Skip to main content
NexITC
C6 · CYBERSECURITY · 12-MONTH MIN · RUN

Continuously audit-ready.
Not audit-scrambling.

C6 · ComplianceOps™ UAE is NexITC's managed compliance evidence operations retainer for UAE regulated organisations subject to PDPL, ISR, ADHICS v2, MoF/FTA eInvoicing, and internal governance obligations. Not an audit-cycle scramble. Not a one-time controls implementation. A 12-month subscription running monthly evidence refresh, control verification, exception governance with SLA enforcement, and audit-cycle export packaging — with Practice Lead — Cybersecurity as named account owner. Regulated organisations often run C6 in parallel with [[C7|C7 SecOpsCommand™]] for the full continuous security-and-compliance posture.

COMMITMENT
12 mo min
SERVICE ELEMENTS
5 named
COMMERCIAL
Retainer
C6·PROJECTION / EVIDENCE COMPLETENESS
C6
BASELINE
62%
EVIDENCE COMPLETENESS · POST-AUDIT DECAY
C6
TARGET
≥92%
EVIDENCE COMPLETENESS · STEADY STATE
ONBOARD
BASELINE
STEADY
REVIEW
PDPL / ISR
SUSTAINED
ADHICS v2
GOVERNED
EXCEPTION SLA
ENFORCED
SCENARIO · UAE HEALTHCARE · N=1
ILLUSTRATIVE
§ 00 · THESIS
01
WHY COMPLIANCE EVIDENCE DEGRADES
IN THE MONTHS BETWEEN AUDITS.

Every UAE compliance officer we have engaged with has passed their initial implementation — PDPL policies documented, ISR controls in place, ADHICS v2 mappings signed off. What is rarely present six months later is the specific evidence trail proving those controls are still operating: the specific access review conducted last month, the specific exception with named remediation ownership past its aging SLA, the specific PDPL processing record refreshed against actual system state. Compliance implementation is an event; compliance operations is a discipline. Evidence generated at audit time is evidence assembled — the auditor's job then becomes forensic reconstruction, not audit validation.

The instinct is to hire consultants at audit time to reconstruct the evidence. The instinct treats compliance as a periodic event. What produces sustained audit-readiness is the operating cadence between audits — monthly evidence refresh, control verification with named owners, exception governance with SLA enforcement per severity class, audit-cycle export packaging maintained continuously. C6 does that work as a 12-month subscription. Continuously audit-ready, not audit-scrambling — and the honest position is that the retainer only makes sense if evidence generation is treated as a control expectation, not an audit expense. Evidence assembled at audit time costs three ways: reconstruction consultancy, opportunity cost during business quarter freeze, and the reputational risk of findings the sustained posture would have prevented.

STATE · AUDIT-CYCLE
Compliance implementation complete. Evidence degradation begins within 3 months. Exceptions accumulate without governance. Access reviews scheduled but rarely conducted. Annual audit triggers 6-8 week evidence reconstruction consultancy. Business quarters interrupted by audit preparation.
STATE · CONTINUOUSLY-READY
Monthly evidence refresh operating. Exception governance with SLA per severity class. Access reviews conducted monthly with named owners. Audit-cycle exports assembled continuously — audit becomes verification, not reconstruction. Business quarters uninterrupted by audit preparation.
§ 01 · OPERATING STREAMS

Six operating streams,
running on monthly cadence.

Six operating streams sequenced across onboarding (M 01), baseline period (M 02-03), and steady state operations (M 04+). Each stream has named cadence, SLA commitment, and Practice Lead accountability.

STREAM 01
MONTHLY

Evidence refresh cadence

Monthly evidence generation against the mapped control library — access reviews, log samples, configuration snapshots, PDPL processing records, ADHICS v2 evidence artifacts. Not reactive assembly at audit time — active generation with named cadence and completeness SLA.

STREAM 02
MONTHLY

Control verification with named ownership

Named control owners perform monthly verification against evidence produced by Stream 01. Verification failures generate exceptions routed through Stream 03. Not compliance-team assembly — operations discipline embedded in existing accountability structures. Evidence generated but never verified is documentation, not compliance.

