Compliance & security pack

Structure your compliance and security obligations into a coherent, applicable and steerable system.

In a single assignment, we bring together the regulatory, organisational and security building blocks your situation requires: GDPR compliance, security governance, documentation, awareness, steering and specialised support.

€8,000–20,000
See detailed content

Included in this pack

  • Obligations map
  • Gap matrix
  • Priority documentation set
  • Security plan
  • Defined governance
  • Compliance roadmap
  • Monitoring system

One compliance plan instead of a succession of independent workstreams.

Why address compliance and security in a single journey?

Obligations overlap

Data protection, risk management, IT security and governance do not work in silos.

Evidence is often shared

Documentation, controls, responsibilities, monitoring and procedures can feed several requirements.

Workstreams must be coordinated

A written policy without technical implementation is not enough; technical protection without governance is hard to sustain.

You avoid duplication

The same teams are not solicited separately for several similar diagnostics and documentary productions.

Your compliance architecture

One system rather than four separate workstreams

Compliance & security governance

GDPR

Personal data

Cybersecurity

IT protection

ISSP

Rules & responsibilities

ISO 27001

Foundation & gaps

DPO / leads

Role & governance

Awareness

Teams

Each building block feeds the others, to limit redundant documents and parallel systems.

Example: an SME must meet the requirements of a major contracting authority

Initial situation

The client asks for:

  • GDPR guarantees
  • a cybersecurity questionnaire
  • an ISSP
  • ISO 27001 elements
  • an organisation of responsibilities

The company has scattered documents, but no coherent system.

Outcome

A single foundation that lets you answer the client immediately and, if needed, continue afterwards towards a full ISO 27001 certification.

Documentary compliance ≠ real compliance

Our objective is not only to produce documents

Necessary

Document

  • policies
  • procedures
  • registers
  • responsibilities

Operational

Implement

  • controls
  • owners
  • practices
  • awareness
  • monitoring
  • indicators

What you get concretely

At the end of the pack, you have:

Obligations map

Applicable obligations and requirements classified by theme and priority level.

Gap matrix

What exists, what is missing and what needs to be corrected.

Priority documentation set

Policies, procedures, registers and documents built within the agreed scope.

Security plan

Organisational and technical measures to implement.

Defined governance

Owners, roles, validation circuits and control points.

Compliance roadmap

Time-ordered actions with owners and priorities.

Monitoring system

KPIs, deadlines, reviews and maintenance mechanisms.

Your progress after the pack

  1. Level 1

    Fragmented

    Scattered documents, poorly defined roles.

  2. Level 2

    Structured

    Policies and responsibilities formalised.

  3. Level 3

    Deployed

    Procedures applied by the teams.

  4. Level 4

    Steered

    Controls, indicators and reviews.

  5. Level 5

    Continuous improvement

    The system is maintained and refined.

This pack is for you if…

1

You have several compliance topics in parallel

GDPR, security, ISO, client requirements…

2

Your documentation exists but is fragmented

3

You have already undergone an audit or received findings

4

A client or contracting authority is tightening its requirements

5

You are preparing a certification or a major contracting process

6

You want to move from scattered documents to a steered system

When should you choose a specialised assignment instead?

1

You are looking only for a DPO

If you only need monthly steering, the outsourced DPO subscription is the right format.

2

Your need concerns ISO 27001 only

If you are aiming directly for a complete ISMS and certification, ISO 27001 support is the right format.

The pack is relevant when several dimensions must be coordinated in a single programme.

What are your main compliance and security challenges?

Your priority scope

Overall maturity 36 %
Priority workstreams 4
Urgency High
  • GDPR40 %
  • Security50 %
  • Documentation30 %
  • Governance40 %
  • ISO20 %

Recommended journey

Compliance & security pack

Priorities

  • bring GDPR documentation up to standard
  • formalise the ISSP
  • structure governance
  • prepare the ISO 27001 foundation

Indicative orientation. Final scope is confirmed after a scoping discussion.

How the pack works

  1. 1

    Baseline & gaps

    • document collection
    • interviews
    • requirements mapping
    • gap analysis
    • prioritisation
  2. 2

    Design & production

    • policies
    • procedures
    • registers
    • responsibilities
    • action plans
    • security measures
  3. 3

    Roll-out & steering

    • validation
    • communication
    • awareness
    • support
    • controls
    • transition to recurring mode

The areas we can integrate into your journey

Depending on your situation, we combine the relevant building blocks in a single plan. The depth of each area is scoped with you: these are not four fully included services.

GDPR compliance

Documentary and operational upgrade based on the gaps identified within the pack scope.

