Compliance & audit readiness

Prove your controls work — continuously, not once a year

Guardian's compliance practice maps your existing security controls to every framework you are held to, closes the gaps that matter, and replaces the annual evidence scramble with monitoring that produces auditor-grade proof on demand.

14 Frameworks supported with a maintained control mapping
78% Of evidence collected automatically once monitoring is live
-64% Median reduction in hours spent preparing for an external audit
0 Qualified opinions across 210 supported SOC 2 Type II audits

Guardian does not act as your auditor. We prepare, map and monitor; an independent assessor of your choosing issues the opinion.

Why programmes stall

You are not running six programmes. You are running one, badly labelled six times.

Most organisations discover, somewhere around their third framework, that they are answering the same question repeatedly in slightly different vocabulary. Access review, change management, logging, encryption, vendor oversight and incident response account for the large majority of every framework's demands — but each is evidenced separately, by a different team, on a different cadence.

Guardian collapses that duplication. We build a single control library for your organisation, map each control to every framework clause it satisfies, and attach an evidence source to each one. From that point a new framework is a mapping exercise measured in weeks, not a programme measured in quarters.

  • One control, many obligations. A typical enterprise library of 180 controls satisfies more than 1,400 individual framework requirements.
  • One evidence source per control. Collected once, presented in whichever format the assessor expects.
  • One owner per control. Named, with a review date, so nothing drifts silently between audits.
ISO/IEC 27001 93 Annex A controls SOC 2 64 trust criteria points PCI DSS 4.0 277 sub-requirements HIPAA 54 safeguards GDPR Art. 5, 25, 32–34 NIS2 Art. 21 measures 180 controls one library, one owner each 1,412 requirements satisfied Representative mid-size enterprise mapping, 2026

Framework coverage

What we support, and what each engagement produces

Coverage means a maintained clause-by-clause mapping, a defined evidence source per control, and consultants who have taken clients through the assessment — not a logo on a slide.

Framework coverage, control mapping status and typical readiness timeline.
Framework Applies to Guardian control mapping Evidence automation Typical time to ready
ISO/IEC 27001:2022 Any organisation seeking a certified information security management system All 93 Annex A controls plus clauses 4–10 of the management system High — 81% 5–8 months to stage 1
SOC 2 Type II Service organisations reporting to customers in North America Security, availability, confidentiality, processing integrity and privacy criteria High — 86% 3 months to readiness, then a 6-month observation window
PCI DSS 4.0 Any entity storing, processing or transmitting cardholder data All 12 requirements, including the customised approach and targeted risk analyses Medium — 68% 6–10 months, driven by segmentation work
HIPAA Security Rule Covered entities and business associates handling protected health information Administrative, physical and technical safeguards with risk analysis documentation Medium — 72% 3–6 months
GDPR Processing of personal data of individuals in the EU and UK Articles 5, 25, 30, 32–34; records of processing and transfer impact assessments Medium — 64% 4–7 months
NIS2 Directive Essential and important entities across 18 sectors in the EU Article 21 risk management measures, Article 23 incident reporting, governance duty Medium — 70% 4–8 months
DORA EU financial entities and their critical ICT third-party providers ICT risk framework, incident classification, resilience testing, register of information Medium — 66% 6–9 months
FedRAMP Moderate / High Cloud service providers selling to United States federal agencies NIST SP 800-53 Rev. 5 baselines with continuous monitoring obligations Assisted — 54% 12–18 months

Scroll the table horizontally to see every column.

Also supported with maintained mappings: CIS Controls v8.1, NIST CSF 2.0, TISAX, CMMC Level 2, ISO 27017/27018 and the UK Cyber Essentials Plus scheme.

Multi-jurisdiction by default. Where two frameworks conflict — data residency against log retention, for instance — we document the conflict, the position taken and the legal basis, so an assessor sees a decision rather than an omission.

Scope reduction first. The cheapest control is the one you no longer need. Most PCI DSS engagements begin by shrinking the cardholder data environment; we have removed entire business units from scope with tokenisation alone.

