Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Compliance & GRC

Organizations that need to demonstrate compliance to a regulator, a client, or an insurer — often against several frameworks at the same time.

Last updatedAugust 22, 2026

The problem this solves

A client, a regulator, or an insurer asks for proof of compliance, sometimes against several frameworks at once — ISO 27001 for a tender, law 05-20 for operations in Morocco, GDPR for European citizens' data. Treating each framework in isolation multiplies the work without a proportional reduction in risk.

What's included

Gap diagnosis against the targeted framework(s)

Risk analysis (ISO 27005, EBIOS RM, or FAIR depending on context)

Drafting of the documentation set (policies, procedures, registers)

Support implementing risk treatment measures

Certification-audit preparation

Response to your clients' security questionnaires

UCM (Unified Control Mapping) methodology: a single control set mapped simultaneously onto ISO 27001, NIS2, law 05-20, NESA, NCA ECC, and GDPR — an organization subject to several frameworks implements once and demonstrates compliance to each (full methodology at /approche/ucm)

Frameworks applied

ISO/IEC 27001:2022Law 05-20 & DGSSI requirementsLaw 09-08 & CNDPGDPRNIS2DORANESA / UAE IA StandardsNCA ECC-2:2024SAMA CSFPCI DSS v4.0SOC 2Bank Al-Maghrib & ACAPS directives

Deliverables

Gap diagnosis report

Risk register and treatment plan

Documentation set (policies, procedures)

UCM mapping of controls shared across the relevant frameworks

Certification-audit preparation file

Documented responses to client security questionnaires

Varies with the number of frameworks and starting maturity — from a few weeks for a targeted upgrade to several months for full certification preparation

Typical duration

Client prerequisites

  • Designation of an internal compliance point of contact
  • Access to existing documentation (policies, contracts, architecture diagrams)
  • Availability of business stakeholders for diagnostic interviews

Frequently asked questions

Do we have to redo all the work for every framework we're subject to?

No — that is exactly the purpose of the UCM (Unified Control Mapping) methodology: a single control set is implemented once, then mapped onto each relevant framework (ISO 27001, NIS2, law 05-20, NESA, NCA ECC, GDPR). An organization subject to several frameworks implements once and demonstrates compliance several times. Full methodology at /approche/ucm.

Does the engagement guarantee we obtain certification?

No. The decision to certify belongs exclusively to the accredited certification body, which conducts an independent audit. The engagement prepares the organization for that audit but cannot replace it or guarantee its outcome.

How many frameworks can you cover in parallel?

It depends on the organization's actual perimeter (sector, countries of operation, clients). The frameworks applied are listed above; the initial diagnosis determines which ones actually apply to your situation.

Get in touch