Services

Five services, one way of working

Every engagement has a written scope, named deliverables and a fixed fee agreed before we start. Pick the one that matches your situation, or book a scoping call and we will tell you which applies.

01

ISO 27001 implementation and certification readiness

We build your information security management system (ISMS) from where you are today to a passed Stage 2 audit. The scope, the deliverables and the fee are agreed before work begins, and we stay with you until the certificate is issued.

For: Software and IT services companies whose overseas clients ask for an ISO 27001 certificate in security questionnaires or tenders.

Scope, deliverables and timeline
03

Personal Data Protection Act readiness

Sri Lanka’s Personal Data Protection Act No. 9 of 2022 brings its core obligations for controllers and processors into force on 1 January 2027. We assess where you stand, build the records, notices and procedures the Act requires, and align the work with ISO 27001 and ISO 27701 so the same evidence serves both.

For: Any Sri Lankan organisation that processes personal data of customers, employees or users.

Scope, deliverables and timeline
04

Business continuity and ISO 22301

Business impact analysis, continuity and recovery plans, and exercises that show the plans work when something goes wrong. Structured as a management system and taken to certification if ISO 22301 is a requirement for you.

For: Companies whose clients or regulators ask for a tested business continuity plan.

Scope, deliverables and timeline
05

ISO 9001 quality management

For companies that want a quality management system alongside their security programme, or need the ISO 9001 certificate for tenders. We can build it as part of one integrated management system so quality, security and continuity share the same audits and reviews.

For: Software and services companies asked for ISO 9001 in tenders and vendor onboarding.

Scope, deliverables and timeline

Which standard do you actually need?

The honest short version. We will confirm it against your contracts and regulator during scoping.

If this is your situationStart here
Overseas clients ask for a certificate in security questionnaires or RFPsISO 27001, and SOC 2 if your clients are mostly in the United States
You supply systems or services to a licensed bankISO 27001 (accredited certificate), plus ISO 22301 if you host critical infrastructure
You are a licensed finance company or insurerISO 27001 as the evidence framework for your regulator, with internal audit and maintenance to keep it current
You hold personal data of customers, patients or employeesPDPA readiness, aligned with ISO 27001 if you are certifying anyway
You already hold ISO 27001Internal audit and surveillance support, or the 2022 transition if your certificate is still on the 2013 edition
Tenders ask for ISO 9001ISO 9001, ideally as one integrated system with ISO 27001

Not sure where you stand? Start with a scoping call.

Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.