Hand it over — or run it yourself.
This is the done-for-you half of Onwyn: certification readiness across 30 standards, where AI does the heavy drafting and mapping and a named senior consultant verifies every artifact, plus offensive security testing, 24/7 defensive operations, and a maintained obligations register for German companies establishing in the UK. Every engagement runs through the same portal — one scope, one evidence library, one place your team and your auditor look — at a single fixed fee scoped to your size (see the published ranges). Fifteen frameworks — ten of them from this catalog — are also live as self-serve programs in the Compliance Engine, from €149/month, with a consultant one click away when you want one.
Certification readiness & audit support
We take you from first gap assessment to a passed audit — AI-accelerated, human-signed. AI drafts, maps and tracks; a named senior consultant reviews and approves every artifact before it reaches your auditor. You see exactly what is done, what is open, and what the auditor will ask for.
- Gap assessment — AI classifies where you stand against every requirement; your consultant validates the verdicts and sets priorities.
- Requirement-by-requirement plan — owners, deadlines, and status for every open item.
- Policy drafting — AI drafts your full policy set from your actual context in days; your consultant reviews and finalizes before anything reaches an auditor.
- Evidence collection & staleness tracking — the portal flags expiring evidence automatically, before it becomes an audit finding.
- Auditor coordination — your auditor gets scoped, read-only portal access instead of email attachments.
Certify once, reuse everywhere
The portal maintains an AI-built crosswalk between standards. Evidence collected for ISO 27001 is automatically suggested against SOC 2, NIS2, and beyond — your consultant confirms each mapping, and your second framework starts partly done, not from zero.
VAPT — vulnerability assessment & penetration testing
Manual, scenario-driven testing by senior testers — not a scanner export. You define the scope, we attack it, and you get findings your engineers can act on and your auditor will accept.
Scope options
Web applications, APIs, external perimeter, internal network, and cloud configuration review — individually or combined into a single engagement.
Deliverables
- Prioritized findings report — each finding CVSS-scored, with reproduction steps and concrete remediation guidance.
- Retest included — fix it, we verify it, the report reflects the verified state.
- Executive summary — risk in business terms, written for your board and your customers.
- Evidence-ready report — formatted to slot directly into certification engagements as pentest evidence.
Findings feed directly into the portal as evidence — when your ISO 27001 or SOC 2 engagement needs a current pentest report, it is already there.
Managed SOC — 24/7 monitoring & response
A Security Operations Center that watches your estate around the clock, so a 3 a.m. alert reaches an analyst — not an unread inbox. You keep visibility through the portal; we handle the watching.
What's covered
- Log ingestion — from your applications, endpoints, cloud accounts, and identity providers.
- Detection engineering — rules tuned to your environment, not a generic ruleset left on defaults.
- Alert triage — analysts separate real incidents from noise before anything reaches your team.
- Incident response playbooks — agreed in advance, so containment starts in minutes, not meetings.
- Monthly reporting — incidents, trends, and coverage, delivered into the portal as audit-usable evidence.
SOC 2 is not a SOC
SOC 2 is an attestation you earn — an auditor examines your controls and issues a report. Managed SOC is an operational service you subscribe to — people and tooling monitoring your systems 24/7. They are complementary, and many clients need both: the Managed SOC produces exactly the monitoring evidence a SOC 2 audit asks for.
Germany to the United Kingdom — without the surprises
A German company opening a UK branch or subsidiary inherits a second set of obligations overnight: registration, data protection, employment, tax registration, and sector rules that were somebody else's problem the day before. Most of it is knowable in advance. Almost none of it is written down in one place, in German, for a company of your shape.
That is what we maintain: a dated register of the obligations that attach to your structure, who they sit with, when they fall due, and what evidence closes them — kept current as the underlying law moves, in the same portal your ISO 27001 programme already runs in.
What you get
- An obligations register, scoped to your structure — branch or subsidiary, staff or no staff, personal data or none. The scoping questions determine which obligations appear; you answer them, we do not guess.