OUTCOME
SUSTAINED
AUDIT-READY POSTURE
+ EXCEPTIONS GOVERNED
STREAM 03
MONTHLY

Exception governance with SLA enforcement

Exceptions surfaced from control verification governed by SLA per severity class. Exception aging tracked with named remediation ownership; chronic exceptions escalated. Not exception logs for audit — active governance that prevents exception accumulation. This is where most retainers do the load-bearing work.

STREAM 04
QUARTERLY

Audit-cycle export packaging

Audit exports maintained continuously — evidence packages assembled quarterly for internal governance review, ready for external audit at any time. Auditors receive verification-ready packages, not reconstruction consultancy. Audit-cycle preparation becomes a lookup, not an expedition.

STREAM 05
MONTHLY

Regulatory framework tracking

Framework changes tracked across PDPL, ISR, ADHICS v2, MoF/FTA eInvoicing (where applicable), and internal governance requirements. Framework revisions mapped to control library updates within 30 days of published change. Not annual review — continuous monitoring with named ownership.

STREAM 06
MONTHLY

Executive scorecard & review

Monthly executive scorecard (evidence completeness %, exception aging by severity, audit findings trend, framework alignment) with named target trajectories. Direct monthly review with compliance leadership and executive sponsor. Board-defensible reporting cadence for regulated organisations.

EXPLICITLY NOT COVERED
Initial compliance implementation
That's B8 Controls Implementation Build™ — fixed-scope Cybersecurity build for PDPL/ISR/ADHICS v2 control library establishment. C6 operates the compliance posture you have implemented; B8 builds the compliance foundation. Sequence: A3 → B8 → C6 for the full cycle.
One-time compliance gap assessment
That's A3 Compliance Fast-Track™ UAE — 3-week compliance posture baseline with 90-day plan. A3 baselines what needs closing; C6 operates what's in place.
Security operations management
That's C7 SecOpsCommand™ — managed security operations retainer for MTTA, playbook execution, vulnerability governance, and drills. C6 operates compliance evidence; C7 operates security controls. Regulated organisations often run both in parallel.
Blockchain-enabled provenance operations
That's D2 ProvenanceOps™ Subscription — Expand-tier subscription for verification-grade integrity operations across supply chain, compliance evidence chain-of-custody, and multi-party trust. C6 handles standard compliance evidence; D2 layers integrity operations where verifiable chain-of-custody matters.
§ 02 · ANNUAL CADENCE

Twelve-month subscription.
Three lifecycle stages.

The retainer runs for 12 months minimum with three lifecycle stages: onboarding (M 01), baseline period (M 02-03), and steady state operations (M 04-12) with the annual review gating renewal. Monthly cadence and SLA commitments are steady from M 02 onward.

Q 01Q 02Q 03Q 04Phase 1 · OnboardingPhase 2 · Steady state operationsPhase 3 · Annual reviewOnboarding complete · baseline capturedEND M 01 · GATE 01Annual review begins · renewal scopedEND M 11 · GATE 02Annual renewal decisionEND M 12 · GATE 03OPERATING RHYTHMMonthly evidence refresh + control verification + exception review · Quarterly audit-cycleexport + governance review · Annual reviewNAMED ACCOUNTABILITYPractice Lead — Cybersecurity (CEO escalationavailable)
§ 03 · OPERATING MODEL

Compliance evidence,
run on cadence not calendar-scramble.

Every C6 subscription follows a fixed operating model tuned to your regulatory scope in the first month. Not a compliance implementation; not a periodic audit exercise. The rhythm that produces sustained evidence completeness, exception governance, and audit-cycle readiness across the 12-month cadence.