Assessor-neutral. Guardian holds no audit practice and takes no referral fee. We work alongside whichever QSA, certification body or CPA firm you appoint, and we will happily be introduced to one you already trust.

Gap assessment

Four weeks to know exactly where you stand

Every engagement opens with a fixed-scope, fixed-fee gap assessment. It ends with a scored control register, a remediation plan sequenced by effort, and a defensible date you can give the board.

Scope and discovery

We establish which systems, data flows, business units and third parties fall inside the boundary — and, critically, which can be excluded. Interviews with control owners run alongside automated inventory collection from your cloud and identity providers.

Week 1

Control testing

Each control is tested rather than asked about. We sample access reviews, pull change records, inspect encryption configuration and read the last three incident tickets. Design and operating effectiveness are scored separately.

Weeks 2–3

Gap analysis

Findings are mapped to every applicable framework clause, so one deficiency shows its full blast radius. Each gap carries a severity, an estimated remediation effort in person-days, and a dependency chain.

Week 3

Roadmap and readout

A sequenced plan with owners, dates and quick wins separated from structural work, presented to the executive sponsor and to the engineering leads in two different sessions with two different levels of detail.

Week 4

Deliverable

The control register

A live spreadsheet and platform view of every control: identifier, statement, owner, framework mappings, test procedure, evidence location, last tested date and current status. It becomes the operating document for the programme and the first artefact your assessor asks for.

ID Control Maps to Status
AC-04 Quarterly access recertification for privileged roles ISO A.5.18 · SOC 2 CC6.2 · PCI 7.2.4 Effective
LOG-02 Centralised, tamper-evident audit logging with 400-day retention ISO A.8.15 · SOC 2 CC7.2 · PCI 10.5 · NIS2 21(2)(g) Effective
VM-07 Critical vulnerabilities remediated within 7 days on internet-facing assets ISO A.8.8 · PCI 6.3.3 · NIS2 21(2)(e) Partially effective
TPR-03 Security review before onboarding any processor handling personal data ISO A.5.19 · GDPR Art. 28 · DORA Ch. V Gap

Deliverable

The readiness scorecard

A single view of maturity per control domain, scored on design and on operating effectiveness. It is deliberately blunt: leadership sees where the programme actually is, and where the next quarter's budget will move the needle furthest.

Identity & access management 84%
Logging & monitoring 91%
Change & configuration management 67%
Vulnerability management 58%
Third-party risk 39%
Business continuity & resilience testing 72%

Illustrative scorecard from an anonymised financial services engagement at the end of week four.

Continuous compliance

Controls drift. Monitoring catches it in hours, not at the next audit.

Point-in-time compliance is a photograph of a moving object. Guardian Sentinel evaluates your control set against live configuration and telemetry continuously, raises a finding the moment a control stops operating, and files the evidence automatically when it is operating correctly.

Continuous control evaluation

Each automated control has a test that runs on a schedule — hourly for configuration checks, daily for access, weekly for process controls. Results are timestamped and immutable.

Drift alerting with ownership

A failed control raises a ticket to its named owner with the exact delta — which bucket became public, which role gained a wildcard, which host stopped shipping logs — not a generic policy violation.

Evidence collected as it happens

Screenshots, configuration exports, ticket references and approval records are captured at the moment of the test and stored against the control, with a hash chain so an assessor can verify nothing was edited later.

Audit-window reporting

Select a date range and a framework; receive the population, the sample, the evidence and the exception log in the format your assessor requested. What used to take three weeks takes an afternoon.

See the automation engine
sentinel · compliance posture · rolling 12 months
60% 70% 80% 90% 100% Public storage bucket · closed in 4 h MFA policy exception · closed in 26 h Log shipper outage · closed in 9 h M1 M4 M7 M10 M12 Controls passing continuous evaluation 96% · 173 of 180 Illustrative customer posture. Drift events are control failures detected and remediated inside the audit window.

A full engagement

What twelve months looks like

Illustrated with a SOC 2 Type II and ISO 27001 dual-track programme for a 900-person software company — the most common shape of work we do.

