ISO/IEC 27001:2022
Information security management readiness
A complete ISMS built to pass a Stage 1 and Stage 2 audit, scoped to your business, not a template dump.
Typically 12–20 weeks to audit readiness
See the scopeISO 27001 for information security and ISO 42001 for AI management, designed, documented, and operated with one advisor. Plus quantum technology courses for the teams that have to plan past today's cryptography.
Card, bank transfer, or cryptocurrency via Coinbase for Business.
Two ways we work
ISO/IEC 27001:2022
A complete ISMS built to pass a Stage 1 and Stage 2 audit, scoped to your business, not a template dump.
Typically 12–20 weeks to audit readiness
See the scopeISO/IEC 42001:2023
Governance for the AI you are already shipping: inventory, impact assessment, controls, and oversight that stands up to scrutiny.
Typically 10–18 weeks to audit readiness
See the scope27001 + 42001
One set of controls, one internal audit cycle, two certifications. The efficient path when both standards are in scope.
Typically 16–26 weeks to audit readiness
See the scopeHow a programme runs
01
We fix the boundary, then test every clause and control against what you actually do today.
02
A risk methodology your team can run, and a control set written to your operations.
03
Records start accumulating early, access reviews, supplier checks, incidents, training.
04
Internal audit, management review, certification body selection, and support through Stage 2.
Training
The working mental model engineers need: qubits, superposition, entanglement, and where the real limits sit.
Build a cryptographic inventory, pick your migration order, and defend the plan to auditors and the board.
A board-level briefing on quantum timelines, regulatory pressure, and what to fund this budget cycle.
Beyond computing: QKD, quantum networks, and quantum sensing, capability, cost, and honest limitations.
Payment flexibility
Settle engagements and course fees in major cryptocurrencies alongside conventional card and bank transfer. Useful for international clients, treasury-held digital assets, and organisations that would rather not wait on correspondent banking.
Insights
Certification
Both are management system standards with the same skeleton. The difference is what you are managing, and the evidence an auditor expects.
Post-quantum
The threat is real but it is not universal. The deciding factor is how long your data must stay confidential.
Certification
Documentation is not the hard part. Demonstrating that your management system is operating is.