CORE PRACTICE DOMAIN • 14 ENGAGEMENTS

Compliance & Audit

Global Regulatory Readiness & Certification Audits

Hands-on gap analysis, readiness assessments, and formal accreditation guidance for ISO 27001, SOC 2, PCI DSS, and Cyber Essentials.

Available Assessments in Compliance & Audit

RawSec Assurance

ISO 27001 Certification Services in the UK

RawSecLabs delivers practical ISO 27001:2022 implementation, from initial gap analysis, through ISMS design and policy authoring, to internal audit and certification body liaison. We focus on building an ISMS your tea...

RawSec Assurance

Cyber Essentials for SaaS Companies

RawSecLabs is an IASME-licensed Certification Body for Cyber Essentials certification services with genuine cloud-native expertise. We already test AWS, GCP and Azure environments and audit SaaS platforms for SOC 2 an...

RawSec Assurance

Cyber Essentials for Law Firms & Solicitors

RawSecLabs is an IASME-licensed Certification Body for Cyber Essentials certification services with an understanding of how law firms actually run: case management systems, dictation workflows, fee earners on personal...

RawSec Assurance

Cyber Essentials Renewal & 2026 Danzell Changes

RawSecLabs is an IASME-licensed Certification Body for Cyber Essentials renewal services designed around exactly this problem. Before you resubmit, we compare your previous responses against the current requirements, ...

RawSec Assurance

Cyber Essentials for Healthcare & NHS Suppliers

RawSecLabs is an IASME-licensed Certification Body for Cyber Essentials certification services with healthcare-sector fluency. We already deliver security work for healthcare organisations, so we understand clinical s...

RawSec Assurance

SOC 2 Compliance & Audit Services

RawSecLabs delivers SOC 2 Type I and Type II audits engineered for modern technology environments, multi-tenant SaaS, AI/ML platforms, healthcare and fintech variants, MSP and cloud provider operations. We map control...

RawSec Assurance

Cyber Essentials Plus Readiness & Consultancy

RawSecLabs is an IASME-licensed Certification Body for Cyber Essentials, with Cyber Essentials Plus assessments launching soon. Until then, our security professionals deliver Plus readiness consultancy: we prepare you...

RawSec Assurance

Specialized NY 23 NYCRR 500 Services

23 NYCRR 500 sets minimum cybersecurity requirements,such as appointing a CISO, conducting risk assessments, implementing access controls, logging, and incident reporting,for any organisation under NYDFS regulation. T...

RawSec Assurance

ISO 27001 Internal Audit Services in the UK

Many organisations struggle to maintain the independence and competence of internal audits when run by their own teams, the auditor needs to be free of conflict of interest with the area audited. Outsourcing to RawSec...

RawSec Assurance

Cyber Essentials Certification Services UK

RawSecLabs is an IASME-licensed Certification Body for Cyber Essentials, with Plus assessments launching soon, backed by the same CREST-accredited security team that delivers our penetration testing, PCI DSS and ISO 2...

RawSec Assurance

Cyber Essentials for SMEs: Small Business Guide

RawSecLabs is an IASME-licensed Certification Body for Cyber Essentials certification services built for SMEs without in-house IT security. We translate the Danzell question set into plain English, tell you exactly wh...

RawSec Assurance

PCI DSS QSA Company

As a PCI SSC Qualified Security Assessor (QSA) Company, RawSecLabs delivers PCI DSS v4.0.1 services across the full programme lifecycle: scope definition, gap analysis, remediation support, Report on Compliance (ROC) ...

RawSec Assurance

Microsoft Office 365 CIS Security Services

While Office 365 ships with strong security features, most organisations fail to configure them properly, leaving critical gaps that attackers can exploit. Misconfigurations, weak authentication, and overlooked settin...

RawSec Assurance

PCI ASV Scanning Services

RawSecLabs, a PCI SSC QSA Company, delivers quarterly ASV scans in partnership with an SSC-Approved Scanning Vendor: scheduled scans, rapid re-scans after remediation, and the formal attestation reports your acquirer ...

Need a customized Compliance & Audit scope?

Our principal consultants will assess your architecture, compliance drivers, and asset complexity to formulate a non-destructive, high-value testing plan.

Consult with a Lead Assessor