ISO 27001, SOC 2 & PCI DSS Readiness
Understand applicable requirements, evaluate existing controls and prepare your security program for the next stage of compliance readiness.
Frameworks are easier to satisfy when you know which parts apply to you. A great deal of effort gets spent on requirements that were never in scope, while the ones that genuinely matter are discovered late — usually by someone external.
Readiness work is about closing that distance beforehand: establishing what applies, mapping it to what you already do, and being honest about the difference. Most organizations have more controls in place than they can demonstrate; the gap is often evidence rather than practice.
What is ISO 27001, SOC 2 and PCI DSS readiness?
This covers readiness work for three distinct compliance frameworks. ISO 27001 is an information security management system standard focused on governance, risk treatment and a managed set of controls reviewed over time. SOC 2 is a reporting framework built around trust services criteria, evidencing that controls operated consistently over a period, usually for customer assurance. PCI DSS is a requirements standard for environments handling payment card data, focused on segmentation, protection of cardholder data and tightly specified technical controls. In practice, most of the readiness work is evidence, not controls: teams are often already doing much of what a framework expects, but cannot yet show it in a record they could hand over.
Who needs it? Organizations where a customer contract now requires a specific framework as a condition of signing, organizations entering a regulated market where security expectations are set externally, organizations preparing for a scheduled external assessment, and organizations whose security programme grew without structure, where controls exist in practice but were never mapped.
How TMG Security helps. TMG Security identifies which of the activity you are already doing counts as evidence for the selected framework and turns that into a record you can hand to an assessor or customer, covering scope definition, risk methodology and control mapping through to internal review, and delivers output leadership can act on.
Most of the work is evidence, not controls
Teams usually discover that they are doing much of what a framework expects — access is reviewed, changes are approved, backups are tested. What they cannot do is show it. The activity happens in conversations and tickets rather than in a record anybody could hand over.
That distinction matters, because it changes what the work is. Building a missing control is a project. Demonstrating an existing one is usually a process change, and it is where readiness effort pays back fastest.
How this is put together.
Three layers. A programme fails at whichever one is weakest — and it is rarely the first.
What applies to you
What you actually do
What you can show
What each one is actually for.
Select a framework to see its focus and the considerations it usually raises.
Not every framework applies to every organization. Which are relevant depends on your sector, your customers and where you operate.
ISO 27001 vs. SOC 2 vs. PCI DSS
These three frameworks answer different questions and are not interchangeable. ISO 27001 asks whether you are running a managed information security programme: it certifies a management system, not a point-in-time control set, and is usually chosen when an organization wants a recognised, ongoing security governance structure. SOC 2 asks whether your controls actually operated as described over a period of time: it produces a report for customer assurance rather than a certification, and is usually chosen when enterprise buyers are asking for evidence rather than a badge. PCI DSS is not a choice in the same sense, it is a requirement for any organization that stores, processes or transmits payment card data, with tightly specified technical controls around segmentation and cardholder data protection.
In practice, organizations often need more than one: a SaaS company selling to enterprises frequently pursues SOC 2 for customer assurance while working toward ISO 27001 for its broader security programme, and any organization handling card payments needs PCI DSS regardless of what else it pursues. Which combination applies depends on your sector, your customers and where you operate. For a closer, side-by-side look at how these three frameworks compare, see TMG's ISO 27001 vs SOC 2 vs PCI DSS Comparison Guide.
What readiness work covers
SCOPE OF SERVICEReadiness and gap assessment support. TMG Security is not a certification body or auditor and does not issue certifications or audit opinions.
How readiness work runs
- 01SCOPEEstablish what is in scope and which requirements genuinely apply.
- 02MAPConnect requirements to controls that already exist.
- 03ASSESSTest whether those controls operate, and whether that can be shown.
- 04PRIORITISERank gaps by risk and by what blocks other work.
- 05REMEDIATESupport the changes, including documentation and evidence.
- 06REVIEWConfirm the gaps closed and stayed closed.
When Does Framework Readiness Become Urgent?
Output leadership can act on.
Which of these apply depends on engagement scope.
Where current practice differs from the requirements that apply to you.
Which controls address which requirements, and where nothing does.
What the gaps mean in terms of risk, not just non-conformity.
What needs to exist in writing, and what it needs to say.
Whether you could demonstrate a control operates, if asked.
Sequenced work, with dependencies made explicit.
A version of the findings that a board or exec team can act on.
Adjacent parts of the programme.
How pricing and scope are determined
There is no published fixed price for framework readiness work. Each engagement is scoped and priced individually based on factors such as which framework or frameworks are being pursued, the size and complexity of the organization, and how much of the required evidence already exists versus needs to be built. These factors are discussed during scoping before a quote is provided.
Questions we get asked before an engagement.
No. Certification and audit opinions come from an accredited certification body or a qualified auditor. We prepare you for that process — establishing what applies, closing gaps and getting evidence in order — but the assessment itself sits with an independent party.
Usually whichever one a customer or market is asking for. Where there is a genuine choice, the deciding factors are what your buyers recognise and how much structure your programme already has. Starting with two at once rarely goes well.
It depends on the starting position and the framework, and we would rather scope that after looking than quote a number here. The pattern is that documentation and evidence take longer than people expect, and technical controls less.
Policies are necessary and rarely sufficient. The common finding is a policy that describes something the organization does not actually do, which is worse than not having it — an assessor will test the claim.
Discuss Framework Readiness
Tell us which framework is being asked for and who is asking. That usually determines both the scope and the deadline.
