Obligations overlap
Data protection, risk management, IT security and governance do not work in silos.
Structure your compliance and security obligations into a coherent, applicable and steerable system.
In a single assignment, we bring together the regulatory, organisational and security building blocks your situation requires: GDPR compliance, security governance, documentation, awareness, steering and specialised support.
Included in this pack
Data protection, risk management, IT security and governance do not work in silos.
Documentation, controls, responsibilities, monitoring and procedures can feed several requirements.
A written policy without technical implementation is not enough; technical protection without governance is hard to sustain.
The same teams are not solicited separately for several similar diagnostics and documentary productions.
Your compliance architecture
Compliance & security governance
Personal data
IT protection
Rules & responsibilities
Foundation & gaps
Role & governance
Teams
Each building block feeds the others, to limit redundant documents and parallel systems.
Initial situation
The client asks for:
The company has scattered documents, but no coherent system.
Pack
We deliver:
Outcome
A single foundation that lets you answer the client immediately and, if needed, continue afterwards towards a full ISO 27001 certification.
Documentary compliance ≠ real compliance
Necessary
Operational
At the end of the pack, you have:
Applicable obligations and requirements classified by theme and priority level.
What exists, what is missing and what needs to be corrected.
Policies, procedures, registers and documents built within the agreed scope.
Organisational and technical measures to implement.
Owners, roles, validation circuits and control points.
Time-ordered actions with owners and priorities.
KPIs, deadlines, reviews and maintenance mechanisms.
Level 1
Scattered documents, poorly defined roles.
Level 2
Policies and responsibilities formalised.
Level 3
Procedures applied by the teams.
Level 4
Controls, indicators and reviews.
Level 5
The system is maintained and refined.
GDPR, security, ISO, client requirements…
If you only need monthly steering, the outsourced DPO subscription is the right format.
If you are aiming directly for a complete ISMS and certification, ISO 27001 support is the right format.
The pack is relevant when several dimensions must be coordinated in a single programme.
Your priority scope
Recommended journey
Priorities
Indicative orientation. Final scope is confirmed after a scoping discussion.
Depending on your situation, we combine the relevant building blocks in a single plan. The depth of each area is scoped with you: these are not four fully included services.
Documentary and operational upgrade based on the gaps identified within the pack scope.
See our full GDPR supportDuring the pack: security foundation, gap analysis and priority documentation. A complete ISMS and certification preparation sit with the dedicated ISO 27001 assignment.
See ISO 27001 supportBuild or update the required documentary framework: ISSP, rules, procedures and responsibilities according to scope.
See our security policy supportDuring the pack: GDPR governance scoping, role definition and responsibilities, and designation or kick-off if included in the offer. Monthly steering then sits with the DPO subscription.
See outsourced DPOISO 27001
The pack
Then optionally
DPO function
During the pack
After the pack
The outsourced DPO can continue monthly steering if your organisation needs it.
See outsourced DPOThe quote states in black and white the frameworks, documents, workshops and support included.
Depending on the formula selected, the following may require a complementary assignment:
Your teams take over with the procedures and tools handed over.
Periodic Complianz reviews.
See audit & advisoryRecurring GDPR steering.
See outsourced DPOContinue towards certification.
See ISO 27001 supportMaintain and improve protections.
See cyber supportNo. The pack lays a foundation: security, gap analysis and priority documentation. Full ISO 27001 support (complete ISMS, certification preparation) is a dedicated journey. Certification audit by a certification body is not included.
The pack scopes GDPR governance: role, responsibilities, and designation or kick-off if included in the formula. It is not a DPO subscription. Monthly steering, beyond the period set in the quote, sits with the outsourced DPO formula.
Yes. The depth of each area (GDPR, ISSP, security, ISO, DPO) is scoped with you. If you only need one specialised assignment, that is a better fit than a pack.
No. The pack structures the system and identifies gaps. An in-depth pentest or an exhaustive technical audit remain complementary assignments, if you activate them.
We describe the measures to implement and coordinate roll-out within the agreed scope. Implementation of certain infrastructures, and heavy technical work, can be a complementary assignment, with your teams or providers.
No. Security licences are out of scope. They are identified during scoping and remain your responsibility, or are quoted separately.
Yes. The baseline assessment builds on what already exists. We identify what can be kept, what must be updated and what is missing.
Yes. We work with your internal teams and your providers. The pack does not require you to change technical counterparties.
You choose the maintenance mode: team autonomy, periodic Complianz reviews, outsourced DPO, ISO support, or cyber support. Nothing is imposed after the pack.
Typically 2 to 5 months, depending on the number of entities, existing maturity and documentary volume. Duration is confirmed in the quote.
Yes. Roll-out can be phased. Deployment support is one of the items scoped before we start and stated in the quote.
€8,000–20,000
Indicative pricing — tailored quote within 24 business hours on average after qualification.
Quick, free estimate with no commitment — we usually reply within 24 hours.
By submitting this form, you accept our privacy policy.
Choose a day and then a time slot. We will confirm your appointment by email or phone.
Preferred time slot
Request sent successfully
We will get back to you shortly to confirm your time slot.
Availability shown is indicative; final confirmation is provided by our team.