How we help
Kellwick clients rarely share an industry. What they share is that an external requirement has raised the standard they must meet. When an audit, regulator, customer or contract moves the bar, we turn that requirement into a clear scope, working controls, defensible evidence and continuous governance.
When organisations call us
You do not need to fit an industry to work with us. You need one of these to be true.
A customer, tender or growth plan now requires ISO 27001 or another assurance standard.
A regulatory obligation such as DORA or NIS2 has become an operating requirement.
Enterprise procurement or a security review is asking questions your current evidence cannot answer cleanly.
A contract or supply-chain position introduces CMMC, NIST SP 800-171 or other security obligations.
AI, new products, suppliers or data use create governance requirements your existing system does not cover.
Security and GRC need senior ownership, but a full-time CISO is not the right answer.
One plan, every framework
The same four steps carry every engagement, whether it starts with ISO 27001, DORA, NIS2, SOC 2, CMMC or a vCISO retainer.
Understand scope, obligations, current controls, evidence and gaps - so you know exactly where you stand before someone else asks.
Prioritise remediation, assign ownership and implement what is missing, without letting compliance paralyse delivery.
Build the evidence trail, test readiness and prepare for external scrutiny - so the audit or regulator finds what you already know.
Keep controls, risks, suppliers, metrics and governance current through ongoing support or a vCISO retainer.
What ready looks like
Every control, risk and supplier has a named owner. Nothing lives only in someone's head.
Policies become controls that actually run in product, engineering and operations - not documents nobody follows.
The proof an auditor, regulator or buyer asks for is mapped, current and where you expect it.
Readiness becomes an operating discipline you keep, not a fire drill you repeat before every deadline.
Fit
We work best with a specific situation, not a specific sector. Being clear about it saves everyone time.
Best fit
Not a fit
What it costs
Scoped for one question - a questionnaire, a framework a buyer named, a platform that was configured once and never revisited - rather than a full programme.
Scoped on a call
Fast, expert answers to a stalled security questionnaire - up to 150 questions, so a deal stops waiting on you.
For larger or ongoing needs, see Full Questionnaire Support.
Scoped on a call
Get audit-ready for a SOC 2 examination - scope the Trust Services Criteria, build the controls and evidence, and walk into the CPA's audit prepared. Most ISO 27001 evidence carries over.
What changes the price: Number of Trust Services Criteria in scope · Type I (point in time) vs Type II (over a period) · Company size · Current evidence quality
Kellwick prepares you; the SOC 2 report itself is issued by a licensed CPA firm (their fee is separate).
Scoped on a call
AI management system readiness against ISO 42001's Annex A and the AI impact assessment that sets it apart from ISO 27001.
What changes the price: Number of AI systems · Scope · Existing ISMS
Scoped on a call
Ongoing questionnaire response backed by a reusable answer library, so each one gets faster, not harder.
What changes the price: Volume · Complexity
Scoped on a call
Turn a half-configured compliance platform into real, audit-grade evidence - not a screen full of green checks an auditor will reject.
What changes the price: State of the platform · Number of controls · Scope
Every engagement is fixed-scope and fixed-price before it starts. Prices exclude taxes, certification-body fees, travel and third-party services, and are set on a short scoping call. All pricing.
Whatever raised it - an audit, a regulator, a customer or a contract - start with a clear read of your gaps, priorities and evidence.