Skip to content
Home / Services / Compliance
Pillar III · Governance

Compliance & Audit

Navigate complex regulatory landscapes with expert guidance in IT audit, governance, risk management, and compliance — PCI-DSS, ISO 27001, SOC 2, LGPD/GDPR, and BACEN on a single page.

Overview

Berghem's Compliance and Governance pillar covers the entire regulatory cycle — from the IT audit that identifies the current state, to GRC consulting that structures the program, to gap analysis that prioritizes remediation, to regulatory testing that proves adherence before an external auditor or QSA.

We don't work with paper checklists. Each engagement delivers measurable posture, auditable evidence, gap-based roadmap, and sign-off ready for the main frameworks: PCI-DSS, ISO 27001, SOC 2, LGPD/GDPR, BACEN, and sector regulations.

Everything included

IT Audit — infrastructure, access, data, and BCP
GRC Consulting — governance, risk, and compliance
Gap Analysis — ISO 27001, PCI-DSS, SOC 2
LGPD/GDPR compliance and BACEN regulations
Regulatory pentest PCI-DSS and SWIFT CSP
Prioritized roadmap and QSA/auditor sign-off
Module 01 · Program

Diagnosis and Governance

Comprehensive audit of the current state and structuring of the governance, risk, and compliance program — foundation for any sustainable regulatory initiative.

ISO 27001 · BCP · Access

IT Audit

Comprehensive assessment of infrastructure, controls, and processes against industry standards and regulatory requirements — infrastructure and network audit, access control review, data protection, and business continuity assessment.

Governance · Risk · Compliance

GRC Consulting

Governance, risk management, and compliance aligning the security program with business objectives — governance framework, risk assessment, policy and procedure development, and complete compliance program design.

Module 02 · Frameworks

Adequacy and Validation

Gap identification against target frameworks and regulatory testing that produces the evidence required by external auditor, QSA, or regulator — from prioritized diagnosis to sign-off.

ISO · PCI · SOC 2 · LGPD · GDPR

Gap Analysis

Gap identification between current posture and target frameworks, with actionable and prioritized remediation plans — ISO 27001, PCI-DSS readiness, SOC 2 preparation, and LGPD/GDPR compliance review, with timeline and effort estimates.

PCI-DSS · SWIFT CSP · BACEN

Regulatory Testing

Specialized pentests and security assessments to meet specific regulatory and compliance requirements — PCI-DSS penetration testing, SWIFT CSP assessment, BACEN compliance testing, and sector regulatory testing with QSA sign-off.

Frequently Asked Questions

What compliance frameworks does Berghem cover?
Berghem provides testing and audit services for PCI-DSS (all SAQ types and ROC), ISO 27001 (gap analysis and readiness), LGPD (Brazil's data protection law), GDPR (EU data protection), SOC 2 Type I and Type II, SWIFT CSP, and the EU AI Act. We also support organizations pursuing multiple certifications simultaneously through integrated audit programs that reduce duplication and accelerate timelines.
How long does a compliance gap analysis take?
A compliance gap analysis typically takes two to six weeks depending on the framework, organizational size, and scope. PCI-DSS gap analysis for a focused cardholder data environment may take two to three weeks, while a comprehensive ISO 27001 readiness assessment for a large organization may require four to six weeks. Berghem delivers a prioritized findings report with remediation recommendations and an estimated timeline to certification readiness.
Can Berghem help achieve PCI-DSS certification?
Berghem provides comprehensive PCI-DSS support including scope definition, gap analysis, remediation guidance, penetration testing (required by PCI-DSS Requirement 11.3), and pre-assessment validation. While Berghem is not a Qualified Security Assessor (QSA), we prepare organizations thoroughly for the formal QSA audit, significantly increasing first-pass certification success rates. Our financial sector expertise means we understand the nuances of cardholder data environments in banking and fintech.
Do you perform third-party risk assessments?
Yes. Berghem evaluates the security posture of your vendors, partners, and service providers through structured third-party risk assessments. This includes vendor security questionnaire analysis, external attack surface evaluation, compliance verification, and risk scoring. For organizations using AI services from third parties, we also assess AI-specific risks including data handling, model security, and regulatory compliance of AI vendors.

Ready to get started?

In a 30-minute conversation, we'll map your regulatory landscape and design the ideal scope — from initial diagnosis to full certification.

Contact Us