Home / Consulting / Compliance readiness assessment

Consulting · a bounded assessment

Find the gaps before the assessor does.

Name the standard and the date. We assess you against it, tell you what is missing and what your evidence will not survive, and leave you a prioritised list with owners against it. A gap assessment, or a pre-audit if the date is close.

When this is the right one

There is a standard, and there is a date.

  • A certification or attestation is due and nobody knows how close you are
  • A customer contract now names a standard you have never been assessed against
  • The last audit produced findings that have not been closed
  • Controls are described in policy but the evidence for them is thin
  • You need to know the cost of readiness before committing to the date

Most readiness work goes wrong in the same place. The control is genuinely operating, and the evidence that it operated cannot be produced — so a real control fails an assessment on documentation.

Assessing against the standard early separates the two, while there is still time to fix either one.

Standards we assess against

The one you have to meet, not the one we prefer.

PCI DSS

Cardholder data environment scoping first, because an unscoped assessment prices the wrong thing.

ISO 27001

Statement of Applicability, control operation and the evidence trail behind both.

NIST CSF

Profile-based, so the target is a decision you make rather than every subcategory at once.

Another standard

Sector obligations, a customer’s own framework, or an internal control set. Say which.

Named outputs

What comes back.

Scope definition

What is in and what is out, written down before anything is assessed against it.

Gap register

Requirement by requirement: met, partly met or not met, and what the finding rests on.

Evidence review

Whether what you hold would satisfy a third-party assessor, judged as they would judge it.

Prioritised remediation

Sequenced by what blocks the date, with an owner and an estimate against each item.

Readiness position

A plain answer on whether the date is realistic, given early enough to move it.

An accepted decision

The engagement closes on what you decide to do, not on delivery of a report.

Scope is set by the standard, the environment it applies to and whether you want a gap assessment or a full pre-audit. All three are agreed before the work starts and carry a fixed price.

For your reviewers

Where this assessment stops

What it is not

  • Not certification. We are not a certification body and this assessment does not certify you.
  • Not a QSA assessment or a Report on Compliance. For PCI DSS this is readiness work before one.
  • Not an independent audit opinion — we are not independent of remediation we help design.
  • Not a guarantee of the outcome. We assess honestly; the assessor still forms their own view.

Fields marked are required. Everything else helps us prepare and can be left blank.

PCI DSS, ISO 27001, NIST CSF, or whichever one you have been asked to meet.

An audit, a certification window or a contract deadline. It decides gap assessment or pre-audit.

The environment, systems or entity in scope. A rough boundary is fine — settling it properly is part of the work.

Never assessed, previously certified, or assessed with findings still open. Past reports save time.

The person accountable for the outcome, and the person who will do the remediation.

A month is fine. It lets us check we can actually start when you want to.

We reply within two business days. The call settles the scope and the standard, and says plainly if the date is not achievable.

If you need the certification audit itself, that is a certification body and not us — we will say so on the call and tell you what to ask them for.

Prefer to start smaller? Take the two-minute Workflow Failure Check  ·  Or just call (02) 8213 9000.