GRC / Compliance8–16 weeks

Compliance Program

Build and sustain the controls needed to achieve and maintain regulatory certification.

Compliance programmes fail when they treat certification as a destination rather than an ongoing capability. Mitigence designs compliance programmes that satisfy auditors and genuinely reduce risk — mapping controls to multiple frameworks simultaneously where possible to reduce duplicated effort.

ComplianceGRCISO 27001:2022SOC 2NIST CSF 2.0DORA

Engagement Phases

1

Gap Assessment

1–2 weeks

Measure current controls against target framework requirements (ISO 27001:2022, SOC 2, NIST CSF 2.0, PCI DSS v4.0.1, DORA, or equivalent).

2

Control Mapping

1–2 weeks

Map requirements to controls, identify overlaps across frameworks, and assign ownership for each control domain.

3

Policy & Procedure Development

2–4 weeks

Author or update policies, standards, and procedures to the level of evidence required for audit.

4

Implementation Support

3–6 weeks

Support control owners through implementation — technical, operational, and process-level changes.

5

Audit Preparation & Evidence Pack

1–2 weeks

Compile evidence, conduct internal readiness review, and prepare your team for auditor interviews.

What You Receive

  • Gap assessment report with control heatmap
  • Control mapping to target framework(s)
  • Policy and procedure documentation suite
  • Control implementation evidence pack
  • Internal audit readiness report
  • Audit preparation briefing for key stakeholders

Ready to scope this engagement?

Tell us about your environment and objectives — we'll map the approach to your context.

Schedule a call →