Hand it over — or run it yourself.
This is the done-for-you half of Onwyn: certification readiness across 31 standards, where AI does the heavy drafting and mapping and a named senior consultant verifies every artifact, plus offensive security testing, a maintained obligations register for German companies establishing in the UK. Every engagement runs through the same portal — one scope, one evidence library, one place your team and your auditor look — at a single fixed fee scoped to your size (see the published ranges). Eighteen frameworks — eleven of them from this catalog — are also live as self-serve programs in the Semantic Compliance Engine, from €149/month, with a consultant one click away when you want one.
Certification readiness & audit support
We take you from first gap assessment to a passed audit — AI-accelerated, human-signed. AI drafts, maps and tracks; a named senior consultant reviews and approves every artifact before it reaches your auditor. You see exactly what is done, what is open, and what the auditor will ask for.
- Gap assessment — AI classifies where you stand against every requirement; your consultant validates the verdicts and sets priorities.
- Requirement-by-requirement plan — owners, deadlines, and status for every open item.
- Policy drafting — AI drafts your full policy set from your actual context in days; your consultant reviews and finalizes before anything reaches an auditor.
- Evidence collection & staleness tracking — the portal flags expiring evidence automatically, before it becomes an audit finding.
- Auditor coordination — your auditor gets scoped, read-only portal access instead of email attachments.
Certify once, reuse everywhere
The portal maintains an AI-built crosswalk between standards. Evidence collected for ISO 27001 is automatically suggested against SOC 2, NIS2, and beyond — your consultant confirms each mapping, and your second framework starts partly done, not from zero.
VAPT — vulnerability assessment & penetration testing
Manual, scenario-driven testing by senior testers — not a scanner export. You define the scope, we attack it, and you get findings your engineers can act on and your auditor will accept.
Scope options
Web applications, APIs, external perimeter, internal network, and cloud configuration review — individually or combined into a single engagement.
Deliverables
- Prioritized findings report — each finding CVSS-scored, with reproduction steps and concrete remediation guidance.
- Retest included — fix it, we verify it, the report reflects the verified state.
- Executive summary — risk in business terms, written for your board and your customers.
- Evidence-ready report — formatted to slot directly into certification engagements as pentest evidence.
Findings feed directly into the portal as evidence — when your ISO 27001 or SOC 2 engagement needs a current pentest report, it is already there.
Managed SOC — 24/7 monitoring & response Not yet available
We are building this. It is not something you can buy from us today, and we would rather say so here than in a first meeting.
The intent is a Security Operations Center that watches your estate around the clock, so a 3 a.m. alert reaches an analyst rather than an unread inbox — with the monthly reporting landing in your portal as evidence a framework will accept.
What that needs before we will sell it: an analyst rota that genuinely covers nights and weekends, detection engineering tuned per client rather than a vendor default, and a costed price we can stand behind. None of those is a promise we can make yet.
SOC 2 is not a SOC
Worth separating, because the names collide. SOC 2 is an attestation you earn — an auditor examines your controls and issues a report, and we run those engagements today. Managed SOC is an operational service you subscribe to: people and tooling watching your systems. Only the first is something Onwyn can deliver right now.
Germany to the United Kingdom — without the surprises
A German company opening a UK branch or subsidiary inherits a second set of obligations overnight: registration, data protection, employment, tax registration, and sector rules that were somebody else's problem the day before. Most of it is knowable in advance. Almost none of it is written down in one place, in German, for a company of your shape.
That is what we maintain: a dated register of the obligations that attach to your structure, who they sit with, when they fall due, and what evidence closes them — kept current as the underlying law moves, in the same portal your ISO 27001 programme already runs in.
It is the longest-running engagement Onwyn sells, and the one least like the others: five register domains, three classes of deadline, and a fixed-fee programme run to a named go-live date. It has its own page, because summarising it here undersold it.
What you get
- An obligations register, scoped to your structure — branch or subsidiary, staff or no staff, personal data or none. The scoping questions determine which obligations appear; you answer them, we do not guess.
- Owners, deadlines and evidence — every obligation has a named owner on your side, a date, and the artifact that closes it. The same evidence model as the Semantic Compliance Engine, because it is the same engine.
- Event triggers, not just dates — a hire, a posting, a new director or a redundancy round each fire their own obligations, on their own clocks. Those are the ones companies miss, because no calendar knows the event happened.
