COMPLIANCE HANDLED.
YOUR ENGINEERS STAY ON FEATURES.

SOC examination readiness, ISO 27001 ISMS certification readiness, and GDPR remediation support for operational legacy environments. We embed with your team, take the engineering workload, and hand back a remediated environment with audit-ready evidence — while your roadmap keeps moving.

THE AUDIT IS COMING.
YOUR ROADMAP DOESN'T CARE.

Enterprise buyers, auditors, regulators, and boards now demand evidence: support for SOC examinations, an ISO 27001-conformant ISMS, and demonstrable GDPR controls. For teams running operational legacy systems, that evidence is expensive — and the people who must produce it are the same people who ship your product.

  1. /01

    Evidence lives in systems nobody wants to touch.

    Legacy environments weren't built for audit trails, access reviews, or data mapping — retrofitting them is real engineering work, not paperwork.

  2. /02

    Compliance work cannibalizes feature work.

    Every senior engineer reassigned to remediation is a feature that doesn't ship. The opportunity cost compounds every sprint.

  3. /03

    Deadlines are external and non-negotiable.

    Enterprise deals, certification windows, and regulator timelines don't move because your backlog is full.

COMPLIANCE REMEDIATION SERVICES.

WHAT WE TAKE OFF YOUR PLATE.

/02

ISO 27001 ISMS implementation and readiness

For
Organizations implementing or strengthening an ISMS for ISO/IEC 27001 certification.
Work
Translate identified gaps into technical controls, traceable procedures, and operational evidence.
Deliverables
A remediation backlog, control implementations, evidence workflows, and handover documentation.
Dependencies
Your defined ISMS scope, risk decisions, accountable owners, and certification-body requirements.
Boundary
werkwerk prepares the environment and evidence; an accredited certification body makes the certification decision.
ISO/IEC 27001 · ISMS · READINESS
/03

GDPR control-gap remediation

For
Teams that need technical and operational remediation around personal-data processing.
Work
Support data mapping, implement agreed privacy controls, and make control operation traceable.
Deliverables
Technical remediation, processing documentation inputs, evidence workflows, and implementation records.
Dependencies
Your processing inventory, legal interpretation, risk decisions, and accountable privacy stakeholders.
Boundary
werkwerk implements agreed technical measures and does not provide legal opinions or determine legal compliance.
GDPR · PRIVACY · REMEDIATION

Supporting engineering capabilities

Engineering disciplines used to make controlled change repeatable, traceable, and maintainable.

/04

Software quality engineering

Test strategy, automation, and quality gates that produce repeatable evidence for controlled releases.

/05

Enterprise content management

Retention, access control, and governed records that support reliable retrieval and review.

/06

Software requirements engineering

Traceable, testable requirements connecting business intent, implementation, verification, and evidence.

/07

AI-enabled business processes

Secure workflows using AI agents with human oversight, defined controls, and traceable decisions.

EMBEDDED COMPLIANCE ENGINEERING.

WE EMBED. WE REMEDIATE. YOU SHIP.

werkwerk is not a staffing agency or an auditor. Our remediation team works inside your development and operations environment, implementing agreed controls and evidence workflows in your tools and codebase. Your team reviews the work, retains decision-making authority, and keeps its capacity focused on the product roadmap.

- seniors reassigned to audit prep

+ seniors on the product roadmap

- compliance as a quarterly panic

+ compliance as a background process

- consultants writing recommendations

+ engineers shipping remediations

TECHNOLOGY ENVIRONMENTS WE SUPPORT.

Tools and platforms in which we implement and document controlled change:

  • .NET
  • PHP
  • SQL Server
  • MySQL
  • PostgreSQL
  • Node
  • Angular
  • Svelte
  • React
  • Azure
  • AWS
  • Nebius
  • STACKIT
  • ELO
  • Mistral AI

OUR COMPLIANCE REMEDIATION PROCESS.

FOUR PHASES. NO SURPRISES.

  1. 01

    ASSESS

    Gap analysis against your target framework. You get a findings register with effort estimates — a real plan, not a slide deck.

  2. 02

    REMEDIATE

    Our engineers implement controls, fix findings, and build evidence pipelines inside your environment, in priority order.

  3. 03

    VERIFY

    Readiness validation against the agreed criteria. We review control operation and address remaining gaps before independent assessment.

  4. 04

    HANDOVER

    Documentation, runbooks, and training so your team owns compliance as a routine — not a dependency on us.

Then the auditors show up, and it's boring. That's the point.

COMPLIANCE ENGINEERING FAQ.

What does compliance remediation include?

Compliance remediation turns identified control gaps into implemented technical and operational changes. Depending on scope, that can include access controls, change-management safeguards, evidence collection, data mapping, documentation, testing, and handover. The exact work is agreed from the target framework, system boundaries, existing findings, and the responsibilities retained by your team.

What does SOC 2 readiness support include?

SOC 2 readiness support can include assessing gaps against the applicable Trust Services Criteria, implementing agreed controls, establishing repeatable evidence collection, and preparing documentation for review. Your organization defines scope and owns its controls. An independent CPA firm performs the examination and determines whether it can issue a SOC report.

Does werkwerk perform the SOC examination?

No. werkwerk provides engineering remediation and readiness support but does not perform the independent SOC examination or issue a SOC report. We implement agreed changes and prepare evidence in coordination with your team and, where appropriate, the independent CPA firm responsible for the examination.

Can werkwerk certify an ISO 27001 ISMS?

No. werkwerk can support ISMS implementation, technical remediation, evidence workflows, and certification preparation. Certification is performed by an accredited certification body, which independently assesses the defined scope and decides whether to issue certification.

How do you work with legacy production systems?

We begin with the system as it operates today rather than assuming a greenfield replacement. Changes are prioritized around risk, operational constraints, and the target control. We work within existing tools and release practices, add traceability and safeguards where needed, and document decisions so the resulting controls remain maintainable.

What deliverables does an engagement produce?

Deliverables depend on scope and can include a prioritized findings register, implemented controls, evidence workflows, test assets, operating procedures, implementation records, and handover materials. The engagement definition identifies which artifacts werkwerk produces, which decisions remain with your organization, and what an auditor, certification body, or legal adviser must assess independently.

Does werkwerk provide legal advice on GDPR?

No. werkwerk supports the technical and operational implementation of agreed privacy requirements. Legal interpretation, lawful-basis decisions, and formal conclusions about GDPR compliance remain with your organization and qualified legal or privacy advisers.

Which languages and working model are available?

werkwerk works in English and German. Engagements are embedded and collaborative: work is carried out with your responsible engineering, operations, security, and privacy stakeholders in the tools and codebases relevant to the agreed scope.

YOUR AUDIT DEADLINE IS ALREADY MOVING.
SO SHOULD YOU.

Tell us your framework and your deadline.