GRC & Compliance
Per-tenant monthly add-on. ISO 27001, NIS2, GDPR coverage via Cyberday ISMS. Available to COSAINT clients below the 50-user COSAINT Strategic minimum.
Available to COSAINT clients below the 50-user COSAINT Strategic minimum. At 50 users and above, GRC is included in COSAINT Strategic.
Discuss Your Compliance RequirementsFour levels of compliance support
Start with the ISMS platform, policy framework, and the logging ISO 27001 requires. Add a named compliance consultant, certification support, and vCISO advisory as your requirements grow.
GRC Foundation
ISMS platform and policy framework
Get your ISMS running on Cyberday with ISO 27001 control mapping, a maintained policy library, and the logging Annex A requires. Managed by Tarbh Tech, reviewed quarterly. Suits organisations driving their own compliance programme.
- Cyberday ISMS platform, full framework library included
- ISO 27001 Annex A control mapping and evidence artefacts
- Policy library setup and maintenance
- Blackpoint LogIC SIEM: log collection, retention, and monitoring (Annex A 8.15, 8.16)
- Platform administration and user management
- Quarterly ISMS review
GRC Managed
Foundation plus a named ISMS owner
A named compliance consultant owns your ISMS day to day, with fortnightly working sessions. For organisations building towards certification or maintaining an ISMS without internal resource.
- Everything in GRC Foundation
- Named ISMS owner, a qualified compliance consultant
- Fortnightly 2-hour workshops with minutes and action tracking
- Risk assessment, risk register, and risk treatment plan
- Statement of Applicability
- Supplier and vendor security assessments
- Management review twice yearly
GRC Certified
Managed plus audit and certification
Everything needed to reach certification and hold it. Independent internal audit, and we attend the external audits with you. For organisations actively certifying or already certified.
- Everything in GRC Managed
- Annual independent internal audit by a qualified ISO 27001 lead auditor
- Stage 1 and Stage 2 certification support
- Surveillance and recertification audit attendance
- Non-conformity and corrective action tracking to closure
GRC Advisory
Certified plus vCISO and multi-framework
Adds strategic security advisory and support for frameworks beyond ISO 27001. For regulated organisations, or those reporting compliance posture to a board.
- Everything in GRC Certified
- vCISO advisory, 4 hours per month
- Multi-framework implementation: NIS2, DORA, GDPR, ISO 27701
- Business continuity plan documentation
- Tabletop exercise facilitation
- Quarterly management review reports and board-level narrative
Prices are per tenant per month, exclusive of VAT, and do not vary with user count. External certification body fees are payable directly by the client.
Frameworks covered
ISO 27001
International standard for information security management systems. Annex A control mapping and evidence packs included.
NIS2
EU Network and Information Systems Directive. Readiness assessment and alignment for essential and important entities.
GDPR
General Data Protection Regulation. Data protection policies, breach notification procedures, and processor management.
Technology Partners
The platforms and partners we work with to deliver governance, risk, and compliance outcomes.
GRC & Compliance FAQ
Which COSAINT tier do I need?
What is Cyberday?
Can I start with GRC Foundation and upgrade later?
What if we are on COSAINT Strategic?
Discuss your compliance requirements
ISO 27001, NIS2, GDPR – we will help you build and maintain the compliance framework your organisation needs.
Get in TouchOr email us at hello@tarbh.tech