OPERATING MODEL · SIX ELEMENTS
CADENCE · SLA · SIGNED
This is the operating model applied on every C6 retainer — adapted to your regulatory scope (PDPL / ISR / ADHICS v2 / MoF-FTA / internal governance) and existing compliance tooling, not reinvented per subscription.
01
Onboarding: control library mapping (M 01)
Existing control library inventoried against regulatory scope. Evidence-generation cadence established per control class. Named control owners identified across the organisation. Baseline evidence completeness captured against target trajectory. First monthly executive scorecard delivered at end of onboarding.
02
Evidence refresh discipline with named ownership
This is where most retainers do the load-bearing work. Evidence generated at audit time is evidence assembled — the auditor's job then becomes forensic reconstruction, not audit validation. C6 maintains monthly evidence refresh cadence with named control owners performing verification. Evidence completeness treated as SLA commitment, not documentation task.
03
Exception governance with SLA per severity class
Exceptions surfaced from control verification governed by SLA per severity class (critical / high / medium / low). Aging exceptions surfaced monthly with named remediation ownership and rationale for exception. Chronic exceptions escalated to executive sponsor with named remediation path.
04
Audit-cycle export packaging maintained continuously
Audit exports assembled quarterly for internal governance review, ready for external audit at any time. Not reactive assembly at audit time — continuous packaging discipline. Auditors receive verification-ready packages; audit becomes lookup, not expedition.
05
Regulatory framework tracking
Framework changes tracked across regulatory scope with 30-day mapping SLA. PDPL, ISR, ADHICS v2, MoF/FTA (where applicable), and internal governance revisions mapped to control library updates within named cadence. Not annual review — continuous monitoring with named ownership.
06
Monthly review with compliance leadership
Monthly scorecard delivered with named target trajectories per KPI. Direct review with compliance leadership and executive sponsor. Board-defensible reporting cadence for regulated organisations. Reviews that never happen produce retainer cost without operational value — attendance is treated as SLA commitment.
!
DISCLOSURE · INDEPENDENCE
C6 is a managed evidence operations retainer, not a GRC platform selection or reseller relationship. The subscription operates against your existing compliance tooling — no platform swap, no vendor pre-selection. NexITC works across GRC platforms, evidence-automation vendors, and audit tools without vendor economics gating operational choices. In practice, we have identified evidence-generation improvements that use native platform features rather than third-party additions, and we have surfaced tooling gaps whose closure is best delivered by internal teams rather than any consulting engagement.
§ 04 · BASELINE VS MANAGED

From audit-cycle reconstruction
to continuous evidence operations.

A typical pre-engagement state has compliance implementation complete, evidence degrading within the months between audits, and 6-8 week reconstruction consultancy triggered by annual audit. The subscription produces the operating cadence under which evidence completeness, exception aging, and audit-cycle readiness sustain measurably — not manufactured findings, not tooling upgrade recommendations.

BASELINE · M 01
TYPICAL STATE
STATE_01
Compliance implementation complete
IMPLEMENTED · NOT SUSTAINED
STATE_02
Evidence completeness degrading month-over-month
3-MONTH DECAY PATTERN
STATE_03
Access reviews scheduled, rarely conducted
CALENDAR ITEM ONLY
STATE_04
Exceptions accumulating without governance
AGING UNMANAGED
AUDIT ANSWER
'We are in the middle of the audit-cycle scramble' — 6-8 week reconstruction consultancy at audit time
OPERATIONAL REALITY
  • Business quarters interrupted by 6-8 week audit preparation scramble
  • Evidence reconstruction consultancy engaged periodically (three-figure daily rates)
  • Aging exceptions accumulate without governance escalation until audit surfaces them
  • Framework revisions (PDPL, ADHICS v2) tracked annually rather than continuously
C6 · CADENCE
MANAGED · M 04+
STEADY-STATE
PLATFORM_01
4-KPI Operating Cadence
Evidence Completeness · Exception Aging by Severity · Audit Findings Trend · Framework Alignment — Measured Monthly with Named Target Trajectories
PLATFORM_02
Governance & Named Accountability
Monthly Evidence Refresh · Control Verification with Owners · SLA-Enforced Exception Governance · Quarterly Audit-Cycle Exports · Practice Lead — Cybersecurity Owns Cadence
↓ ONBOARDED · MAPPED · GOVERNED · MEASURED ↓
GRC TOOLING · UNCHANGED
C6 operates what you have — no platform swap, no vendor pre-selection. The subscription runs against your existing GRC/evidence-automation tooling with monthly SLA enforcement
STEADY-STATE OUTCOME
  • Evidence completeness sustained above 92% continuously (not periodically)
  • Exception aging governed by SLA per severity class with named remediation ownership
  • Audit-cycle preparation reduces from 6-8 weeks to 2-day export exercise
  • Framework revisions mapped to control library updates within 30-day SLA

