Depth 28 · Service line

Security and compliance readiness

Security and compliance readiness is the engineering work that puts a company in a position to meet security and data protection rules, and to show that it does. It turns written requirements into controls that exist in systems, with evidence that they work. Our part is preparation and implementation, not legal advice: whether a given law applies to you is a question for your counsel.

Inside this line

Three sub-services: NIS2 and DORA readiness, data protection contour and secure delivery.

Input
Your existing policies, an inventory of systems and suppliers, any prior audit findings, and a contact who owns security decisions.
Method
We read the requirement text, map each requirement to the systems it touches, check whether a working control exists, and collect evidence for each control from the systems themselves rather than from documents alone.
Deliverable
A register of controls with their evidence, a list of gaps with owners, and the technical fixes you choose to have us implement.
Measured by
Controls with current evidence, gaps closed against their planned dates, and findings from your own or external audits.

Level 3 · 01

NIS2 and DORA readiness

NIS2 and DORA readiness is preparation for two EU laws on cybersecurity and operational resilience. NIS2, Directive (EU) 2022/2555, sets security and incident reporting duties for medium and large organisations in sectors listed in the Directive, such as energy, transport, health and digital infrastructure. DORA, Regulation (EU) 2022/2554, sets rules on managing technology risk for financial entities in the EU and for some of their technology suppliers. UK organisations fall under the UK NIS Regulations 2018 and the ICO regime instead, so which set applies depends on where you operate. Whether any of them applies to your company is a legal question for your counsel; our work is preparation, not legal advice.

Inside it

  • Requirement breakdown from Directive (EU) 2022/2555 or Regulation (EU) 2022/2554
  • Mapping to systems and teams
  • Incident handling and reporting procedures
  • Supplier and third party risk review
  • Gap register with owners

Measured by Requirements with a working control and current evidence, and gaps closed against their planned dates.

Deliverable · Level 4→ Control gap registerControl gap register: every requirement, the control that meets it or the gap where none does, the evidence and an owner.

Level 3 · 02

Data protection contour

Data protection contour is the engineering side of data protection: knowing what personal data a company holds, where it flows, who can access it, how long it is kept and how it is deleted. It produces the records of processing, data flow maps, retention and deletion rules, access controls and subprocessor lists that a privacy programme depends on. It is not legal drafting; your lawyers write the policies and contracts.

Inside it

  • Records of processing activities
  • Data flow mapping
  • Retention and deletion in the systems
  • Access control review
  • Subprocessor list

Measured by Systems covered in the records of processing, records deleted on schedule, and data access requests answered within the period the applicable law sets.

Level 3 · 03

Secure delivery

Secure delivery is building security checks into the way software is written and released, so problems are caught before they reach production. It covers code review, dependency scanning, secrets handling, access to production and a record of what was deployed when. It reduces risk; it does not make software free of vulnerabilities.

Inside it

  • Dependency and code scanning
  • Secrets management
  • Reviewed changes only in production
  • Least privilege production access
  • Deployment audit trail

Measured by Open findings from scanners by severity and age, secrets found in code, and deployments without a linked review, which should be zero.

Where this applies

Who this is for: CTOs, security and compliance leads whose counsel has said NIS2, DORA or data protection rules apply, and who now need controls and evidence to match.

Sectors this line is set up for, not a list of clients.

Payments and fintechIND 01
DORA preparation: ICT risk registers, incident procedures and third party records.
Companies facing European regulation
NIS2 gap registers that map each requirement to a control and its evidence.
B2B softwareIND 02
Answers and evidence for customer security questionnaires, kept current.
Professional servicesIND 03
A record of where client data lives and who can reach it.

Shape of the work

REQUIREMENTCONTROLEVIDENCESTATUSRequirement AMetRequirement BPartialRequirement CGapRequirement DMet
Control register: rows of requirements, each mapped to a control, an owner, evidence and a status of met, partial or gap.

What you get

  • 28.1 · NIS2 and DORA readinessControl gap register: every requirement, the control that meets it or the gap where none does, the evidence and an owner.
  • 28.2 · Data protection contourRecords of processing, a data flow map, a subprocessor list, and retention and deletion rules implemented in the systems.
  • 28.3 · Secure deliveryA pipeline with security checks, a secrets store in use, a production access list and a deployment audit trail.

What we work with

Data
PostgreSQL · pgvector · Supabase · Redis · dbt · BigQuery
Cloud and delivery
Vercel · Cloudflare · AWS · Google Cloud · Docker · Terraform · GitHub Actions
Quality and observability
Playwright · Sentry · uptime monitoring · structured logging · error budgets
Security and access
SSO and SAML · secret managers · dependency scanning · SBOM · least privilege reviews

These are the tools we work with, not partnerships, certifications or resale agreements.

How this fits the other lines

When this is not the right line

If you need a certificate, an audit opinion or legal advice, you need an accredited auditor or a lawyer: our work is preparation only. If you need a penetration test with a formal report, hire a specialist testing firm.

Questions about this line

What evidence do we receive at the end?
A control register that links each requirement to the document, configuration or log that shows it is met, with an owner and a date on every row. Gaps stay on the register with their owners until they are closed.
Can you tell us whether NIS2 or DORA applies to our company?
We can show you the criteria in the text and how your company appears to sit against them, but whether a law applies to you is a legal question for your counsel. We start the technical work once that answer is settled, or alongside it if you choose.
Will this work get us certified?
We are not a certification body and cannot certify anyone. The work prepares the controls and evidence an auditor will ask for, so that an audit tests what already exists rather than what is promised.
Do you write our privacy policy and contracts?
No. Legal documents belong to your lawyers. We provide the technical facts they need, such as what data is held, where it flows and who processes it, so that what the documents say matches what the systems do.

Name the framework your counsel raised

Tell us which framework your counsel says applies and what evidence you hold today. We reply with how we would build the register.

Name the framework

An email exchange first, no call needed.