- Coordination, not hand-offs — we run the schedule with your UK accountant, your formation agent and the partner law firm, and the status lives in one place instead of four inboxes.
- It reuses what you have already done — if you hold ISO 27001, your existing controls and evidence map straight onto the UK GDPR obligations rather than being collected twice.
Where the line is, plainly
Onwyn is not a law firm and does not give legal advice. We maintain the register, run the schedule and prepare the evidence. Where a question needs a lawyer — the structure decision itself, a contract, anything turning on your specific facts — it goes to the German partner firm we work with, named on your engagement, and you deal with them directly. We would rather tell you that on the website than in the second meeting.
Onwyn Sign — sign, seal and verify Beta
Send a PDF to one signer for a simple electronic signature, or seal a document as your organisation. Every sealed document gets its own code and an evidence package, and anyone can check a document at verify.onwyn.io. Compliance clients use it for policy acknowledgements, management review sign-off and supplier agreements.
It is a Beta and is being tested now: one signer per signing request, and the time is recorded by Onwyn's own clock.
The full standards catalog
31 certifications, frameworks and regulations we deliver as consultant-led engagements, across seven groups. Every one runs through the same portal, with the same crosswalk — so evidence you collect for one counts toward the next. Eleven of the 31 are also live as self-serve programs in the Semantic Compliance Engine: those cards carry a second link, and you can start them today from €149/month without talking to anyone. The other 20 are quote-only for now.
Security & compliance frameworks
8 standardsISO/IEC 27001:2022
Information security management system certification.
SOC 2
Trust Services Criteria attestation (Type I / Type II).
Privacy & data protection
6 standardsGDPR
EU data-protection compliance: RoPA, DPIAs, DPAs, privacy notices.
ISO/IEC 27701
Privacy information management extension to ISO 27001.
AI & emerging tech
3 standardsISO/IEC 42001
AI management system certification readiness.
NIST AI RMF
AI risk-management framework assessment.
EU AI Act
Risk-tier classification and high-risk system obligations.
EU regulations
5 standardsRED Cybersecurity (EN 18031)
Radio Equipment Directive Art. 3(3)(d)–(f) — in force now for connected products, and repealed the day the Cyber Resilience Act takes over. Asset inventory, EN 18031 compliance matrix with decision-tree justifications, technical file and Notified Body preparation.
NIS2 Directive
EU network & information security obligations for essential and important entities.
DORA
Digital operational resilience for the EU financial sector.
EU Cyber Resilience Act
Product cybersecurity requirements incl. SBOM and CE marking.
Industry-specific
4 standardsExport controls & defense
3 standardsAccessibility
2 standardsFive further frameworks are live in the Semantic Compliance Engine ahead of their consultant-led service: TISAX for the automotive supply chain, AI impact assessments, ISO 22301 for business continuity, ISO 9001 for quality management, and BSI C5 for cloud providers selling into the German public sector — self-serve today, with consultant-led delivery in preparation. That makes eighteen live in the engine against 33 in this services catalog; more are added continuously.
A committed price for the platform, published ranges for services
Our prices live on their own page. The Semantic Compliance Engine has committed prices — €149, €349 or €649 a month by company size, locked for 36 months, sign up today. Consultant-led engagements are published as honest ranges; answer a few one-click questions and the estimator shows yours instantly. No form first, no discovery-call theater.
Prefer a plain list? See the services price ranges.
How an engagement runs
The same four steps whether you buy one certification or the full program.
Scope & quote
Tell us the standard, the timeline, and the size of your organization. You get a scoped, fixed-fee quote — estimate it yourself first — with no discovery-call maze.
Kickoff in the portal
Your workspace is live on day one: the requirement tree, the plan, and your named consultant, all in one place.
Execute
AI drafts policies and maps evidence against each requirement; your consultant reviews, corrects and approves. The portal tracks status and flags anything going stale.
Audit & certify
Your auditor works from scoped read-only access to the same evidence library. Findings are tracked to closure — then you certify.
Other platforms leave you alone with the checklist. Ours comes with a consultant.
There have been two ways to get compliant: buy software and do everything yourself, or buy a consultancy and pay by the hour. Onwyn joins the two halves — a platform you run yourself, with senior help one click away.