Reference pattern. Some subscriptions surface that the compliance implementation is stronger than assumed and the leverage sits on evidence discipline rather than framework re-mapping — the honest output is 'the control library is right; the retainer's job is discipline not implementation.' That's a legitimate finding, not a failure to justify implementation upgrades. The alternative is manufacturing framework-gap findings to sell re-implementation work the compliance team doesn't need — which erodes the sustained-posture advisor role the retainer requires.

§ 05 · REPRESENTATIVE SCENARIO

A UAE healthcare group,
evidence completeness sustained above 92% continuously.

Representative pattern for a UAE healthcare group that had passed initial ADHICS v2 implementation but experienced evidence degradation within 3 months, with annual audit surfacing 12 aging exceptions past SLA. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.

SCENARIO / C6 / UAE HEALTHCARE · CONTINUOUS COMPLIANCE
COMMITMENT · 12 MO
EVIDENCE COMPLETENESS
92%+
Baseline 62% → Steady state ≥92%
EXCEPTION AGING
<30days
Aging past SLA reduced across all severity classes
AUDIT CYCLE
2 DAYS
From 6-8 week reconstruction to lookup exercise
SITUATION

A UAE healthcare group had passed initial ADHICS v2 implementation and internal PDPL controls establishment 18 months prior. Evidence completeness had degraded to 62% by month 4, with access reviews scheduled quarterly but rarely conducted, control verification largely paper-based with unclear ownership, and 12 exceptions past SLA accumulated across critical/high severity classes. Annual audit had triggered 8-week reconstruction consultancy at three-figure daily rates. Compliance leadership under pressure from board about sustainability of the compliance investment.

ENGAGEMENT

12-month C6 subscription. Onboarding (M 01): existing control library inventoried against ADHICS v2 + PDPL scope, evidence-generation cadence established per control class, named control owners identified across clinical operations / IT / HR / procurement, baseline evidence completeness captured (62% overall, 45-88% by control class). Baseline period (M 02-03): monthly evidence refresh cadence launched, control verification workflows deployed with named owners, exception governance workflow with SLA per severity class established. Steady state (M 04+): monthly evidence refresh operating across all mapped controls, control verification with named ownership, exception governance with monthly aging review and named remediation, quarterly audit-cycle export packaging assembled, monthly executive scorecard delivered to compliance leadership and executive sponsor.

OUTCOME

Evidence completeness sustained above 92% continuously by end of Q2, above 95% by end of Q3. Exception aging past SLA reduced from 12 exceptions to 0 by end of Q2 across critical/high severity classes; medium/low classes governed within named SLA thresholds. Annual audit-cycle preparation reduced from 6-8 week reconstruction consultancy to 2-day export exercise. Auditor findings dropped to zero critical/high in the following annual audit. Healthcare group renewed C6 for year 2 with expanded scope to include a newly-acquired clinical operations unit; began parallel C7 SecOpsCommand™ engagement for continuous security operations.

§ 06 · SERVICE ELEMENTS

Five service elements,
each with monthly SLA cadence.

Every service element has documented SLA commitment, monthly delivery cadence, and named Practice Lead accountability. Not one-time deliverables — recurring operational outputs.

E_01

Monthly Evidence Refresh

Monthly evidence generation against the mapped control library — access reviews, log samples, configuration snapshots, PDPL processing records, ADHICS v2 evidence artifacts. SLA: evidence completeness ≥92% by end of Q2, sustained through steady state.

