Skip to content
INLD LimitedCybersecurity Consulting

Service

Compliance Advisory

ISO/IEC 27001 readiness, SOC 2 gap analysis and regulatory support for GDPR, DORA and MiCA. Advisory work is separated from assessment work so independence is preserved.

Compliance advisory at INLD is about closing the distance between how an organisation actually operates and what a framework requires it to evidence. We run readiness assessments against ISO/IEC 27001:2022 Annex A controls and the SOC 2 Trust Services Criteria, identify which requirements are met in practice but undocumented, which are documented but not performed, and which are genuinely absent. For regulated firms we map security obligations arising from GDPR, DORA and MiCA onto existing controls so the same evidence serves more than one obligation. We do not issue certifications and we are not a certification body; our role is to prepare an organisation so that an accredited auditor finds what they expect to find.

What the engagement covers

Compliance advisory work closes the distance between how an organisation operates and what a framework requires it to evidence. A readiness assessment establishes, control by control, which requirements are met in practice and documented, which are met in practice but undocumented, which are documented but not performed, and which are absent. Those four categories need entirely different responses, and conflating them is the most common reason a first external audit goes badly.

We state plainly what INLD is not: we are not a certification body, we do not issue certificates, and we hold no accreditation that would allow us to do so. Our role is preparatory. An accredited auditor decides whether a management system conforms; our work is to make sure that when they look, they find what they expect.

ISO/IEC 27001:2022 readiness

Readiness work covers both the management system clauses and the Annex A controls. Clause work looks at scope definition, risk assessment methodology and its consistent application, the statement of applicability, objectives and measurement, internal audit, and management review. Control work walks Annex A in its 2022 structure — organisational, people, physical and technological — and records the evidence that exists today for each applicable control.

The 2022 revision introduced controls that mature technology organisations often perform without recognising them as controls: threat intelligence, information security for cloud services, ICT readiness for business continuity, configuration management, data masking, web filtering and secure coding. A significant part of a readiness engagement is identifying existing practice that already satisfies a control and simply needs to be evidenced, which reduces remediation cost substantially.

SOC 2 gap analysis

For organisations pursuing SOC 2, we assess against the Trust Services Criteria in scope — security always, with availability, confidentiality, processing integrity and privacy added where the client's commitments require them. The analysis focuses on whether each control operates consistently and produces an artefact that can be sampled over a period, since a Type II report tests operating effectiveness across time rather than design at a point. Controls that work but leave no evidence trail are treated as gaps, because for audit purposes they are.

GDPR, DORA and MiCA

For GDPR we review the technical and organisational measures required by Article 32, the handling of personal data across environments including non-production, retention and deletion in practice, processor arrangements, international transfer safeguards, and the breach detection and notification path with its 72-hour obligation.

For firms in scope of DORA, we review ICT risk management framework documentation, incident classification and reporting readiness, digital operational resilience testing arrangements, and third-party ICT risk registers including concentration exposure. For digital asset firms in scope of MiCA, we review the operational resilience and custody safeguarding requirements and how they interact with existing security controls.

Where the same organisation carries several of these obligations, we build a consolidated control map showing where one implemented control satisfies requirements under multiple regimes. Most firms discover they have fewer genuine gaps than the sum of their framework checklists suggests, and a single well-evidenced control frequently answers three separate questions.

Independence

Advisory work and technical assessment work are kept separate on our side. Where INLD has provided remediation advice on a control, we say so in any subsequent assessment report covering that control, so a reader can judge the independence of the conclusion for themselves. We do not resell tooling and we take no referral commission from any vendor, certification body or licensing intermediary.

Output

The engagement produces a readiness report with control-by-control status, a gap register with owner, effort estimate and priority for each item, a consolidated control map where multiple regimes apply, and a remediation plan sequenced against the target audit date. A follow-up review before the audit window confirms which gaps have closed.

Start with a scoping conversation

Tell us about your environment, regulatory context and timelines. We will tell you what an assessment would realistically involve, before any commitment.