Six pre-packaged programmes built around the most common regulatory challenges we see. Every programme has a defined scope, timeline, and price — so you can plan with confidence.
GDPR-ready in 8 weeks.
A structured programme for organisations that need to establish a compliant privacy framework from the ground up — or fix an existing one that won't pass scrutiny.
Certified in 4 months.
Everything needed to achieve ISO 27001:2022 certification — from gap analysis through to external audit, with Dutient managing the certification body relationship.
Compliant before enforcement.
A focused programme to classify your AI systems, assess risk exposure under the EU AI Act, and implement the governance controls required for each risk tier.
Expert oversight, flexible commitment.
A senior Data Protection Officer embedded in your organisation on a fractional basis — handling regulatory queries, DPIAs, breach management, and board reporting.
One programme. Dual certification.
Achieve GDPR compliance and ISO 27001 certification together — sharing evidence, policies, and audit activities across both standards for maximum efficiency.
Built around your reality.
Not every organisation fits a standard programme. We design bespoke engagements — from multi-jurisdiction privacy transformations to sector-specific AI governance frameworks.
Yes — every programme is a starting point. We scope the exact deliverables with you before any contract is signed, so there are no surprises mid-engagement.
Fixed-fee for every packaged programme. You know the cost before we start. Certification body fees are included where listed.
Yes, and often it's more efficient to do so. Our Privacy + Security Bundle is specifically designed for this. We'll advise on the optimal sequencing.
We offer maintenance retainers from Month 3 of any programme. Many clients move from a project engagement to an ongoing advisory relationship.
Book a free 30-minute scoping call. We'll map your obligations and recommend the right starting point.
Book a Free Scoping Call