Cyber Key Security

SOC 2 · HIPAA · PCI DSS · ISO/IEC 27001:2022 · ESG

Certificate consultancy

One control programme. Several buyer and regulator conversations.

We prepare organisations for independent attestation and certification. We do not issue certificates ourselves — we make you audit-ready, stay with you through the examination, and keep the programme alive afterwards.

Why this is hard without a partner

Enterprise buyers now expect SOC 2 Type II. International customers and public-sector tenders expect ISO/IEC 27001:2022. Healthcare work brings HIPAA. Card data brings PCI DSS v4.0. EU disclosure rules are turning ESG from a slide deck into auditable data. The controls overlap by roughly 70–80%, but the evidence, sampling, and language do not. Running five projects in parallel burns the same engineers five times.

What CKS delivers

Scope that matches how you sell

System boundaries, in-scope people and vendors, and a clear decision on Type I versus Type II, Stage 1/2, SAQ versus ROC, or ESG disclosure readiness — before anyone writes a policy.

Unified control catalog

Access, encryption, logging, change, vendor risk, incident response, and awareness mapped once across SOC 2 Trust Services Criteria, ISO 27001 Annex A, HIPAA safeguards, and PCI DSS requirements.

Gap analysis and remediation roadmap

Current-state versus required evidence, owners, and a sequence that respects change windows — not a 200-page report you cannot action.

Audit liaison

We work with your chosen CPA firm or accredited certification body: evidence packs, walkthroughs, finding close-out, and surveillance-year hygiene.

Frameworks we prepare you for

Pick the market you are entering. We start there, then reuse evidence everywhere else it legally and professionally applies.

SOC 2

AICPA Trust Services Criteria. Type I is a point-in-time snapshot of design; Type II tests operating effectiveness over a period — typically 3–12 months. US B2B SaaS procurement still treats Type II as table stakes. We treat it as a continuous evidence operation, not a once-a-year scramble.

HIPAA

Security, Privacy, and Breach Notification Rules. Risk analysis, administrative / physical / technical safeguards, and Business Associate Agreements. We align technical work with what OCR actually samples after an incident — not a checkbox PDF.

PCI DSS v4.0

Cardholder data environment, MFA on CDE access, targeted risk analyses, and authenticated vulnerability scanning. We help you choose SAQ versus ROC, shrink scope where it is honest to do so, and prepare for the requirements that became mandatory under 4.0.

ISO/IEC 27001:2022

An Information Security Management System: context, risk, Statement of Applicability, Annex A (93 controls across organisational, people, physical, and technological themes), Stage 1 and Stage 2, then surveillance. 2013 certificates are expired — 2022 is the only live path.

ESG consultancy

Materiality, governance, and data that can survive assurance. For EU-facing companies we structure work with CSRD/ESRS in mind: policies, processes, and evidence — not marketing claims. We do not greenwash.

Engagement shape

  1. 1. Discover

    Business model, systems, data classes, customers, and which frameworks actually unblock revenue.

  2. 2. Gap and design

    Control catalog, SoA or TSC mapping, policy set, and a 90-day remediation plan with named owners.

  3. 3. Operate and evidence

    Access reviews, logging, vendor DD, training, change tickets — the rhythm Type II and ISO surveillance demand.

  4. 4. Examine and sustain

    Auditor coordination, finding remediation, and a calendar so year two is cheaper than year one.

What you leave with

  • A scoped readiness programme tied to sales and regulatory reality
  • Policies, registers, and evidence that multiple frameworks can reuse
  • A named CKS consultant through the examination window
  • A sustainment calendar for surveillance, Type II refresh, and PCI cycles

FAQ

Do you issue SOC 2 reports or ISO certificates?
No. Independent CPA firms issue SOC 2 reports. Accredited certification bodies issue ISO/IEC 27001 certificates. We prepare you, remediate, and stay through the audit. That separation is how the market stays honest.
SOC 2 or ISO 27001 first?
US enterprise buyers: SOC 2 Type II first. International, public-sector, or EU customers: ISO 27001:2022 first. Many clients run both on a shared catalog — we will tell you if that is cheaper than sequencing.
How long does Type II take?
Design and gap work can start immediately. The observation window is usually three to twelve months. We do not invent a shorter Type II.
Can HIPAA and PCI share the same programme?
Baseline security controls overlap. PHI handling and cardholder data add domain-specific work. We map once, then add only what those regimes uniquely require.

Talk to an expert today

+359 895 155 438
info@cyberks.com

Call now

Talk to an expert today

One control programme. Several buyer and regulator conversations.

Call nowFree consultation