Methodology
How we deliver ISO 27001, SOC 2, Essential Eight and ISO 42001 in 8–14 weeks — inside your existing Microsoft 365 environment, without buying a GRC platform.
This page covers exactly what happens in each phase, what you'll see at each milestone, and what we expect from you. If you're considering an engagement and want to understand what you're paying for before booking a call, this is the page to read.
Every engagement follows the same structure. Each phase closes with evidence — there's no waiting until the end to find out whether you'll pass.
Two weeks to a complete picture. We map your environment, find the gaps, and produce a prioritised remediation roadmap — not a 100-page report you'll never read.
Phase 1 can be delivered as a standalone engagement. If after the assessment you decide to pause, change direction, or take it in-house, you keep everything we produced. There's no obligation to continue to Phase 2.
Build the management system. Controls, policies, evidence capture, and governance — all running inside your existing Microsoft 365 environment, without overbuilding.
Fixed price for this phase is set at the end of Phase 1 based on what we actually find. No scope creep, no surprise variations — milestone payments only released when you sign off on the deliverable.
Evidence is captured at the point of change, never reconstructed the night before an audit. By the time we reach certification, the evidence pack is already audit-grade.
The single biggest failure mode in compliance engagements is leaving evidence collection to the end. Auditors don't just want to see that a control exists — they want to see it operating over time. If you only start capturing evidence in week 8, your audit will fail or be heavily qualified.
We design every control so the evidence is generated automatically as the control operates. Conditional Access decisions logged in real-time. Approval workflows that produce audit trails by design. Configuration baselines that prove their own currency. By the time we hit Phase 4, you have months of operating evidence — not a frantic scramble.
ISO certifications require surveillance audits annually for three years, then full recertification. Because the evidence pipeline is automated, surveillance audits become a routine confirmation rather than a fresh fire drill. Most clients report surveillance years 2 and 3 cost 80–90% less than the original implementation.
External certification with no surprises. 100% first-time pass rate across all our engagements — because by the time the auditor arrives, we've already QA'd everything they'll ask for.
Not magic — methodology. We've structured the previous three phases so that everything an auditor will ask for already exists, is current, and is defensible before we book the audit. We do an internal dress rehearsal of the audit two weeks before the external auditor arrives. If we wouldn't pass our own internal review, we don't book the external one.
Three structural choices that change the economics and the experience.
Everything we deliver lives inside Microsoft 365. SharePoint for evidence libraries. Power BI for control dashboards. Defender, Intune, Purview, Entra for the controls themselves. No GRC platform licence — no $15–60k/year fee that compounds across surveillance years.
Price agreed before Phase 2 starts, based on real findings from Phase 1. Payments released against delivered milestones — not hours billed. If a phase takes longer than estimated, that's our problem, not yours.
The person who scopes your engagement is the same person who delivers it. Not a partner who pitches and then hands off to juniors. Direct accountability, faster decisions, no relearning.
A free 30-minute call gives you a precise scope, realistic timeline, and a fixed-price quote. If the answer is "you don't need us yet," we'll tell you.