Software-only platforms
Self-serve, no one to call
- Integrations and dashboards — but when a requirement is unclear or the auditor pushes back, you're on your own
- Template controls; the judgment calls and the policy writing stay with your team
- Expert help means a separate consultancy contract on top of the platform fee
- Mostly US-hosted; EU data residency is the exception, not the rule
Traditional consultancy
Human-only delivery
- Senior expertise on the pitch — often junior delivery on the partner's rate card
- Hourly meters and change orders; scope drifts upward as you go
- Months of elapsed time between workshops; documents go stale on delivery
- Status lives in email threads and spreadsheet versions
Platform + consultant, together
The third way
- Self-serve Semantic Compliance Engine from €149/month — guided requirements, live in under a day
- A senior consultant one click away on any requirement — review, call, or done-for-you
- Consultant-led engagements at one fixed fee — never an hourly meter
- Your auditor works in the same portal, so fieldwork shrinks
- EU data residency, EU-routable AI, full AI opt-out included
Common questions
Can we start with just VAPT?
Yes. VAPT is a standalone engagement with its own scope and report. If you later start a certification, the report is already in your portal as evidence — nothing is redone.
Do you work with our existing auditor?
Yes. We prepare you for the audit; the certification body of your choice conducts it. If you do not have one, we recommend accredited auditors we have worked with and coordinate scheduling.
How does portal access work for auditors?
Auditors get scoped, read-only access limited to the engagement under audit — the requirement tree, evidence, and findings, and nothing else. Access is time-boxed and every view is logged.
Can we reuse evidence across ISO 27001 and SOC 2?
Yes — this is the point of the crosswalk. Evidence is attached once and mapped to every requirement it satisfies across frameworks. A typical ISO 27001 program covers a substantial share of SOC 2's Trust Services Criteria before the SOC 2 engagement even starts.
Where is our data hosted?
In the EU. Portal data — evidence, policies, findings — stays in EU-resident infrastructure, with encryption in transit and at rest. Data-processing terms are part of every engagement contract.
How is pricing structured?
In the open. The platform has committed prices — €149, €349 or €649 a month by company size, locked for 36 months, and you can sign up without talking to anyone. Consultant-led engagements are published as ranges, and the estimator on the pricing page gives you yours in about a minute, no call required; a short scoping settles the exact fixed fee inside the range. No hourly meters, ever. Certification-body audit fees are always passed through at cost — never marked up, never bundled for margin.
Can we run a framework ourselves instead of hiring you?
Yes, and for eighteen frameworks you can start today. The Semantic Compliance Engine gives you the same requirement tree, guidance and evidence vault our consultants work in — ISO 27001, ISO/IEC 27701, ISO 22301, ISO 9001, SOC 2, GDPR, NIS2, TISAX, DORA, the EU Cyber Resilience Act, BSI C5, the EU AI Act, ISO/IEC 42001, the NIST AI RMF and AI impact assessments are live self-serve from €149/month. On any requirement you can pull in a senior consultant for a review, a call, or done-for-you implementation, so choosing self-serve now does not close the door on help later. The other 20 standards in this catalog remain consultant-led engagements. Create your account — you're live in under a day.
We're a very small company — is this affordable for us?
Yes — small companies are exactly who the low end of our published ranges is scoped for. For a small organization's first certification we scope a lean, portal-led engagement and route the audit itself to a certification-body partner sized for small companies, so the certificate-issuance fee stays proportionate to your size instead of being priced for a 200-person audit.
How is AI actually used in our engagement?
AI drafts policies from your actual context, suggests evidence-to-requirement mappings across frameworks, and flags stale or missing evidence. Every AI-generated artifact stays marked as a draft until your named consultant reviews and approves it — nothing AI-written reaches your auditor unreviewed, and you can always see which items are AI-suggested versus consultant-confirmed. AI does not conduct audits, penetration tests, or SOC monitoring — those are done by people.
Can we opt out of AI processing?
Yes. External AI processing can be disabled for your engagement entirely — your consultants then work conventionally in the same portal. When AI is enabled, processing can be routed through EU-hosted models, your data is never used to train them, and the same EU data-residency terms apply.
Tell us the standard. We'll quote the path.
A scoped, fixed-fee quote within days — one scope, one price, no hourly meter — and a portal workspace ready the day you accept. Or start in the Semantic Compliance Engine tonight and bring a consultant in when you need one.