NIS2 · DORA · ISO/IEC 27001 · CIS CSC
M3 Consulting is a small, senior team built around one belief: compliance and cybersecurity aren't two different disciplines. We work across your controls, your architecture and your audit evidence — so nothing gets lost in translation between the compliance function and the engineers who have to implement it.
What sets us apart
Every recommendation traces from a regulatory clause to a concrete control or design decision — not the other way round.
No bench of juniors learning on your engagement. Every project is staffed by people who have implemented what they audit.
Recommendations are scoped to your actual risk profile and resources — not a generic maturity template copied between clients.
Services
Each service can stand alone or run together as part of a wider compliance and security programme.
Gap assessments, risk management frameworks, incident reporting procedures and ICT third-party risk management, built for essential entities and financial institutions alike.
Read more →Full-lifecycle ISMS support — scoping, risk methodology, Statement of Applicability, internal audits and certification-audit readiness.
Read more →Independent audits of IT general controls, access management, change management and vendor oversight, with a prioritised remediation plan.
Read more →Network, identity, endpoint and cloud architecture assessed against the CIS Controls, mapped to the Implementation Group that fits your organisation.
Read more →How we work
We turn away work that doesn't fit our model. In exchange, every client gets direct access to the consultants doing the work — no account managers relaying messages between you and the people who understand your systems.
More about M3 →Insights
A practical read on entity classification and the first 90 days of obligations.
Read →Getting ICT third-party risk documentation right before the auditor asks for it.
Read →Why IG1 is often the right ambitious answer, and when it isn't.
Read →A first conversation costs nothing and commits you to nothing. Tell us what's driving the engagement — an audit, a deadline, a board request — and we'll tell you honestly what it will take.
Get in touch