Frequently Asked Questions
Everything you need to know about working with Gradeon. Can't find an answer? Get in touch and we'll respond within one business day.
What services does Gradeon offer?
Gradeon offers six core disciplines: IT Consulting, Compliance (including PCI DSS, DORA, ISO 27001), Cyber Security (penetration testing, vCISO, CaaS), IT Infrastructure (office relocation, cabling, cloud migration), Payment Services (Paytia-powered secure phone payments), and Process Automation.
How does Gradeon approach PCI DSS compliance?
We manage the entire PCI DSS compliance process end-to-end. From initial scoping and SAQ completion through gap analysis, remediation, and certification. We liaise with acquirers, auditors, and service providers so your team can focus on running the business.
What is your CaaS (Consultancy as a Service) model?
Our CaaS model provides ongoing cyber security support rather than a one-off engagement. It includes virtual CISO (vCISO) leadership, breach support, framework alignment, and annual validations and certifications. All tailored to your risk profile and budget.
Do you work with businesses outside London?
Yes. Although we are London-based, we work with businesses across the UK and internationally. We combine local expertise with a global outlook and operate both on-site and remotely depending on client requirements.
What is DORA and does my business need to comply?
DORA (Digital Operational Resilience Act, EU 2022/2554) is enforceable from 17 January 2025. UK-based firms that operate in or serve EU financial markets must comply. It covers ICT risk management, incident reporting, resilience testing, and third-party provider management. Gradeon can assess your eligibility during a free consultation.
How do I take card payments securely over the phone?
Gradeon partners with Paytia to provide PCI DSS compliant phone payment solutions. Instead of reading card details aloud to an agent, customers type them directly into their phone keypad. This means your business never handles cardholder data. Eliminating your PCI DSS scope for phone payments.
How quickly can Gradeon start on a project?
We typically schedule an initial consultation within 48 hours of enquiry. For urgent matters such as breach support or compliance deadlines, we can mobilise immediately. Contact us at info@gradeon.co.uk or call 0238 184 9633.
What size of businesses does Gradeon work with?
We work with businesses of all sizes. From growing startups requiring foundational IT infrastructure to FTSE-listed enterprises needing complex compliance programmes. Our approach is always tailored to the specific context and scale of each client.
How long does ISO 27001 certification take?
The timeline depends on your current security posture, but typically 6–12 months from initial gap analysis to certification. Gradeon manages the full process including documentation, control implementation, internal audit, and external certification body coordination.
Who do I contact if I have a technical problem or urgent query?
You can reach us by email at info@gradeon.co.uk, by phone on 0238 184 9633, or via our contact form. For breach support and urgent cyber security incidents, call us directly for immediate assistance.
Book a free consultation with our team.
We'll discuss your requirements, assess your current position, and outline a clear path forward.