Cyber security & compliance consultancy

Achieve and maintain compliance with confidence.

Expert-led consultancy across ISO 27001, SOC 2, NIST, PCI DSS, NIS2 and DORA. We assess where you stand, build the programme with your team, and stay with you through certification and beyond.

  • Fixed-scope engagements
  • Practitioner-led
  • Independent of certification bodies
  • 50+Clients protected
  • 22Professional certifications
  • 11Frameworks covered
Certified expertise
  • CISSP
  • CISA
  • ISO 27001 Lead Auditor
  • CISMP
  • CompTIA CySA+
  • CompTIA Security+
  • +16 more
Our services

Four ways we help, depending on where you are.

All services
Sectors

Deep experience in regulated and high-assurance sectors.

Financial services

DORA, PCI DSS and regulator expectations for operational resilience.

Defence & government supply chain

CMMC, NIST 800-171, Cyber Essentials Plus and security-cleared delivery.

Technology & SaaS

ISO 27001 and SOC 2 to unblock enterprise procurement.

Critical infrastructure & energy

NIS2 obligations, OT-aware risk assessment and incident readiness.

Healthcare & life sciences

Data protection, ISO 27001 and supplier assurance for sensitive data.

Legal & professional services

Client-driven certification and confidentiality controls.

Manufacturing

Supply chain security requirements from customers and insurers.

Public sector

Cyber Essentials, NCSC CAF alignment and framework-based assurance.

Why Forged Compliance

Compliance that holds up after the certificate is issued.

Most programmes are built to pass one audit. Ours are built so your own team can run them, evidence them, and pass the next one without us.

  1. Practitioner-ledLed by CISSP, CISA and ISO 27001 Lead Auditor certified practitioners who have implemented and audited the standards we advise on.
  2. Fixed scope, fixed priceDeliverables, timeline and price agreed in writing before work starts.
  3. IndependentWe prepare you for certification and support you through it; we do not certify, resell or refer for commission.
  4. Documentation written in-houseComplete policy, standard and procedure sets, maintained to current framework editions.

A typical certification engagement

Around sixteen to twenty weeks from first call to Stage 2, depending on what already exists.

Weeks 1–3Gap assessment and roadmap
Weeks 4–14Build: risk, controls, documentation, evidence
Weeks 15–17Internal audit and management review
Weeks 18–20Stage 1 and Stage 2 support

Speak to a consultant

A 30-minute scoping call to understand your obligations, timeline and options. No obligation.