03 of 05
From gap assessment to certification, end-to-end.
Built on how certification audits actually run — Stage 1, Stage 2, surveillance.
Definition of audit boundary and mapping controls clause-by-clause against target frameworks (ISO 27001, SOC 1/2, GDPR, DPDP). For ISO 27001:2022, includes all 93 Annex A controls and a draft Statement of Applicability.
Policy authoring and control implementation run as tracked sprints. Includes a formal risk assessment and risk treatment plan mandatory for ISO 27001.
Continuous, automated collection of timestamped/version-controlled evidence. Includes mandatory artifacts such as the SoA, internal audit programs, and management review minutes.
Internal mock audit dress rehearsal. Full management of the external process (Stage 1, Stage 2, walkthroughs, queries). For SOC 2, includes sequencing Type I and Type II observation windows.
Automated monitoring for configuration drift ensures readiness for annual surveillance audits. Management of privacy obligations including GDPR 72-hour breach clocks and CERT-In 6-hour reporting directions.