- Owners, deadlines and evidence — every obligation has a named owner on your side, a date, and the artifact that closes it. The same evidence model as the compliance engine, because it is the same engine.
- Kept current — when a threshold, a fee or a filing deadline changes, your register changes and you are told what moved and when. A register that was right in March and silent since is worse than no register.
- Coordination, not hand-offs — we run the schedule with your UK accountant, your formation agent and the partner law firm, and the status lives in one place instead of four inboxes.
- It reuses what you have already done — if you hold ISO 27001, your existing controls and evidence map straight onto the UK GDPR obligations rather than being collected twice.
Where the line is, plainly
Onwyn is not a law firm and does not give legal advice. We maintain the register, run the schedule and prepare the evidence. Where a question needs a lawyer — the structure decision itself, a contract, anything turning on your specific facts — it goes to the German partner firm we work with, named on your engagement, and you deal with them directly. We would rather tell you that on the website than in the second meeting.
The full standards catalog
30 certifications, frameworks and regulations we deliver as consultant-led engagements, across seven groups. Every one runs through the same portal, with the same crosswalk — so evidence you collect for one counts toward the next. Seven of the 30 are also live as self-serve programs in the Compliance Engine: those cards carry a second link, and you can start them today from €149/month without talking to anyone. The other 23 are quote-only for now.
Security & compliance frameworks
8 standardsISO/IEC 27001:2022
Information security management system certification.
SOC 2
Trust Services Criteria attestation (Type I / Type II).
Privacy & data protection
6 standardsGDPR
EU data-protection compliance: RoPA, DPIAs, DPAs, privacy notices.
ISO/IEC 27701
Privacy information management extension to ISO 27001.
AI & emerging tech
3 standardsISO/IEC 42001
AI management system certification readiness.
NIST AI RMF
AI risk-management framework assessment.
EU AI Act
Risk-tier classification and high-risk system obligations.
EU regulations
4 standardsNIS2 Directive
EU network & information security obligations for essential and important entities.
DORA
Digital operational resilience for the EU financial sector.
EU Cyber Resilience Act
Product cybersecurity requirements incl. SBOM and CE marking.
Industry-specific
4 standardsExport controls & defense
3 standardsAccessibility
2 standardsFive further frameworks are live in the Compliance Engine ahead of their consultant-led service: TISAX for the automotive supply chain, AI impact assessments, ISO 22301 for business continuity, ISO 9001 for quality management, and BSI C5 for cloud providers selling into the German public sector — self-serve today, with consultant-led delivery in preparation. That makes fifteen live in the engine against 30 in this services catalog; more are added continuously.
A committed price for the platform, published ranges for services
Our prices live on their own page. The Compliance Engine has committed prices — €149, €349 or €649 a month by company size, locked for 36 months, sign up today. Consultant-led engagements are published as honest ranges; answer a few one-click questions and the estimator shows yours instantly. No form first, no discovery-call theater.
Prefer a plain list? See the services price ranges.
How an engagement runs
The same four steps whether you buy one certification or the full program.
Scope & quote
Tell us the standard, the timeline, and the size of your organization. You get a scoped, fixed-fee quote — estimate it yourself first — with no discovery-call maze.
Kickoff in the portal
Your workspace is live on day one: the requirement tree, the plan, and your named consultant, all in one place.
Execute
AI drafts policies and maps evidence against each requirement; your consultant reviews, corrects and approves. The portal tracks status and flags anything going stale.
Audit & certify
Your auditor works from scoped read-only access to the same evidence library. Findings are tracked to closure — then you certify.
Other platforms leave you alone with the checklist. Ours comes with a consultant.
There have been two ways to get compliant: buy software and do everything yourself, or buy a consultancy and pay by the hour. Onwyn joins the two halves — a platform you run yourself, with senior help one click away.
