Cybersecurity & compliance consultancy · EU
Understand the rules. Assess your readiness. Build with confidence.
DATADEFENZ is a cybersecurity and compliance consultancy building a regulatory readiness platform. We help organisations work out which cybersecurity, privacy, AI and digital regulations apply to them, assess how ready they are, and build the evidence to prove it — from Sri Lanka's PDPA to NIS2, ISO 27001 and the EU AI Act.
No charge, no obligation. You leave knowing what applies to you.
The question every compliance conversation begins with. Thirteen regulations, standards and frameworks assessed against your answers — each with the reason it applies to you and how confident that answer is. Nothing is stored and nothing is sent.
Scope, controller or processor, the real timeline, and a ten-dimension readiness view.
Open → ISO/IEC 27001:2022 ISO 27001 Gap AssessmentClauses 4–10 and all 93 Annex A controls, rated on evidence and effectiveness.
Explore → Platform NIS2 ReadinessThe dedicated NIS2 applicability, requirements and remediation platform.
Explore Platform →How we work
Three movements, in this order.
Most security spend fails at the joins — an assessment nobody acts on, a control nobody can evidence. We run the whole line, so each stage produces the input the next one needs.
Find out where you actually stand
Applicability first, gap second. What binds you, what you already satisfy, and what the distance costs — written so a board can fund it and an engineer can act on it.
- Scope and applicability determined in writing
- Assessment against a named standard, not a house checklist
- Findings rated by exposure, sequenced by dependency
Close the gap with things that run
Policies people can follow, controls engineers can implement, and the technical work to back them — testing, pipeline security, monitoring design, awareness programmes.
- Control set mapped once, satisfying every framework that asks
- Technical delivery by vetted specialists, scoped by us
- Remediation sequenced against your actual capacity
Make it demonstrable on demand
The gap between implemented and demonstrable is where audits are lost. Every control names its evidence, its owner and its collection interval before we call it done.
- Evidence model wired into the tools you already run
- Certification, audit and customer-questionnaire support
- Reporting a board and an auditor can both use
Services
Six categories. Sixteen engagements.
Most are fixed scope and fixed price — you can read what is included and see a sample of the output before a sales process starts.
GRC & Compliance
The rules and the paperwork
Open 1 serviceSecurity Culture
Training humans, not just firewalls
Open 3 servicesRisk Management
What could go wrong, and what are we doing about it
Open 5 servicesTechnical Security
The hands-on defence side
Open 1 serviceLeadership Advisory
Senior expertise without a full-time hire
Open 1 serviceFast-Turnaround
The urgent, sales-blocking stuff
OpenTry before you hire
The practice, running, in your browser.
Consultancies usually ask you to take competence on trust. These are working tools, not demos — start with the question every compliance conversation begins with.
All 93 Annex A controls
ISO/IEC 27001:2022, browsable, in plain English — with the findings our sample report raised attached to the controls they hit.
Open the explorer Live checkCheck your own headers
A real read-only check against seven HTTP response headers on a domain you own. Small, but genuinely running.
Run a check Navigator · NewSri Lanka PDPA, end to end
Scope against the four statutory triggers, controller or processor, the data lifecycle, what the 2025 Amendment actually changed, and a readiness self-assessment.
Open the navigatorSecurity operations
We support the SOC, not just the paperwork.
Dedicated security-operations specialists, running two assessments most consultancies do not offer: SOC-CMM for security operations maturity, and control-level assessment against the NIST SP 800-series. Both answer a question a maturity percentage cannot — is this capability actually good, and can you prove it?
SOC Maturity Assessment
The open model the industry benchmarks against. Five domains — Business, People, Process, Technology and Services — with maturity and capability scored separately, because a SOC can own excellent tooling and still score badly on how it runs.
- Evidence-validated, not a self-assessment questionnaire
- Element-level heat map showing where the weakness sits
- Target profile matched to your threat exposure
- A baseline you can re-run annually to show movement
NIST 800 Assessment & Consultancy
The control detail behind the Cybersecurity Framework. Where CSF gives a maturity conversation for the board, the 800-series gives a control-by-control determination — satisfied, or other than satisfied — with the assessment evidence to back it.
- Baseline selection and documented tailoring decisions
- Assessment following the SP 800-53A method
- System Security Plan and POA&M in the expected structure
- Mapped to your existing ISO 27001 or CSF work
Proof, not adjectives
Read the deliverable before you buy it.
We publish full sample reports — real document structure, real finding language, real remediation sequencing. DATADEFENZ does not publish client names or logos. Every figure and finding shown on this site is drawn from sample deliverables built in-house.
Start here
Tell us which regulation is keeping you up.
Thirty minutes, no charge. You leave with a view on what applies to you and roughly what closing it would take — whether or not you work with us.
