FIRST CERTIFICATION
Your customer wants a certificate before they will sign. We get the security right first.
Delivered by
Delivered on Drata, Thoropass or Sprinto, or on a platform you already own.
Loading the calendar
Open the booking pageCalendar not loading? Open Calendly directly
Not sure which certificate you need? That is what the call is for.
info@goldlineconsultancy.co.ukOne practitioner
from diagnostic to Stage 2
Fixed fee
agreed before any work starts
A few hours a week
from your team, not your roadmap
The procurement team asking for ISO 27001. The CISO who will not sign off the integration without SOC 2. That is not a compliance problem, it is a revenue problem, and it is the one this engagement exists to clear.
Your engineers should be building, not writing security policies. The engagement is designed so your team's time goes on the decisions only they can make, and the rest is not theirs.
The person who scopes the engagement delivers it, from the free diagnostic through to sitting in the room at Stage 2. No handover to someone more junior, because there is nobody more junior.
The scope, the fee and the practitioner are committed before any work starts. The certification decision belongs to your certification body, and anyone promising you that outcome is promising something they do not control.
A named enterprise customer has asked for ISO 27001 or SOC 2 and the deal is waiting.
A security questionnaire has arrived and nobody can answer half of it.
You have no security lead, and the founder or first engineer has inherited this.
You need to know which certificate the customer actually wants before spending anything.
PHASE 01
Forty five minutes to establish which certificate the customer actually needs, and whether it is one, both or neither.
PHASE 02
The management system scope written down, and the compliance platform configured against it rather than left on defaults.
PHASE 03
Policies written for how you actually operate, controls implemented, and the evidence an auditor will accept.
PHASE 04
An independent internal audit, certification body engagement coordinated, and the practitioner in the room at Stage 2.
This runs on a compliance platform, because doing it on spreadsheets costs more of your team's time than the platform costs. Goldline is a partner of Drata, Thoropass and Sprinto and will configure whichever suits your stack, or work in one you already own.
THE CHOICE
| A consultant | A platform on its own | Goldline | |
|---|---|---|---|
| Who does the work | Someone senior, billed by the day | Your team, guided by the software | The practitioner who scoped it, on a fixed scope |
| What you get | Advice, and documents you then implement | Evidence collection and continuous control monitoring | The management system, and the evidence to prove it operates |
| Scope and Statement of Applicability | Usually included | Not produced. It records decisions only you can take | Written and defended at audit |
| Clause 9.2 internal audit | Only if independent of the build | Not performed. Software cannot audit itself | Delivered independently, or an independent auditor introduced |
| Your team's time | Meetings, then the work lands with you | Substantial. The platform tracks tasks, it does not do them | A few hours a week during delivery |
| In the room at Stage 2 | Depends on the engagement | No | Yes |
| Commercial shape | Day rate, open ended | Annual licence | Fixed scope, fixed fee, agreed before work starts |
Certification body audit fees are billed separately and pass through at cost.
A free diagnostic call with the practitioner who would do the work. Bring the questionnaire or the contract clause and we will tell you what it is really asking for.
The certification decision rests with your certification body. What Goldline commits to is the scope, the fee and the practitioner.
45 minutes, video, with the practitioner who would do the work. No sales pitch.