What we do
Forged Compliance is an independent cybersecurity compliance consultancy. We scope, build and audit security programmes against ISO 27001, SOC 2, NIST CSF, NIST 800-171 / CMMC, PCI DSS, GDPR, NIS2 and DORA, provide virtual CISO leadership, and write the documentation that underpins all of it. That documentation is also sold directly, as complete editable sets, for organisations that have the expertise in-house and only need the writing done.
Why this exists
Most organisations meet compliance through a general IT or cyber firm that treats the standard as an add-on. The result is a binder of policies nobody follows, controls chosen from a template rather than a risk, and a certificate that wobbles at the first surveillance visit. We built Forged Compliance to work the other way round: start from the requirement and the real risk, build a system the team can run, and write documentation that describes what actually happens.
The documentation business follows from that. The generic 80% of any policy set is the same for every organisation aligning to the same framework, and it should be written once, properly, by someone who has sat through the audit. The remaining 20% is yours: your systems, your roles, your tools. On an engagement we do that part with you; if you buy the sets, you do it yourselves.
How we work
- Written by practitioners. The people who write and review these sets have implemented and audited against the frameworks they cover.
- Kept current. Framework editions and regulations change. We revise sets when they do and push updates to customers within their update period.
- Fixed scope. Engagements are proposed with deliverables, timeline and price up front. We do not sell open-ended day rates unless asked.
- Independent. We prepare you for certification and sit with you through it, but we do not certify you. That separation is what keeps your certificate credible.
- Plain language. The documents are meant to be read by the people who have to follow them, not only by the assessor.
Certified expertise
Every engagement is led by qualified practitioners. Forged Compliance maintains certifications across security, audit, cloud and infrastructure:
Security, audit & governance
- CISSP
- CISA
- ISO 27001 Lead Auditor
- CISMP
- CompTIA CySA+
- CompTIA Security+
- EXIN ISO 27001
Cloud, infrastructure & networking
- CompTIA Cloud+
- CompTIA Cloud Essentials
- EXIN Cloud Computing
- CompTIA Server+
- Cisco CCNA
- Cisco CCT
CompTIA stackable certifications
- CompTIA CSIS
- CompTIA CSCP
- CompTIA CIOS
- CompTIA CCAP
- CompTIA CNIP
IT service management & foundations
- ITIL V3 Foundations
- CompTIA A+
- CompTIA ITF
- CompTIA ITF+
The name
Forging is shaping something durable from raw material with heat and effort, then tempering it so it holds an edge without shattering. That is roughly what good documentation is: shaped to a standard, tempered by use, and expected to last.
Company details
Forged Compliance is a trading name of [Company legal name], registered in [jurisdiction] under company number [number]. Registered office: [address]. VAT number: [VAT number].
General enquiries: hello@forgedcompliance.com
Orders and invoices: orders@forgedcompliance.com
Privacy and data protection: privacy@forgedcompliance.com