Security · Compliance · Consulting

From zero to SOC 2, ISO 27001
and CRA-ready

Nordic Sec is a Swedish security & compliance consultancy. We audit your systems, design the controls, and take you through SOC 2 Type II, ISO 27001:2022, and EU Cyber Resilience Act certification — treating compliance as real engineering, not policy PDFs.

20+
Years in security & infosec
CISSP
Certified practitioner
9 mo
Zero to dual certification
EU
Sweden · remote-first
[01] / Services

What we deliver. Compliance treated as engineering, with honest findings.

Six practices, one team. We audit your systems, design the controls, and take you through SOC 2 Type II, ISO 27001:2022, and EU Cyber Resilience Act certification — building the evidence and secure-by-design practice that stands up to a real auditor, not a policy template.

0x01 — Audit
Security audits

STRIDE threat modelling, code-level vulnerability assessment, and review of your existing security design. We find what automated scanners miss.

  • STRIDE
  • Code review
  • Design review
  • Dependency risk
0x02 — Architecture
Architecture review

System design assessment, trust-boundary and infrastructure review, reliability analysis. Honest evaluation of technical debt and security risk.

  • System design
  • Trust boundaries
  • Reliability
  • Cloud / IaC
0x03 — SOC 2
SOC 2 Type II

Readiness assessment, control design, and an automated evidence pipeline that carries you through the Type II observation window and the auditor's fieldwork.

  • Readiness
  • Control design
  • Evidence automation
  • Type II window
0x04 — ISO 27001
ISO 27001:2022

End-to-end ISMS build against the 2022 Annex A controls — risk register, policies, and Statement of Applicability — through Stage 1 and Stage 2 certification.

  • ISMS
  • Annex A 2022
  • Risk register
  • Stage 1 & 2
0x05 — CRA
Cyber Resilience Act

EU CRA readiness for products with digital elements: security-by-design, SBOM, coordinated vulnerability handling, and conformity documentation ahead of the 2027 deadline.

  • Product security
  • SBOM
  • Vuln handling
  • Conformity
0x06 — SDLC
Secure SDLC

Bake security into how your team ships: threat modelling, SAST/DAST and dependency gates in CI, secure code review, and supply-chain controls that satisfy your framework.

  • Secure by design
  • CI security gates
  • SAST / DAST
  • Supply chain
[02] / Approach

How we work. No black boxes, no filler — you see the process, you keep the output.

Every engagement follows the same rhythm: understand what's being defended, reproduce findings before reporting them, deliver something engineers can act on, and close the loop.

01 · Scope
Threat model first

We start with what you're actually defending — assets, adversaries, tolerances. The engagement is shaped to your risk, not a template.

02 · Review
Reproduced, then reported

Every finding is exploitable, reproducible, and validated before it reaches you. No speculative CVEs, no cosmetic noise.

03 · Report
Written for engineers

Reports ship with proof-of-concept, reproduction steps, and concrete remediation — plus an exec summary that doesn't hide the detail.

04 · Retest
We close the loop

Findings aren't closed until the fix is verified against the original proof of concept. Free re-test within 60 days of delivery.

[03] / Engagement models

Three ways to work together. Pick the one that matches the problem.

FIXED-SCOPE

Defined engagement

Security audit, architecture review, or threat model with a set scope, timeline, and deliverable. Clear price, no surprises.

Typical2–6 weeks
EMBEDDED

Embedded consulting

We join your team — building the ISMS, running the control programme, and mentoring engineers on secure practice. Monthly retainer, flexible scope.

Typical3–12 months
RETAINER

Advisory retainer

On-demand access for architecture decisions, incident response guidance, and review of critical changes. Lightweight and high-signal.

TypicalOngoing
[04] / Selected work

A concrete outcome. Not every engagement lives on a slide.

FEATURED ENGAGEMENT · STARTUP OUTCOME · DUAL CERTIFICATION IN 9 MONTHS

From zero to SOC 2 Type II and ISO 27001:2022 in nine months.

Led the end-to-end security and compliance programme for a startup beginning with no formal security posture. Designed the control framework, authored the policies, built the automated evidence pipeline, and walked the team through Stage 1 and Stage 2 ISO audits and the SOC 2 Type II observation window — reaching both certifications inside nine months, with zero major non-conformities.

  • Control design
  • Policy authoring
  • Evidence automation
  • Risk register
  • Stage 1 & 2
  • Type II observation
  • Auditor liaison
[05] / About

Who we are. A small practice, led by a practitioner.

Alexey Ulyanov
FOUNDER & PRINCIPAL CONSULTANT

20+ years building and securing software systems. A deep engineering background — systems programming, distributed systems, and infrastructure — now focused on security audits and compliance engineering across fintech, SaaS, Web3, and enterprise.

CISSP certified. Led a company from no formal security posture to SOC 2 Type II and ISO 27001:2022 in nine months. Fluent in the 2022 Annex A controls, the EU Cyber Resilience Act, GDPR, and NIST frameworks — and able to read the code the controls are meant to protect.

Based in Sweden. Working with clients across Europe — remote-first, timezone-flexible.

LinkedIn profile
Certification
CISSP · Infosec · 2025
Training & coursework
NIST CSFISO 27001Incident Response & RiskCISO Masterclass
Compliance frameworks
SOC 2 Type IIISO 27001:2022EU CRAGDPRNIS2
Security expertise
Threat modellingCode auditArchitecture reviewSecure SDLCEvidence automation

Let's discuss your project.

Security audit, SOC 2 / ISO 27001 readiness, or CRA compliance — we're ready when you are. Most engagements start with a 30-minute scoping call.