Home / Consulting / Compliance readiness assessment
Consulting · a bounded assessment
Find the gaps before the assessor does.
Name the standard and the date. We assess you against it, tell you what is missing and what your evidence will not survive, and leave you a prioritised list with owners against it. A gap assessment, or a pre-audit if the date is close.
When this is the right one
There is a standard, and there is a date.
- A certification or attestation is due and nobody knows how close you are
- A customer contract now names a standard you have never been assessed against
- The last audit produced findings that have not been closed
- Controls are described in policy but the evidence for them is thin
- You need to know the cost of readiness before committing to the date
Most readiness work goes wrong in the same place. The control is genuinely operating, and the evidence that it operated cannot be produced — so a real control fails an assessment on documentation.
Assessing against the standard early separates the two, while there is still time to fix either one.
Standards we assess against
The one you have to meet, not the one we prefer.
PCI DSS
Cardholder data environment scoping first, because an unscoped assessment prices the wrong thing.
ISO 27001
Statement of Applicability, control operation and the evidence trail behind both.
NIST CSF
Profile-based, so the target is a decision you make rather than every subcategory at once.
Another standard
Sector obligations, a customer’s own framework, or an internal control set. Say which.
Named outputs
What comes back.
Scope definition
What is in and what is out, written down before anything is assessed against it.
Gap register
Requirement by requirement: met, partly met or not met, and what the finding rests on.
Evidence review
Whether what you hold would satisfy a third-party assessor, judged as they would judge it.
Prioritised remediation
Sequenced by what blocks the date, with an owner and an estimate against each item.
Readiness position
A plain answer on whether the date is realistic, given early enough to move it.
An accepted decision
The engagement closes on what you decide to do, not on delivery of a report.
Scope is set by the standard, the environment it applies to and whether you want a gap assessment or a full pre-audit. All three are agreed before the work starts and carry a fixed price.
For your reviewers
Where this assessment stops
What it is not
- Not certification. We are not a certification body and this assessment does not certify you.
- Not a QSA assessment or a Report on Compliance. For PCI DSS this is readiness work before one.
- Not an independent audit opinion — we are not independent of remediation we help design.
- Not a guarantee of the outcome. We assess honestly; the assessor still forms their own view.
Prefer to start smaller? Take the two-minute Workflow Failure Check · Or just call (02) 8213 9000.