Certifications mapped
Digital Health Regional Compliance
Periculo covers the cyber and information security side of digital health compliance, security controls, risk assessments, audits, and evidence gathering. Where a certification also involves clinical, regulatory, or usability requirements, we work alongside your specialist teams.
0
0
Regions
0
Sucess
UK | Germany | France | Spain | Netherlands | Italy | Sweden | Denmark | Norway | Finland | Belgium | US
The Certification Landscape
Every certification you need, mapped to the markets that require it
Scan by name and typical timeline, then expand any certification for who needs it and what it involves. Global baseline standards are highlighted, establish these first and most regional schemes reuse the same evidence.
How We Help You
Every certification, managed end-to-end
Testimonials
“From the very beginning, their team was incredibly responsive, supportive and approachable. They were always available to clarify requirements and help us feel fully prepared before every audit.”
Nassos Katsaminis// Auxilis.ai
Global baseline standards (ISO 27001, SOC 2, the ISO 270xx family, HITRUST) are recognised across markets and form the evidence foundation. Country-specific certifications are legal or connectivity requirements for a particular national health system — they typically extend or reuse your baseline controls rather than starting from scratch.
Almost never. The right set depends entirely on the markets you sell into and the data you handle. We scope the certifications that actually unlock your target markets, and sequence them so each one reuses the evidence from the last.
Yes — that is the core of our approach. NEN 7510, ISO 27017/27018/27701, ACN Cloud QC2 and others build directly on ISO 27001. We maintain one control set and evidence base and extend it, rather than running each certification as a separate project.
Individual certifications range from around one month (Cyber Essentials) to 12–18 months (Spain ENS, HITRUST r2). Run in parallel with a shared evidence base, most organisations reach the certifications for a new market within 6–12 months of starting.
Latest Insights
Tailored for Defence: Why Generic AI-Generate...
Ask an AI assistant to write an Acceptable Use Policy, and it will produce something plausible-looking in seconds: don't...
The Rules of Engagement: What Your Certificat...
Somewhere in every DCC preparation project, a compliance officer asks a reasonable question: "Can our Certification Body...
DCC Level 2/3 Hybrid: The Assessment Process,...
If your contract requires Defence Cyber Certification (DCC) Level 3, there's one thing worth knowing before you go any f...
DCC Level 1: The Assessment Process, Step by ...
For suppliers in the UK Ministry of Defence (MOD) supply chain, Defence Cyber Certification (DCC) Level 1 is typically t...
How to Manage Operational Technology (OT) Und...
Industrial control systems have traditionally sat outside IT's compliance conversations, too specialised, too fragile, t...
Why Cyber Essentials and DCC Scope Rarely Mat...
CE scope and DCC scope are not the same thing, and treating them as interchangeable is the single most common reason Def...
DCC Penetration Testing Requirements: A Compl...
UK defence procurement no longer assesses cybersecurity contract by contract. The Ministry of Defence (MOD) and IASME ha...
Threat Report 188
In this week's report: A brand new flaw in Microsoft SharePoint is already being attacked, just days after test code for...
