Services on Heelr
Governance, risk and compliance
Compliance work usually lands with a deadline behind it. A customer will not sign until they see a certificate. A regulator has set a date. A procurement process depends on a framework you have not yet started. For most companies the difficulty is not the work itself but knowing which framework applies to them, what good looks like, and who to trust to get there.
Heelr connects you with cybersecurity professionals who prepare organisations for the governance, risk and compliance requirements that matter across the UK and Europe. Every professional has their identity verified and their certifications validated, so you are working with someone who has done this before. Whether you need a single certification or an ongoing risk and governance programme, you agree the scope and price before any work begins.
Which framework does your company need?
The right framework follows what is driving the requirement.
If a UK customer or a public-sector contract is asking for baseline security assurance, [Cyber Essentials](/services/grc-and-compliance/cyber-essentials) is usually the starting point. It is achievable quickly and is increasingly a condition of winning work.
If you are selling to larger enterprises or internationally, [ISO 27001](/services/grc-and-compliance/iso-27001) tends to be the framework buyers recognise and require.
If your customers are North American enterprises, particularly in software, they will often ask for [SOC 2](/services/grc-and-compliance/soc-2-preparation) rather than ISO 27001.
If you operate in an affected EU sector or supply one, [NIS2](/services/grc-and-compliance/nis2) may impose security and incident-reporting obligations on you directly.
If you sell into financial services in the EU, your customers may require evidence of alignment with [DORA](/services/grc-and-compliance/dora).
A provider can confirm which of these applies to you before you commit to anything, and help you sequence them if more than one is in your future.
Beyond certification: ongoing governance and risk
Not all compliance work ends with a certificate. Some organisations need help building the underlying governance: risk registers, security policies, supplier assessments, and the reporting that boards and auditors expect. Providers on Heelr can support the one-off certification push or the ongoing programme behind it. For the documentation layer specifically, see security policies. For preparing to be audited, see audit readiness and security audits.
How compliance work runs on Heelr
You describe the framework you need and your deadline. You receive proposals from verified professionals, or buy a fixed-scope package directly. Your payment is held securely and released only when you approve the delivered work. Because every provider is identity-verified and credential-checked, you are not gambling on an unknown name.
Common questions
What is the difference between GRC and compliance?
Compliance is meeting a specific requirement, such as passing an ISO 27001 audit. GRC, which stands for governance, risk and compliance, is the wider practice of managing security risk and governance in a structured way, of which certification is one part. Many companies start with a single compliance need and grow into a broader GRC programme as they scale.
Which compliance framework should we get first?
It follows your buyers and your regulators. UK companies often start with Cyber Essentials, companies selling internationally with ISO 27001, software companies selling to North America with SOC 2. A provider can confirm which applies before you spend anything.
Can one provider handle more than one framework?
Often yes. Many providers cover both ISO 27001 and Cyber Essentials, and some cover SOC 2 preparation alongside them. You can also engage different specialists for different frameworks.
Does the provider certify us?
No. Certification is issued by an independent certification body or auditor. The provider prepares you and gets you ready to pass. Keeping preparation and certification separate is how the standards are designed to work.
