Tayside Technical Services Logo

Compliance readiness · Dundee, Angus & Tayside

A customer has asked for Cyber Essentials or ISO 27001. We tell you exactly what you are missing.

A fixed-price readiness assessment against the complete published control set, not a sample. You get a gap analysis, a prioritised remediation plan, and a list of the evidence you need to produce, so you can answer the questionnaire or book the certification audit with confidence.

We are based in Angus and work with businesses across Dundee, Tayside and the wider Scottish supply chain.

Most people call us on one of these days

A customer sent a security questionnaire

Forty pages of questions about controls nobody in the business has ever documented, and a deadline attached to a contract you cannot afford to lose.

A tender demands Cyber Essentials

You are bidding for public sector work, or supplying someone who is, and certification has become a condition of being considered at all.

A large customer wants ISO 27001

Renewal is conditional on a standard you have never been through, and the quotes you have had are five figures and several months.

We assess the full control set

Not a representative sample, and not a generic checklist. Every control in the published standard, with the evidence required for each one.

Cyber Essentials

37

v3.3, in force since 26 April 2026

The UK government-backed scheme. Five technical controls, and the usual requirement for Scottish public sector contracts.

ISO/IEC 27001:2022

93

All 93 Annex A controls

The full information security management standard. Commonly demanded by large private-sector customers.

SOC 2

61

AICPA Trust Services Criteria

All 33 common criteria plus Availability, Confidentiality, Processing Integrity and Privacy. Usually requested by US customers.

UK GDPR

69

Mapped to the ICO's nine audit toolkits

Structured on the Information Commissioner's own Data Protection Audit Framework, with every control mapped to UK GDPR articles.

What you receive

Control-by-control gap analysis

Every control marked met, partial or gap, with the reasoning and the document that supports it.

Prioritised remediation plan

What to fix, in what order, with the automatic-failure items called out first.

Evidence request list

The specific documents and records you need to produce, so you are not guessing what an assessor will ask for.

What we are, and what we are not

We prepare you for assessment. We do not issue certificates. Cyber Essentials certification is issued by an IASME-accredited certification body, and ISO 27001 certification by an accredited certification body. Anyone telling you otherwise is worth a second look.

Assessments are produced with our own tooling and reviewed by a person before they reach you. The tooling is why a full 93-control ISO 27001 gap analysis costs what it does rather than five figures.

Common questions

Know what you are missing before your customer does

Tell us which standard has been asked of you and when you need it by.