Managed Compliance

Certification, run for you end to end

Our consultants take you from gap assessment to certificate — writing the policies, gathering the evidence, and sitting with you in the audit — with Aqua GRC holding the control set once you are certified.

What we manage
Gap assessment Policy authoring Evidence collection Audit support
ISO 27001 readiness LIVE
IMPLEMENTED Evidenced
78 of 93 controls fully evidenced

Evidence collected automatically from cloud, identity, and endpoint systems each week.

OPEN Escalated
9 controls awaiting owner action

Supplier reviews and two access recertifications, each with a named owner and due date.

DOCUMENTED Complete
100% policy set signed and published

Policies authored, approved at management review, and acknowledged by all staff.

Stage 1 audit booked for next month, on the original timeline.

Frameworks We Take You Through

One Control Set.
Every Certificate.

Map a control once and reuse it across every framework you pursue. Your second certification costs a fraction of your first.

ISO 27001

Full ISMS build, internal audit, and Stage 1 and Stage 2 support.

Certification

SOC 2

Readiness, observation window preparation, and auditor liaison.

Type I & II

GDPR

ROPAs, DPIAs, subject request handling, and processor agreements.

Compliance programme

HIPAA

Risk analysis and safeguard implementation for protected health data.

Safeguards

PCI-DSS

Scoping, segmentation evidence, and QSA engagement support.

SAQ & RoC

NIST CSF

Current and target profile assessment with a costed roadmap.

Maturity uplift

CTDISR

Regulatory baseline delivered alongside your existing certifications.

Regional baseline

Customer Assurance

Security questionnaires and due diligence answered on your behalf.

Questionnaires
Key Features

Consultants, Evidence And Audit Support
In One Engagement.

Gap Assessment First

We assess you against the standard before quoting the work, so the plan reflects your actual starting point.

Policies Written For You

A full policy set authored around how your business actually operates, not a template pack you have to rewrite.

Evidence Collected Automatically

Aqua GRC pulls evidence from your connected systems, so control operation is proven without screenshot marathons.

Named Consultant

One consultant owns your programme end to end — and is in the room, or the call, for the audit itself.

Internal Audit & Management Review

The mandatory internal audit and management review are run for you, with findings closed before the external auditor arrives.

Surveillance & Recertification

Controls stay evidenced between audits, so surveillance visits are routine rather than a scramble.

How It Works

From Gap Assessment To Certificate

A named consultant runs the programme to a dated plan. You are not handed a spreadsheet and left to interpret the standard.

01 Assess

We scope the certification, assess you against every clause and control, and give you a dated plan with the effort split between our team and yours.

02 Build

Policies, procedures, risk assessment, and the statement of applicability are authored around your business, then implemented with your owners.

03 Evidence

Controls go live in Aqua GRC with evidence collected automatically, and we run the internal audit and management review the standard requires.

04 Certify

We prepare your team for the auditor, attend the audit, and manage any findings through to closure and certificate issue.

Framework crosswalk showing ISO 27001 controls shared with SOC 2, NIST CSF, GDPR, HIPAA and PCI DSS
Continuous Compliance

Stay Certified Between Audits

  • Controls stay evidenced continuously, so surveillance audits need no special preparation.
  • Control owners are reminded before evidence goes stale, not after a finding.
  • Adding a second framework reuses the evidence you already collect.
  • Live posture reporting for customers, insurers, and your board between audits.
Use Cases

Who Uses Managed Compliance?

First Certification Customer Requirements Multi-Framework Recertification

Managed compliance is built for teams facing certification without a compliance function — first-time ISO 27001, a customer demanding SOC 2, or a surveillance audit nobody has prepared for.

Get Started

Get Certified Without Hiring A Compliance Team

Gap assessment, policy authoring, evidence collection, internal audit, and auditor support under one engagement.