Compliance Packs & Audit Readiness
Policies, procedures, SOPs and assessor evidence, generated around your actual estate rather than bought as templates.
Checked 4 October 2026. Built from the full service page.
In short: The IT and security documents an assessor asks for, generated around your actual estate rather than bought as templates, plus the evidence that they are being followed. For the IT lead who has been handed a framework and a date. Start with the evidence rather than the documents, because that is where most estates actually fail.
Who this is for
The problem
Compliance work stalls in the gap between a generic template and a document that describes how your estate actually runs. Policies go stale, evidence is scattered across inboxes and ticket histories, and the first time anyone checks whether it hangs together is the week of the audit, or the day a prospect sends a 200-question security questionnaire to whoever answers those.
What we would do
If a customer, insurer or tender has asked for evidence and you are assembling it retrospectively, start with the artefacts rather than the policies. The recurring failure is not missing documents, it is documents nobody can evidence being followed.
- If you are pursuing ISO 27001 specifically, the Statement of Applicability comes early and shapes everything after it, so scope that before writing anything.
- If the deadline is short and the requirement is Cyber Essentials rather than a full framework, do the certification alone and leave the wider pack for later.
When we are not the answer: If you want a set of policy documents to file and never look at again, buy a template pack from anyone. It will be cheaper than us and equally effective at that job. We are only worth paying for if you intend the controls to be real.
What is included
- IT and security policies, procedures and SOPs written around your estate, not bought as templates
- Compliance packs mapped to your framework: Cyber Essentials, ISO 27001, SOC 2, DSP Toolkit and more
- Internal audits and self-assessments you can run yourself, on demand
- Gap analysis with a prioritised, plain-English list of what to fix first
- Audit-ready evidence packs for assessors and customer security questionnaires
- Living documents that stay current as your systems and controls change
- A clear split of what IT owns and what the wider business owns, agreed up front
- Delivered with EtherAssist and backed by our security team's hands-on remediation
What the last 12 months looked like
What it costs
Scoped and quoted against your estate rather than sold from a rate card. We price what you already run, including the parts that are working and do not need replacing, and the quote itemises what is included so it can be compared line by line with anyone else’s. Managed IT support starts at £40 per user, per month if that is the wider question.
Three questions people ask
What is the difference between Cyber Essentials and ISO 27001, and do we need both?
They answer different questions, which is why plenty of businesses end up holding both.
Will a compliance pack get us through an ISO 27001 audit on its own?
No, and anyone telling you otherwise is selling you documentation rather than certification.
How is this different from buying an off-the-shelf compliance template pack?
Templates give you a generic starting point you still have to rewrite to match your business, your systems and the framework you're being assessed against.
Tell us what you need
A short call to talk through how your IT works today, what your team handles, and what you need from a provider. We will tell you plainly how we would approach it.
Prefer to talk now? Call us on +44 (0)1482 770583.
