Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Cybersecurity

Compliance consulting that prepares you for the external audit.

F Creative Studio 360 helps organisations in any country get a security programme ready for ISO/IEC 27001, SOC 2 or PCI DSS. The certificate is issued by someone else.

A template is not a management system.

The work is built around the standard you are being measured against. For an information security management system that is ISO/IEC 27001. For a service organisation report that is the AICPA Trust Services Criteria used in SOC 2. Where card payments are in scope, it is PCI DSS.

If the organisation already keeps evidence in a platform such as Vanta, the engagement can use those records. F Creative Studio 360 does not require a particular product, and does not sell one.

The standard follows the organisation
A payment business, a software company and a hospital do not sit under the same rules. F Creative Studio 360 prepares against the frameworks that apply where you operate.
Preparation is not the certificate
We help you get ready. An accredited certification body, a licensed accounting firm, or your own qualified assessor issues the result. F Creative Studio 360 does not certify you.
Evidence has to be yours
Policies and screenshots only help if they describe the systems you actually run. The work uses the records your team can keep producing after the engagement ends.
This is not a penetration test
The engagement is scope, gaps, controls and evidence. Systems are not attacked. Authorised testing is a separate engagement, and only when it is written into scope.

What the work covers

The scope is the standard and the entities in front of you. The same method works in any country. The rules inside it change with the obligation.

ISO/IEC 27001
Scope for an information security management system, a gap view, and the policies and records an external certification body will ask to see.
SOC 2
Design of controls, and how they operate over a period, against the AICPA Trust Services Criteria. The attestation is issued by a licensed accounting firm.
PCI DSS
Where cardholder data is in scope, a view of the requirements that apply to that environment. A qualified security assessor, when one is required, is appointed by you.
Other rules that apply
NIST Cybersecurity Framework, GDPR, the HIPAA Security Rule or NIS2, when that is the obligation. A local rule is used only when the organisation is subject to it.
Policies the business can keep
Documents written for the way you work, not a generic pack. Your team owns them after the engagement.
An internal review before the external one
A check that the evidence matches the control, so the external auditor is not the first person to find the gap.

How an engagement runs

The same shape works in any country. It can be done on site or remotely, including when the systems sit in more than one place.

  1. 1

    Confirm the scope

    Which entities, which countries, which systems, and which standard those entities are actually being measured against.

  2. 2

    Find the gaps

    A structured comparison with the chosen standard. No attack on systems, and no availability test.

  3. 3

    Close what is in scope

    A prioritised plan for policies and controls. Implementation stays with your team unless build work is written in separately.

  4. 4

    Gather the evidence

    The records an auditor will ask for, organised so your team can produce them again.

  5. 5

    Sit with the external audit

    Support while the certification body or accounting firm does its work. They issue the result. F Creative Studio 360 does not.

What you receive

  • A written scope for the entities and systems being measured.
  • A gap view against the standard in the engagement.
  • Policies and procedures your team can keep using.
  • An evidence pack organised for the external auditor.
  • Notes from an internal review, when one was in scope.
  • Support during the external audit, without a claim that you are certified.

Rules the work can use

F Creative Studio 360 uses the references that apply where you are governed. Examples include the NIST Cybersecurity Framework, GDPR, the HIPAA Security Rule and NIS2.

For an organisation that is actually subject to them, the work can use CPS 234 and the Essential Eight. Naming a rule is not a statement that you comply with it.

Common questions

What is included in compliance consulting?+

Scope, a gap view against the standards in the engagement, help with policies and evidence, an internal review when that is in scope, and support during the external audit. F Creative Studio 360 does not issue the certificate or the attestation.

How is this different from a cybersecurity audit or a risk assessment?+

A cybersecurity audit reviews controls and configuration. A risk assessment ranks what was found by the effect on the business. Compliance consulting prepares a programme for a named standard so an external party can assess it. They can be scoped together, and they are not the same engagement.

Where do you deliver this?+

For organisations in any country. The work uses the standard you are being measured against, such as ISO/IEC 27001, SOC 2 or PCI DSS. A local rule, such as CPS 234 or the Essential Eight, is used only when that organisation is actually subject to it.

Will you certify us?+

No. ISO/IEC 27001 certification is issued by an accredited certification body. A SOC 2 report is issued by a licensed accounting firm under the AICPA Trust Services Criteria. PCI DSS is assessed by the organisation or by a qualified security assessor when the standard requires one. F Creative Studio 360 prepares the programme. We do not certify it.

Do you file anything with a regulator?+

No. Interpretation of the statute, and any filing, stays with your counsel. F Creative Studio 360 does not file reports for you.

How much does it cost, and how long does it take?+

It depends on the standard, the size of the environment, and whether an internal review is included. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Start with the standard you are being asked to meet.

F Creative Studio 360 will look at the entities, the systems and the standard, then say what a sensible engagement includes.