Dual track 900 employees 3 cloud accounts 140 vendors
Read the full case study
Month 0

Kickoff and scope lock

Boundary agreed, systems inventoried, control owners named and the assessor selected. We insist on naming owners before any remediation begins — unowned controls are the single strongest predictor of a programme slipping.

Months 1–2

Gap assessment and roadmap

Control register built, 180 controls tested, 47 gaps identified. Roadmap splits into nine quick wins deliverable inside a fortnight and four structural projects requiring engineering capacity.

Months 2–5

Remediation and policy build

Policies written to match what the organisation actually does, not aspirational templates. Access recertification automated, log retention extended to 400 days, vendor review workflow implemented, encryption gaps closed on two legacy stores.

Month 5

Continuous monitoring goes live

140 of 180 controls move to automated evaluation in Guardian Sentinel. Evidence begins accumulating from this date, which is what makes the observation window survivable.

Months 6–7

Internal audit and readiness review

We run the audit before the auditor does, using the assessor's own test procedures. Findings are fixed while there is still time, and management responses are drafted for anything that will remain open.

Months 7–12

Observation window and assessment

SOC 2 Type II observation runs while the ISO 27001 stage 1 and stage 2 audits take place. Guardian sits in every assessor session, produces evidence on request and manages the exception log. Report issued in month twelve.

Ongoing

Surveillance and the next framework

Quarterly control review, annual policy refresh and surveillance audit support. The same library then carried this customer into NIS2 readiness in eleven weeks, because 78% of the required measures were already mapped and evidenced.

Our first SOC 2 consumed two engineers for four months and we still scrambled for evidence in the final fortnight. With the control library and continuous monitoring in place, this year's ISO 27001 certification cost us eleven days of internal effort in total. The auditor asked for a sample and we exported it while she was still on the call.

Sofia Reyes

VP Risk & Compliance, Arcline Software

11 days Total internal effort for the ISO 27001 certification audit
140/180 Controls evaluated automatically, no human collection required

See how compliance work pairs with penetration testing for requirement 11.4 evidence, or with managed detection and response for continuous monitoring obligations.

Frequently asked

Practical questions about the engagement

Can Guardian certify us?

No, and that is deliberate. Certification bodies, QSAs and CPA firms must be independent of the party that built the controls. Guardian prepares you, maps your controls, remediates the gaps and manages the evidence; an assessor of your choosing issues the certificate or opinion. We work regularly with all the major bodies and can make introductions if you do not already have one.

We already have a GRC tool. Does this replace it?

Usually not. Most GRC platforms are good at holding a control register and poor at proving controls are operating. Guardian integrates with the major GRC vendors and pushes continuous evaluation results and evidence into the register you already maintain. If you have no tool, the control register and evidence store are included in the engagement at no additional cost.

How do you handle evidence for controls that are not technical?

Roughly a fifth of any framework concerns process and governance — board oversight, training completion, supplier review, disciplinary procedure. These cannot be scraped from an API, so we instrument them instead: workflow steps in your existing systems that produce a dated, attributable record as a by-product of doing the work. Evidence you have to remember to create is evidence you will not have.

Does continuous monitoring require Guardian Sentinel?

The automated evaluation engine runs on the Guardian Sentinel platform, so yes for the automated portion. The advisory work — gap assessment, control library, remediation, audit support — is entirely platform-independent and a significant share of clients take it alone. We will tell you honestly which controls we can automate against your existing stack before you commit.

What happens if the auditor raises a finding anyway?

We stay in the room. Guardian drafts the management response, agrees a corrective action plan with the assessor, and does the remediation work under the original engagement where it falls inside scope. Across 210 supported SOC 2 Type II audits we have not had a qualified opinion, but exceptions do occur and the plan for handling them is written before the audit starts, not after.

How is the work priced?

The gap assessment is fixed fee and fixed scope. Remediation and audit support are quoted as a programme with a defined deliverable set, not a day rate you cannot forecast. Continuous compliance monitoring is licensed per evaluated control per year and is included in the Enterprise platform tier. See pricing for the platform, or contact us for a programme quotation.

Stop rebuilding the same evidence every year

Start with a four-week gap assessment. You will end it with a scored control register, a sequenced plan and a date you can defend to the board.