Skip to content
ReadinessNavigator

Services

Service packages

Packages with defined deliverables, with scope confirmed before work begins. Available packages can be used on their own or as part of a bespoke engagement.

What we offer

Compliance built as an engineering discipline

Three principles guide every engagement: evidence you can defend, a plan built around your priorities, and results you can use independently.

Evidence, not checklists

We build proof an assessor accepts

A ticked box says you answered a question; an assessor wants artefacts. We assemble the threat models, component inventories, test records, and documentation that stand on their own — and every finding cites the requirement behind it, so you can defend it without us in the room.

  • Gap analysis mapped to every framework that applies
  • Threat models, component inventories, and test evidence, assembled
  • Documentation packaged the way an assessor will ask to see it

Sequence, not scramble

We start with what takes longest

Product gaps you can fix in a sprint; process evidence has to accumulate over weeks. We map the shortest defensible path for your product class and start that slow work early — while urgent product fixes proceed in parallel — tied to your release calendar, so the audit is calm rather than a scramble.

  • Remediation prioritised by security risk, deadlines, and dependencies
  • A plan sequenced against your releases, not a generic backlog
  • Audit dry-runs before the assessment that counts

Independence, not lock-in

No lock-in, with us or without us

Our assessments run entirely in your browser and ask nothing of you. Everything we produce in a bespoke engagement is yours to keep and carry forward. Your team can use the deliverables independently and continue the work with us or another partner.

  • Free assessments, scored in your browser
  • Bespoke deliverables are yours to keep and carry forward
  • Support through to sign-off — self-declaration or third-party audit

These principles guide our work throughout the delivery process below. We agree the scope of each engagement around your product and the support your team needs.

Discuss your product

Our delivery process

Five steps, tailored to your needs

The following steps describe our delivery process. We agree which activities are included in your engagement and the deliverables you will receive.

  1. 1

    Assess

    You run the relevant assessment, or we review the product with you. We identify initial gaps against the applicable requirements and discuss what needs closer examination before agreeing the work and its priorities.

  2. 2

    Scope

    We identify which requirements apply to your product, your development processes and your organisation, confirm the route to conformity where one applies, and set the boundaries of the work before anyone starts remediating.

  3. 3

    Remediate

    We prioritise process and technical gaps by security risk, applicable deadlines and dependencies. Work that needs time to produce evidence starts early, while urgent product fixes proceed in parallel, all tied to your release calendar.

  4. 4

    Evidence

    We assemble threat models, test records, component inventories, disclosure and update procedures into the documentation the applicable requirements call for. Each item is linked to its requirement, with gaps and responsibilities made visible for review.

  5. 5

    Certify

    We review the evidence against the applicable requirements, run a dry-run and close the findings. We then support your team through the relevant route to sign-off, whether self-declaration or third-party certification is required.

Bespoke support

Adapt the lifecycle to the way your team works

Beyond the defined package, we can build a secure development process with your team or adapt the release, quality and safety processes you already run. Product-specific implementation and audit support are scoped as a bespoke engagement; they are not included in the Secure SDLC package.

AI-assisted evidence workflows can be part of that engagement. They may draft records and flag drift, but named people review and approve the evidence, and product verification remains independent of implementation. Tool access, confidentiality and data handling are agreed before any onboarding.

Discuss a bespoke engagement

Get in touch

Tell us where you are today

Describe your product, the requirements in view and what you would like help with. We will come back with the package or engagement that fits, and a sensible starting point.

We reply within two working days.

Full contact details
consulting@readinessnavigator.com
Book a 30-minute call

Opens our scheduling page in a new tab — pick a slot that suits you.

Worth including in a first message

  • What you build, and how many product lines are in scope.
  • Which regulations, standards or customer requirements are in view.
  • What is driving the timeline — customer requirement, audit, or CRA deadline.
  • Which package or engagement you are interested in.

Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.