Independent assessments against payment-industry, financial, privacy and EU cybersecurity requirements: from scope and gap analysis to readiness for formal certification or attestation.
Compliance audit against PCI DSS for organisations that store, process or transmit payment card data. Assessment of infrastructure, processes and security controls, with preparation for formal validation of compliance.
Security assessment of PIN processing, cryptographic keys and payment infrastructure against the PCI PIN Security requirements.
Security audit of 3-D Secure components and infrastructure, including access control, cryptography, network security, monitoring and vulnerability management.
Readiness assessment for SOC 2 against the Security, Availability, Confidentiality, Processing Integrity and Privacy criteria, including control analysis and preparation for independent attestation.
Comprehensive GDPR compliance assessment: personal data processing, ROPA, DPIA, data subject rights, third-party management, international transfers and information protection.
Independent assessment against the SWIFT Customer Security Controls Framework (CSCF), including protection of SWIFT infrastructure, access management, monitoring and incident response.
HIPAA compliance assessment for organisations handling medical and personal information, covering administrative, technical and physical safeguards for PHI/ePHI.
Assessment against the Digital Operational Resilience Act: ICT risk management, incident management, business continuity, resilience testing and ICT third-party risk.
Assessment against NIS2 for cybersecurity governance, risk management, incident response, business continuity, supply-chain security, access control and protection of information systems.
Systems, sites, data flows and the applicable framework defined; fixed offer issued.
Controls, processes and evidence checked against the requirements; findings prioritised.
Action plan and guidance while you close the gaps; evidence prepared.
Independent assessment, report or readiness for certification and attestation.
Tell us which framework you need and how your systems are organised: we define the scope and the assessment type.