Skip to content

Case Study: Supporting Cerina Health with ISO 27001 and DSPT Readiness

Cerina Logo

Industry

Digital Health

Challenge

Cerina Health required an internal audit to be completed ahead of their ISO 27001:2022 certification audit and a review of their DSPT submission, all within a tight internal deadline and limited resources.

Results

With Periculo’s expert support, Cerina Health successfully passed their ISO 27001:2022 certification audit and submitted their DSPT application on time. This collaboration not only improved their ISMS maturity but also freed up significant internal capacity, enabling the team to focus on broader compliance priorities.

Key Product

NHS DSPT, ISO 27001

ISO 27001 Certification
DSPT Submission
Internal Capacity Freed
ISMS Maturity

"Periculo's flexible and expert audit support was crucial in helping us achieve our compliance goals. Their guidance ensured we met our deadlines without compromising on quality."

Prasannajeet Mane

Founder, Cerina Health

Couch_LogoRGB_Icon_Black-3

Cerina Health

Cerina Health is a growing innovator in digital health that places information security and data protection at the heart of its operations. With ambitions to expand within the NHS ecosystem, the company faced two immovable deadlines: an ISO 27001:2022 internal audit and a DSPT submission. Both were essential for compliance, credibility, and ongoing business operations. With limited internal resources and only days to act, Cerina turned to Periculo for expert, hands-on support.

The Challenge

Cerina Health’s internal team was confronted with two critical compliance milestones.

The first was an ISO 27001:2022 internal audit. To remain compliant with the standard, the audit had to be completed before the formal certification assessment, which was just one week away. Failure to complete the audit in time risked non-compliance and could delay the entire certification process.

The second was a DSPT submission. This was a mandatory requirement for working with NHS organisations, and Cerina had already set an internal deadline for finalising and submitting their entry. Missing this deadline would risk regulatory setbacks, reputational harm, and potential barriers to NHS engagement.

Both tasks required deep knowledge of security frameworks, audit expertise, and precision execution. Compounding the challenge, Cerina had limited capacity to deliver both workstreams in parallel, heightening the risk of missed deadlines and service disruption.

The Solution

Periculo acted quickly, assigning one of our consultants, Jack, to lead the engagement. The focus was on delivering practical, high-quality audits at speed, without sacrificing rigour or attention to detail.

The engagement included an accelerated internal audit of Cerina’s Information Security Management System (ISMS), covering all ISO 27001:2022 clauses and controls, including risk management, documentation, and operational practices. Alongside this, Periculo performed a full audit and quality review of Cerina’s DSPT submission, ensuring it met NHS guidance and was supported by robust evidence.

To cope with the compressed timeline, Periculo also provided flexible resourcing, reallocating time at short notice and adjusting delivery around Cerina’s internal priorities. This agile approach ensured progress on both workstreams without compromise.

Implementation

Periculo’s approach combined structure with agility to meet the tight deadlines:

  • Rapid onboarding: We secured access and began reviewing ISMS documentation the same day.

  • Focused audit execution: High-risk areas were prioritised, with early feedback provided to close gaps ahead of the certification assessment.

  • Clear reporting: Shortfalls against ISO 27001 and DSPT requirements were documented alongside actionable recommendations.

  • Close collaboration: Daily check-ins with Cerina ensured alignment, flexibility, and quick resolution of queries.

This combination of speed, precision, and collaboration enabled Cerina to meet its compliance goals under intense time pressure.

Results

Despite the challenging timeframe, Cerina Health achieved all of its objectives:

  • A completed and fully documented ISO 27001:2022 internal audit, delivered within five working days, enabling them to approach the certification assessment with confidence.

  • A successful DSPT submission, finalised and submitted on time, ensuring compliance with NHS requirements.

  • A stronger, more mature ISMS aligned with the latest version of the ISO standard, with a clear roadmap for ongoing improvement.

  • Freed-up internal resources, allowing the Cerina team to focus on broader compliance priorities while trusting Periculo to lead on audit delivery.

With the clock ticking, Cerina Health needed more than a checkbox exercise. They required a trusted partner who could step in quickly, deliver quality under pressure, and ensure nothing was overlooked. Periculo delivered exactly that.

Through this engagement, Cerina successfully completed its ISO 27001 internal audit in under a week, passed its certification audit with confidence, and submitted a high-quality DSPT application on time. The result was stronger security, enhanced compliance, and complete assurance that no milestones were missed.

Ready to get started?