E_02

Control Verification with Named Ownership

Named control owners perform monthly verification against evidence produced by E_01. Verification failures generate exceptions routed to E_03. SLA: 100% control coverage verified monthly; verification failures escalated within 5 business days.

E_03 · CORE

Exception Governance with SLA per Severity Class

Exceptions governed by SLA per severity class (critical / high / medium / low). Exception aging tracked with named remediation ownership; chronic exceptions escalated. SLA: critical/high exceptions closed within 30 days; medium within 60; low within 90; aging exceptions escalated monthly.

E_04

Audit-Cycle Export Packaging

Audit exports maintained continuously — evidence packages assembled quarterly for internal governance review, ready for external audit at any time. SLA: audit-cycle export assembled within 2 business days of request; internal governance review packages delivered quarterly on named schedule.

E_05 · MONTHLY SCORECARD

Executive Scorecard & Framework Tracking

Monthly executive scorecard covering evidence completeness %, exception aging by severity class, audit findings trend, and framework alignment status — with named target trajectories per KPI. Delivered with direct monthly review with compliance leadership and executive sponsor. Integrated with regulatory framework tracking across PDPL, ISR, ADHICS v2, MoF/FTA (where applicable), and internal governance requirements — with framework revisions mapped to control library updates within 30-day SLA. The board-defensible reporting cadence for regulated organisations that answers 'are we still audit-ready today?' with specific evidence — and the framework tracking discipline that ensures the answer stays yes as regulations evolve.

CADENCE
MONTHLY
§ 07 · OUTCOMES

Six outcome metrics,
measured baseline to steady state.

Success is not "the subscription is running." It is measured against six specific outcomes captured at onboarding baseline (M 01) and re-measured monthly with target trajectory through steady state (M 04+).

THE EVIDENCE-COMPLETENESS JOURNEY · REPRESENTATIVE
Sixty-two percent to ninety-two, across the year.
≥92%COMPLETENESS ↑
100%75%50%25%062%BaselineM 01 (ONBOARDING)72%Baseline establishedM 03 (BASELINE)85%Q2 improvementM 06 (STEADY)≥92%Q3 targetM 09 (STEADY)
01 · EVIDENCE COMPLETENESS
SUSTAINED
Completeness measured monthly against target trajectory (baseline → steady state).
02 · EXCEPTION AGING
SLA-MANAGED
Aging governed per severity class with named exception ownership.
03 · AUDIT FINDINGS
TRENDING ↓
Findings trend measured across annual audit cycles; target zero critical/high.
04 · FRAMEWORK ALIGNMENT
CURRENT
Framework revisions mapped to control library updates within 30-day SLA.
05 · AUDIT CYCLE EFFORT
REDUCED
Audit-cycle preparation reduced from reconstruction to lookup exercise.
06 · REVIEW CADENCE
MONTHLY
Executive scorecard delivered with direct compliance leadership review.
§ 08 · FIT

Honest scoping.

C6 is a fit when specific conditions are met. It is not a fit when other conditions are — and "the control library is right; the retainer's job is discipline not re-implementation" is a legitimate finding we surface early rather than manufactured up to sell implementation work.

PREREQUISITES
Move fast when these five conditions are in place at onboarding.
01
Compliance leadership or Head of Risk as counterpart

Signs off operating model, SLA commitments, and monthly scorecard reviews. Typically 20-30% time commitment monthly through the retainer with lower steady-state investment after baseline is established.

02
Existing control library and compliance implementation in place

C6 operates the compliance posture you have implemented; it does not build the control library from scratch. Where compliance implementation is incomplete or genuinely absent, [[B8|B8 Controls Implementation Build™]] delivers the foundation before C6 begins.

03
Regulatory scope defined (PDPL / ISR / ADHICS v2 / MoF-FTA / internal)

Scope framework for the subscription — one or more UAE regulatory frameworks + internal governance requirements. Where scope is unclear, [[A3|A3 Compliance Fast-Track™ UAE]] baselines what's applicable before C6 defines the operating scope.