Software-only platforms
Self-serve, no one to call
- Integrations and dashboards — but when a requirement is unclear or the auditor pushes back, you're on your own
- Template controls; the judgment calls and the policy writing stay with your team
- Expert help means a separate consultancy contract on top of the platform fee
- Mostly US-hosted; EU data residency is the exception, not the rule
Traditional consultancy
Human-only delivery
- Senior expertise on the pitch — often junior delivery on the partner's rate card
- Hourly meters and change orders; scope drifts upward as you go
- Months of elapsed time between workshops; documents go stale on delivery
- Status lives in email threads and spreadsheet versions
Platform + consultant, together
The third way
- Self-serve Compliance Engine from €149/month — guided requirements, live in under a day
- A senior consultant one click away on any requirement — review, call, or done-for-you
- Consultant-led engagements at one fixed fee — never an hourly meter
- Your auditor works in the same portal, so fieldwork shrinks
- EU data residency, EU-routable AI, full AI opt-out included
Common questions
Can we start with just VAPT?
Yes. VAPT is a standalone engagement with its own scope and report. If you later start a certification, the report is already in your portal as evidence — nothing is redone.
Do you work with our existing auditor?
Yes. We prepare you for the audit; the certification body of your choice conducts it. If you do not have one, we recommend accredited auditors we have worked with and coordinate scheduling.
How does portal access work for auditors?
Auditors get scoped, read-only access limited to the engagement under audit — the requirement tree, evidence, and findings, and nothing else. Access is time-boxed and every view is logged.
Can we reuse evidence across ISO 27001 and SOC 2?
Yes — this is the point of the crosswalk. Evidence is attached once and mapped to every requirement it satisfies across frameworks. A typical ISO 27001 program covers a substantial share of SOC 2's Trust Services Criteria before the SOC 2 engagement even starts.
Where is our data hosted?
In the EU. Portal data — evidence, policies, findings — stays in EU-resident infrastructure, with encryption in transit and at rest. Data-processing terms are part of every engagement contract.
How is pricing structured?
In the open. The platform has committed prices — €149, €349 or €649 a month by company size, locked for 36 months, and you can sign up without talking to anyone. Consultant-led engagements are published as ranges, and the estimator on the pricing page gives you yours in about a minute, no call required; a short scoping settles the exact fixed fee inside the range. No hourly meters, ever. Certification-body audit fees are always passed through at cost — never marked up, never bundled for margin.
Can we run a framework ourselves instead of hiring you?
Yes, and for fifteen frameworks you can start today. The Compliance Engine gives you the same requirement tree, guidance and evidence vault our consultants work in — ISO 27001, ISO/IEC 27701, ISO 22301, ISO 9001, SOC 2, GDPR, NIS2, TISAX, DORA, the EU Cyber Resilience Act, BSI C5, the EU AI Act, ISO/IEC 42001, the NIST AI RMF and AI impact assessments are live self-serve from €149/month. On any requirement you can pull in a senior consultant for a review, a call, or done-for-you implementation, so choosing self-serve now does not close the door on help later. The other 20 standards in this catalog remain consultant-led engagements. Create your account — you're live in under a day.
We're a very small company — is this affordable for us?
Yes — small companies are exactly who the low end of our published ranges is scoped for. For a small organization's first certification we scope a lean, portal-led engagement and route the audit itself to a certification-body partner sized for small companies, so the certificate-issuance fee stays proportionate to your size instead of being priced for a 200-person audit.
How is AI actually used in our engagement?
AI drafts policies from your actual context, suggests evidence-to-requirement mappings across frameworks, and flags stale or missing evidence. Every AI-generated artifact stays marked as a draft until your named consultant reviews and approves it — nothing AI-written reaches your auditor unreviewed, and you can always see which items are AI-suggested versus consultant-confirmed. AI does not conduct audits, penetration tests, or SOC monitoring — those are done by people.
Can we opt out of AI processing?
Yes. External AI processing can be disabled for your engagement entirely — your consultants then work conventionally in the same portal. When AI is enabled, processing can be routed through EU-hosted models, your data is never used to train them, and the same EU data-residency terms apply.
Tell us the standard. We'll quote the path.
A scoped, fixed-fee quote within days — one scope, one price, no hourly meter — and a portal workspace ready the day you accept. Or start in the Compliance Engine tonight and bring a consultant in when you need one.