ISO 27001, SOC 2 & PCI DSS Readiness
Understand applicable requirements, evaluate existing controls and prepare your security program for the next stage of compliance readiness.
Frameworks are easier to satisfy when you know which parts apply to you. A great deal of effort gets spent on requirements that were never in scope, while the ones that genuinely matter are discovered late — usually by someone external.
Readiness work is about closing that distance beforehand: establishing what applies, mapping it to what you already do, and being honest about the difference. Most organizations have more controls in place than they can demonstrate; the gap is often evidence rather than practice.
Most of the work is evidence, not controls
Teams usually discover that they are doing much of what a framework expects — access is reviewed, changes are approved, backups are tested. What they cannot do is show it. The activity happens in conversations and tickets rather than in a record anybody could hand over.
That distinction matters, because it changes what the work is. Building a missing control is a project. Demonstrating an existing one is usually a process change, and it is where readiness effort pays back fastest.
How this is put together.
Three layers. A programme fails at whichever one is weakest — and it is rarely the first.
What applies to you
What you actually do
What you can show
What each one is actually for.
Select a framework to see its focus and the considerations it usually raises.
Not every framework applies to every organization. Which are relevant depends on your sector, your customers and where you operate.
What readiness work covers
SCOPE OF SERVICEReadiness and gap assessment support. TMG Security is not a certification body or auditor and does not issue certifications or audit opinions.
How readiness work runs
- 01SCOPEEstablish what is in scope and which requirements genuinely apply.
- 02MAPConnect requirements to controls that already exist.
- 03ASSESSTest whether those controls operate, and whether that can be shown.
- 04PRIORITISERank gaps by risk and by what blocks other work.
- 05REMEDIATESupport the changes, including documentation and evidence.
- 06REVIEWConfirm the gaps closed and stayed closed.
When Does Framework Readiness Become Urgent?
Output leadership can act on.
Which of these apply depends on engagement scope.
Where current practice differs from the requirements that apply to you.
Which controls address which requirements, and where nothing does.
What the gaps mean in terms of risk, not just non-conformity.
What needs to exist in writing, and what it needs to say.
Whether you could demonstrate a control operates, if asked.
Sequenced work, with dependencies made explicit.
A version of the findings that a board or exec team can act on.
Adjacent parts of the programme.
Questions we get asked before an engagement.
No. Certification and audit opinions come from an accredited certification body or a qualified auditor. We prepare you for that process — establishing what applies, closing gaps and getting evidence in order — but the assessment itself sits with an independent party.
Usually whichever one a customer or market is asking for. Where there is a genuine choice, the deciding factors are what your buyers recognise and how much structure your programme already has. Starting with two at once rarely goes well.
It depends on the starting position and the framework, and we would rather scope that after looking than quote a number here. The pattern is that documentation and evidence take longer than people expect, and technical controls less.
Policies are necessary and rarely sufficient. The common finding is a policy that describes something the organization does not actually do, which is worse than not having it — an assessor will test the claim.
Discuss Framework Readiness
Tell us which framework is being asked for and who is asking. That usually determines both the scope and the deadline.
