About

We got tired of watching good companies get burned by cut-price compliance shops.

Experts in Compliance was built around one idea: audit preparation should be done by people who have actually held the pen during a real ISO 27001 certification audit or SOC 2 examination, not resold to the lowest-cost subcontractor once the contract is signed.

Who we are

We're a team of GRC consultants, former ISMS managers and security engineers working across the UK, the US and the EU. Between us we've taken organisations through first-time ISO 27001 certification, run SOC 2 Type I and Type II programmes from scratch, and delivered hundreds of penetration tests for companies that needed a clean report before a deal could close.

We work with SaaS companies, fintechs, healthtechs and B2B software vendors, typically teams selling to enterprise or regulated customers for the first time, where "we're SOC 2 compliant" or "we're ISO 27001 certified" has gone from nice-to-have to deal-breaker.

How we work

No engagement is quietly handed off to a subcontractor once you've signed. The consultant on your kickoff call is the consultant who reviews your evidence, assesses your policies, and sits in your internal audit closing meeting. That continuity is why our clients stay with us year over year.

We keep language plain. You'll get a prioritised remediation list, not a 200-page PDF designed to justify an invoice. If a control doesn't apply to your business, we'll say so. An ISMS built from a generic template is one of the fastest ways to fail an audit.

Where our consultants are based

UK. US. EU. That's the list.

Every consultant, auditor and pentester who touches your engagement is based in the United Kingdom, the United States or the European Union. We don't operate an offshore delivery centre and we don't subcontract client work to reduce cost the way a number of budget ISO 27001 and SOC 2 providers in this market do. It's slower to scale that way. We think it's the right trade-off when the work involves your customers' security posture and your own audit evidence.

Independence statement

We can get you ready for the audit. We can't be the ones who grade it.

It's a fair question to ask a compliance firm, so here's the plain answer: we help you prepare, and someone else does the certifying. We don't issue ISO 27001 certificates, and we don't sign SOC 2 reports.

That's not us being modest about what we do. The rules simply don't allow it, and for a sensible reason. If the same firm builds your controls and then marks its own work, the certificate stops meaning very much. ISO/IEC 17021-1, the standard that accredited certification bodies work under, stops them certifying a management system they also consulted on. The AICPA's independence rules do the equivalent for SOC 2, requiring the CPA firm signing your report to be independent of whoever designed the controls. You'd want it that way if you were the customer reading the report.

Some firms in this market are vague about where that line falls. We'd rather just show you:

If you're ever unsure whether something you're proposing crosses that line, ask us. We'd rather have the conversation upfront than have it come up at your Stage 2 audit.