC 27001 and identify where the gaps are.
Documentation and policies
We produce the documents, policies and procedures required — tailored to your business, not generic templates.
Ongoing support and follow-up
Compliance is not a one-off project. We follow up regularly and help you keep documentation and processes up to date.
What's included
Unsure where you stand?
We'll do a free review of your situation and tell you which requirements apply to you.
Contact usFrequently asked questions
Which regulations do you cover?
GDPR, the NIS2 directive and ISO/IEC 27001. Whether you need support in one specific area or all three — we tailor the effort.
How long does a gap analysis take?
Typically 2–4 weeks depending on the size and complexity of the business.
What do we get after a gap analysis?
A clear picture of where you stand, what gaps exist and a prioritised action plan. No generic reports — everything is tailored to your business.
Do we need to get certified?
Not necessarily. We help you decide what gives the most value — sometimes meeting the requirements without formal certification is enough.
Can you support us on an ongoing basis?
Yes. Compliance is not a one-off project. We follow up regularly, keep documentation current and are available when regulations or your business change.
How do you handle cloud services and AI?
We assess your cloud services, third-country transfers and AI usage against applicable regulations. You get a risk assessment and concrete recommendations.
Need help with compliance?
Tell us about your situation and we'll give you an honest assessment. Free of charge, no obligation.