prove

Governance, audit
& compliance.

Understand your obligations and keep the evidence behind them current.

IT audits, technology due diligence, policy frameworks and certification support. We connect the requirement to the control, the owner and the records an auditor, insurer or client needs.

Reading, Berkshire. Supporting organisations across the UK.

Two colleagues discussing a plan together at a glass whiteboard
Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor scheme MicrosoftCertified Expert

Start with the reason for the work

A transaction, a new requirement and an upcoming assessment call for different scopes and different prices.

You have a deal on the table

Technology due diligence for private equity and M&A, or sell-side readiness before you go to market. A fixed fee agreed before we start, and a remediation estimate the deal team can model.

See technology due diligence

Something is being asked of you

A contract, a regulator, an insurer or a prime contractor has named a standard. We work out what applies, measure the gap, then close it in priority order.

See compliance readiness

You already hold the certificate

It now has to stay true. We operate the controls and capture the evidence as the work happens, so the trail is current at the next assessment or questionnaire.

See audit and assurance

The control and its evidence

A policy describes what should happen. The operational record shows what happened: the patch applied, access reviewed, restore tested or incident contained.

We can operate the agreed technology and capture its evidence as the work happens. The scope defines the controls, responsibilities and records needed for your review.

Requirement
The obligation, standard or contract clause being addressed.
Control and owner
What is in place, who maintains it and how exceptions are handled.
Record
The evidence that the control operated, with its date and scope.
Review and action
Findings, decisions and the person responsible for the next step.

Audit, certification and compliance support

Work out what applies, put controls in place and prepare the records needed for assessment. Formal assessment is a separate engagement, and certification depends on the result.

Audit and assurance

The evidence that your controls are in place and working, captured as the technology is run and packaged against the standard being assessed.

  • Evidence packs
  • Logging and records
  • Internal review
  • Between assessments
See audit and assurance

Cyber Essentials and Cyber Essentials Plus

Preparation for Cyber Essentials and for Cyber Essentials Plus, which adds a technical audit where an assessor tests a sample of your devices and accounts, and the controls kept in place at each annual renewal. As an appointed Cyber Essentials and Cyber Essentials Plus certification body, we also assess and certify other organisations, including your suppliers.

  • Readiness review
  • Plus audit
  • Annual renewal
  • Supplier assurance
See Cyber Security

ISO 27001 support

An information security management system (ISMS), from gap analysis and risk treatment to internal audit and certification support. We hold ISO 27001 ourselves. Your chosen certification body performs the external certification audit.

  • Gap analysis
  • ISMS build
  • Internal audit
  • Certification support
See ISO 27001

CAF alignment

Alignment to the Cyber Assessment Framework for organisations in scope of the NIS Regulations, mapped across the framework's outcomes in the order that closes each gap.

  • CAF objectives A to D
  • NIS Regulations
  • Gap to outcome mapping
Talk to us about CAF

Compliance readiness

What applies to you, from GDPR and the UK data protection regime to the rules your regulator enforces: Cyber Essentials, ISO 27001, FCA systems and controls, SRA, CQC, the NHS Data Security and Protection Toolkit, PCI DSS. Working out which of them applies is the first piece of work. A prioritised path, with the policies and evidence behind it, is the second.

  • GDPR readiness
  • Sector rules
  • Policy frameworks
  • Evidence
Talk to us about readiness

Policy frameworks

The documented backbone every standard expects: information security and acceptable use policies, access control and data retention procedures, continuity and incident response plans, written for how you work.

  • Security policy
  • Access control
  • Data retention
  • Incident plan
See policy frameworks

Technology due diligence

Fixed-fee technology due diligence for private equity and M&A: what a target's IT and custom software are worth, what they cost to own, and whether that changes your offer. If you complete, we can fix what we found.

  • Deal Scan
  • Technical DD
  • Sell-side readiness
  • PE and M&A
See technology due diligence

Certification appointments and ISO evidence

Cyber Essentials Plus certification body

Cyber Essentials and Cyber Essentials Plus

We are appointed to assess and certify other organisations for both schemes, including suppliers in your supply chain. Preparation and assessment have separate responsibilities and records.

3core2 Certification and UKAS management-system certification

Our ISO 27001 and ISO 9001 certificates

DSC is certified for ISO 27001 and ISO 9001 by 3core2 Certification, a UKAS-accredited certification body. Our certificate numbers are 00508-ISMS-001 and 00508-QMS-001.

These are certifications held by DSC. We support clients preparing for their own ISO assessment by a certification body.

The technology behind the evidence

Cyber security

Cyber Essentials, ISO 27001 support, agreed monitoring and incident response. The controls and their records connect to the obligation you need to meet.

Explore cyber security

An IT and security audit

Review your IT, spend, security and efficiency. The output is a prioritised plan you own outright.

Explore the audit

Discuss the evidence you need.

Tell us what a client, regulator, insurer or deal team has asked for, and when it is needed. We will help define the review and the work behind it.

0118 359 2220

Monday to Friday, 9am to 5.30pm.
Reply within one working day.