
Radiatus GRC
Our governance, risk and compliance platform for HIPAA, ISO 27001 and SOC 2 programmes.
- Guided risk assessment and risk register
- Policy, evidence and vendor (BAA) management
- Incident tracking, training and reporting
We prepare you for ISO 27001, SOC 2, HIPAA, GDPR and PCI DSS by improving your actual security, not just your paperwork, then support you through the audit.
Enterprise buyers ask for a SOC 2 report before they sign. Healthcare partners need HIPAA safeguards before they share patient data. EU customers expect GDPR compliance. Without the right attestation, deals stall in security review.
But the certificate is evidence, not the goal. We focus on controls that genuinely reduce risk (access, logging, patching, backups, secure development) and then document them so an auditor can verify them. That way the audit is a formality and you are actually harder to breach afterwards.
The controls overlap heavily, so we build one control set and map it to each framework you need.
The international standard for an Information Security Management System. We help define scope, build the risk method and Statement of Applicability, implement Annex A controls and run internal audits before the certification body arrives.
Our ISO 27001 compliance serviceReports on your controls against the Trust Services Criteria (Security, plus Availability, Confidentiality, Processing Integrity and Privacy where relevant). We define controls, automate evidence and work alongside your CPA auditor.
Our SOC 2 readiness serviceSecurity and Privacy Rule compliance for covered entities and business associates: risk analysis, PHI data mapping, policies, BAAs, breach procedures and workforce training.
Our HIPAA compliance serviceRecords of processing, data protection impact assessments, lawful basis and consent design, and data subject request workflows that do not overwhelm your team.
Our GDPR readiness serviceScoping and shrinking the cardholder data environment, network segmentation, logging and the technical testing PCI DSS requires, ahead of your QSA assessment or self-assessment questionnaire.
Our security & compliance serviceReadiness for India's Digital Personal Data Protection Act through our sister cybersecurity practice, SemperWise, alongside CERT-In and sector rules where they apply.
DPDP readiness at SemperWiseEvery engagement follows the same four stages. Timelines depend on your scope and starting point; we give you a realistic plan after the gap assessment.
We assess your current posture against the target framework, identify every gap and rank them by risk and effort.
A prioritised roadmap: policies to write, controls to implement, tools to deploy and training to deliver, with owners.
We work hands-on with your team on technical controls such as encryption, access management and logging, plus penetration testing to prove they work.
We assemble the evidence pack, run a mock audit, and support you through the real one by answering auditor questions with technical context.
Concrete outputs you keep, whether or not you continue working with us.
For a deeper look at the ISO path, read ISO 27001 readiness: what actually gets you certified. Running on AWS with health data? See building HIPAA-aligned workloads on AWS.
Readiness is a project; staying compliant is ongoing. Two products from the Radiatus family help with that.

Our governance, risk and compliance platform for HIPAA, ISO 27001 and SOC 2 programmes.

Our AI-first cybersecurity practice and SemperWise One™ platform for testing and compliance automation.
We configure the controls in your cloud and code, not just recommend them in a report.
Evidence collected from your systems automatically, so staying compliant is not a quarterly scramble.
Internal audits, retests and renewal support after the first certificate.
No. ISO 27001 certificates are issued by accredited certification bodies, and SOC 2 reports by independent CPA firms. Radiatus prepares you for that audit: gap analysis, controls, policies, evidence and support while the auditor is on site.
It depends on scope and starting point. A small organisation with good engineering hygiene can be ready in a few months; larger scopes take longer. SOC 2 Type II also needs an observation period, commonly three to twelve months, during which controls must operate consistently.
Type I assesses whether your controls are designed appropriately at a point in time. Type II assesses whether they operated effectively over a period. Many companies start with Type I and move to Type II once controls have run for a while.
Usually the one your customers or regulators are asking for. US enterprise buyers often ask for SOC 2, international and public-sector buyers for ISO 27001, and healthcare partners for HIPAA. Because the controls overlap heavily, work done for one carries over to the next.
Yes. Most frameworks expect evidence of technical security testing. We run VAPT for web, API, mobile, cloud and network, and our sister practice SemperWise offers continuous pentesting with a verifiable assessment certificate.
Compliance has to be maintained. We can keep evidence current in the Radiatus GRC platform, run periodic internal audits and retests, and support surveillance or renewal audits.
Tell us who is asking for it. A senior engineer will recommend a starting point and a realistic plan.