04
12-month commitment appetite

The operating cadence needs time to establish. Shorter commitments produce onboarding costs without steady-state value. Board or executive sponsor commitment to 12-month minimum is a hard prerequisite.

05
Named control owners identifiable across organisation

Evidence generation requires named control owners across clinical / IT / HR / procurement / operations (as applicable to your organisation structure). Where ownership is unclear or centrally-collapsed to compliance team alone, C6 onboarding includes ownership definition — but sustained operation requires distributed ownership.

NOT SUITABLE IF
Four patterns indicate a different engagement is a better fit.
You need initial compliance implementation, not ongoing operations

That's B8 Controls Implementation Build™ — fixed-scope build for PDPL/ISR/ADHICS v2 control library establishment. C6 operates the compliance posture you have implemented; B8 builds the compliance foundation. Sequence: A3 → B8 → C6 for the full cycle.

You need a one-time compliance gap assessment

That's A3 Compliance Fast-Track™ UAE — 3-week compliance posture baseline with 90-day plan. A3 baselines what needs closing; C6 operates what's in place.

You want security operations management, not compliance evidence operations

That's C7 SecOpsCommand™ — managed security operations retainer for MTTA, playbook execution, vulnerability governance, and drills. Different domain (security controls vs compliance evidence). Regulated organisations often run C6 and C7 in parallel for full continuous posture.

You need blockchain-enabled provenance operations for multi-party trust

That's D2 ProvenanceOps™ Subscription — Expand-tier subscription for verification-grade integrity operations across supply chain, compliance evidence chain-of-custody, and multi-party trust scenarios. C6 handles standard compliance evidence; D2 layers integrity operations where verifiable chain-of-custody genuinely matters.

§ 09 · COMMERCIAL

Managed retainer.
Monthly cadence. No surprises.

Every Run engagement is scoped as a 12-month minimum subscription with monthly delivery cadence. Retainer structure agreed at kickoff. Scope amendments negotiated through the Practice Lead, not surfaced as invoice surprises.

COMMERCIAL MODEL
Managed retainer, 12-month minimum

Priced against defined service elements, SLA commitments, and monthly cadence. Commitment structure supports both operational continuity and predictable budgeting.

COMMITMENT & CADENCE

12-month minimum subscription with monthly delivery cadence. Renewal negotiated at annual review gate (end M 11). Quarterly audit-cycle exports and governance review included within subscription scope; scope amendments (additional regulatory framework, additional business unit) negotiated through the Practice Lead.


INCLUDED IN SUBSCRIPTION
  • 5 named service elements with monthly SLA cadence across the mapped regulatory scope
  • Monthly executive scorecard and review cadence
  • Practice Lead as named account owner
  • Quarterly optimization release with roadmap update
  • Named SLA commitments with monthly reporting
  • 30/60/90-day onboarding milestones with signed acceptance

OUT OF SUBSCRIPTION
  • Multi-domain or enterprise-wide expansion (separate subscription)
  • One-time build engagements or platform implementation
  • Emergency incident-response beyond named SLA scope (available under separate scope)
COMMERCIAL PRINCIPLES
01

Retainer, not billable hours

No hourly billing. Subscription priced against service elements and SLA commitments agreed at kickoff.

02

12-month minimum commitment

The operating cadence needs time to establish. Shorter commitments produce onboarding costs without steady-state value.

03

Change orders authorised

Practice Lead has authority to negotiate scope amendments in the same conversation, not through a separate commercial cycle.

§ 10 · QUESTIONS

The five questions compliance leaders actually ask.

Q_01How is this different from hiring an audit consultancy at audit time?

Audit consultancies engage reactively — you pay three-figure daily rates for 6-8 weeks of evidence reconstruction whenever the annual audit approaches, and the compliance team burns capacity during the audit-cycle window.

C6 is the opposite pattern: continuous evidence generation and governance across the 12 months between audits so audits become verification lookups rather than reconstruction expeditions.

The commercial economics typically favour C6 by year two — sustained retainer cost is lower than the aggregate of annual reconstruction consultancy plus business-quarter opportunity cost during audit-cycle interruption. But the operational economics favour C6 immediately: your compliance team stops living in audit-cycle scramble mode.

