Anyone holding personal data
Core PDPA obligations commence: security measures, records, DPO, breach notification.
From gap assessment to a passed Stage 2 audit, with one named consultant throughout. For Sri Lankan companies of 20 to 300 people.
Standards and rules we work with
From current state to a passed certification audit, with a fixed scope agreed before we start.
Independent internal audits, surveillance preparation and the 2013 to 2022 transition for companies that already hold ISO 27001.
Get ready for Sri Lanka’s PDPA, whose core obligations commence on 1 January 2027, and align the work with ISO 27001 so you do it once.
Business impact analysis, continuity plans and exercises that prove the plans work. Certifiable to ISO 22301 if you need the certificate.
A quality management system alongside your security programme, or on its own when tenders require the certificate.
Core PDPA obligations commence: security measures, records, DPO, breach notification.
IRCSL requires a full-time CISO, ISO 27001-aligned incident reporting and an annual external audit.
CBSL requires accredited ISO 27001 from third parties touching bank data; a new outsourcing direction re-papers every contract.
Forty-five minutes, then a fixed-fee proposal within a week.
Where you stand against the standard, with a dated plan.
Risk assessment, policies, controls and staff training.
Internal audit, then Stage 1 and Stage 2 with your chosen body.
The price and deliverables are in writing before we start.
We do not certify, sell software or take referral fees. You choose the certification body.
The engagement finishes when the certificate is issued, not when the documents are delivered.
Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.