See our full GDPR support

Security foundation & ISO 27001 alignment

During the pack: security foundation, gap analysis and priority documentation. A complete ISMS and certification preparation sit with the dedicated ISO 27001 assignment.

See ISO 27001 support

Security policy (ISSP) & documentation

Build or update the required documentary framework: ISSP, rules, procedures and responsibilities according to scope.

See our security policy support

Organisation of the DPO function

During the pack: GDPR governance scoping, role definition and responsibilities, and designation or kick-off if included in the offer. Monthly steering then sits with the DPO subscription.

See outsourced DPO

ISO 27001

Two distinct stages: foundation, then certification

The pack

Foundation and priority documentation

  • security foundation
  • gap analysis
  • priority documentation

DPO function

Two distinct stages: set-up, then ongoing maintenance

During the pack

Build and set up

  • GDPR governance scoping
  • role definition
  • identification of responsibilities
  • designation / DPO kick-off if included in the offer

After the pack

Maintain the system over time

The outsourced DPO can continue monthly steering if your organisation needs it.

See outsourced DPO

Characteristics

  • Indicative duration: 2 to 5 months on average, depending on volume and maturity.
  • Formalised workshops and checkpoints with your team.
  • Deliverables usable by leadership and operations.

What does the pack scope depend on?

  • number of entities
  • headcount
  • existing maturity
  • documentary level
  • number of obligations covered
  • IT complexity
  • volume of GDPR processing activities
  • number of procedures required
  • ISO objective
  • training needs
  • deployment support

The quote states in black and white the frameworks, documents, workshops and support included.

Scope is defined before we start

Depending on the formula selected, the following may require a complementary assignment:

  • ISO certification by a certification body
  • in-depth pentest
  • exhaustive technical audit
  • implementation of certain infrastructures
  • security licences
  • DPO beyond the agreed period
  • specialised legal audit
  • complex BCP/DRP

Once the system is in place, choose your maintenance mode

Autonomy

Your teams take over with the procedures and tools handed over.

Deliverables associated with the journey

  • Obligations map: applicable requirements classified by theme and priority.
  • Gap matrix: what exists, what is missing, what needs to be corrected.
  • Priority documentation set: policies, procedures, registers within the agreed scope.
  • Security plan: organisational and technical measures to implement.
  • Defined governance: owners, roles, validation circuits and control points.
  • Compliance roadmap: time-ordered actions with owners and priorities.
  • Monitoring system: KPIs, deadlines, reviews and maintenance mechanisms.

Frequently asked questions

Indicative answers — your account manager adapts scope to your context.

Does the pack include ISO 27001 certification?

No. The pack lays a foundation: security, gap analysis and priority documentation. Full ISO 27001 support (complete ISMS, certification preparation) is a dedicated journey. Certification audit by a certification body is not included.

Is the outsourced DPO included?

The pack scopes GDPR governance: role, responsibilities, and designation or kick-off if included in the formula. It is not a DPO subscription. Monthly steering, beyond the period set in the quote, sits with the outsourced DPO formula.

Can we select only certain building blocks?

Yes. The depth of each area (GDPR, ISSP, security, ISO, DPO) is scoped with you. If you only need one specialised assignment, that is a better fit than a pack.

Does the pack replace a cybersecurity audit?

No. The pack structures the system and identifies gaps. An in-depth pentest or an exhaustive technical audit remain complementary assignments, if you activate them.

Do you include the implementation of technical solutions?

We describe the measures to implement and coordinate roll-out within the agreed scope. Implementation of certain infrastructures, and heavy technical work, can be a complementary assignment, with your teams or providers.

Are security licences included?

No. Security licences are out of scope. They are identified during scoping and remain your responsibility, or are quoted separately.

Can we start from documents we already have?

Yes. The baseline assessment builds on what already exists. We identify what can be kept, what must be updated and what is missing.

Can we work with our IT department or existing IT provider?

Yes. We work with your internal teams and your providers. The pack does not require you to change technical counterparties.

What happens after delivery?

You choose the maintenance mode: team autonomy, periodic Complianz reviews, outsourced DPO, ISO support, or cyber support. Nothing is imposed after the pack.

How long does the journey take?

Typically 2 to 5 months, depending on the number of entities, existing maturity and documentary volume. Duration is confirmed in the quote.

Can we stagger the roll-out?

Yes. Roll-out can be phased. Deployment support is one of the items scoped before we start and stated in the quote.

Ready to take action?

€8,000–20,000

Indicative pricing — tailored quote within 24 business hours on average after qualification.

Book a call
Innovation hub