Q_02Which regulatory frameworks are in scope?
In-scope UAE frameworks: PDPL (UAE Federal Data Protection Law), ISR (Information Security Regulation), ADHICS v2 (Abu Dhabi Healthcare Information & Cyber Security Standard), MoF/FTA eInvoicing requirements (October 2026 / January 2027 mandate for applicable organisations), and internal governance requirements. Sectoral variations (banking / financial services / healthcare / government) accommodated. Framework revisions tracked with 30-day mapping SLA to control library updates. Where non-UAE frameworks apply (GDPR for EU-facing organisations, HIPAA where healthcare data flows involve US entities), scope is expanded case-by-case at subscription negotiation.
Q_03Does C6 replace our existing GRC platform or evidence-automation tooling?
No. C6 is a managed evidence operations retainer, not a GRC platform selection or reseller relationship. The subscription operates against your existing compliance tooling — no platform swap, no vendor pre-selection. NexITC works across GRC platforms, evidence-automation vendors, and audit tools without vendor economics gating operational choices. Where evidence-generation improvements use native platform features, we identify them; where genuine tooling gaps exist, we surface them for internal team ownership rather than converting them to consulting scope.
Q_04How does C6 interact with C7 SecOpsCommand for regulated organisations?
Regulated organisations often run C6 and C7 in parallel for full continuous security-and-compliance posture. C6 operates compliance evidence (audit-ready posture across PDPL/ISR/ADHICS v2/MoF-FTA); C7 operates security controls (MTTA, playbook execution, vulnerability governance, AI/agent security). Different domains, same operating discipline. Both use RunSKU 12-month subscription structure and share Practice Lead — Cybersecurity as named account owner. Where an organisation prioritises one first, C7 typically leads for organisations with mature compliance implementation but weak security operations discipline; C6 typically leads for organisations with strong security ops but evidence-scramble compliance patterns.
Q_05What comes after C6 or in parallel?
Two paths. C7 SecOpsCommand™ in parallel for continuous security operations (see above). D2 ProvenanceOps™ Subscription as Expand-tier next-step where verification-grade chain-of-custody genuinely matters — supply chain provenance for manufacturing/trade organisations, compliance evidence chain-of-custody for high-stakes regulated environments, multi-party trust operations. D2 is Expand-tier (available to organisations already operating with Run-tier retainers, since Expand work is data-driven from operational evidence rather than sales-pitched).
§ 11 · NAMED ACCOUNTABILITY

One name.
Six accountabilities.

Specialist consulting means the person who onboards the retainer is the person who owns the cadence — with escalation to CEO on any material issue within 24 hours.

THE ROLE

Practice Lead — Cybersecurity

Named account owner for the duration of the retainer. Present at every monthly review, every quarterly release gate, every difficult conversation. Available for escalation on operational issues within 24 hours.

SIX ACCOUNTABILITIES
01
Commercial arrangement

Including scope amendments and renewal negotiation.

02
Operating cadence

Signs off the monthly performance review and quarterly release.

03
Monthly reviews

With executive sponsor.

04
Change orders

Authorised to negotiate.

05
Escalation path

CEO within 24 hours.

06
SLA accountability

Named commitment to SLA thresholds.

§ 13 · BOOK A CLINIC

30 minutes.
One compliance question.

Bring the specific compliance question blocking your board conversation — evidence completeness degrading, audit-cycle reconstruction consuming quarters, exceptions accumulating without governance, framework revisions untracked, or ADHICS v2/PDPL implementation intact but audit-ready posture uncertain. C6 is scoped in the clinic — regulatory scope, control library state, sponsor, commitment appetite, prerequisites. If C6 is not the fit (implementation needed first, or one-time compliance assessment is the actual need), the clinic surfaces the honest alternative.

CLINIC · C6
  • Regulatory scope confirmation
  • Control library state check
  • Audit-cycle pattern check
  • Fit assessment against A3, B8, C7
Practice Lead — Cybersecurity attends every clinic.