Compliance

Compliance is a
process, not a
purchase.

Accessibility, privacy, security. The requirements are real and the deadlines are real, but most of the work is coordination — knowing what applies to you, gathering what proves it, and keeping it true after the auditor leaves. That is the part we do.

Ask what applies to you See what we work in

Plainly

Oryan is not a certifying body, and we do not hold these certifications on your behalf. The audit and the certificate come from an accredited auditor — that is the entire point of them. What we sell is the work that gets you there, and the platform work that keeps you there.

Where a piece of it is best handled by a specialist platform or an outside auditor, we select it, implement it and manage it. That is usually cheaper and always faster than assembling it yourself, and it means one company answers for the whole programme instead of four vendors pointing at each other.

How it works

Three ways in.

Most engagements start at the first one and stop wherever it stops making sense to keep going. You are not obliged to take all three.

  1. 01

    Tell you what you actually need

    An analysis of which requirements genuinely apply to your business, what closing them costs, and in what order to do it. This is often the most useful thing we do, because a good deal of what people arrive convinced they need turns out not to apply to them — and knowing that early is worth more than any of the work that follows.

    You get A written read on your obligations, the gaps, the sequence and the likely cost.

  2. 02

    Run the process for you

    Scoping, evidence collection, remediation, vendor selection and the long back-and-forth with auditors. We manage it end to end and translate between the specialists and your team, so nobody in your business has to learn a framework in order to get through it.

    You get A managed programme with one point of contact, and your own people left alone to do their jobs.

  3. 03

    Keep it true afterwards

    Compliance decays. Sites get redesigned, staff turn over, standards move, and a control that was true at audit quietly stops being true. We put monitoring, tooling and scheduled re-checks in place, because most of the real risk arrives after the certificate does.

    You get Monitoring, periodic re-checks, and remediation before it becomes somebody's complaint.

What we work in

The frameworks.

Which of these apply depends on what you sell, who you sell it to, and where they live. Usually it is fewer than people expect.

ADA & WCAG

Anyone with a public-facing website. In practice: everyone.

Accessibility is the one that reaches almost every business we work with, and the one that generates actual demand letters. We audit against WCAG, remediate the code and the design, and run a managed accessibility layer on top for the things that cannot be fixed at the source.

Cookie consent

Anyone running analytics or ad pixels.

A banner is the visible part and the least important one. What matters is that consent is captured before the tags fire, that preferences are honoured, and that there is a record of both.

GDPR

Anyone holding data on people in the EU or UK.

Lawful basis, data mapping, retention, subject access, processor agreements. Most of the work is finding out what personal data you are actually holding and why.

CCPA

Anyone holding data on California residents at scale.

Disclosure, opt-out of sale or sharing, and the plumbing to honour a request without it becoming a manual job for somebody.

SOC 2

Usually triggered by a customer's procurement team.

Security controls plus the evidence that they operate. We scope it, close the gaps, assemble the evidence, and manage the relationship with the auditing firm through to the report.

ISO 27001

Often required for enterprise or international contracts.

An information security management system rather than a checklist — which is why it is mostly a documentation and governance exercise before it is a technical one.

HIPAA

Healthcare, and anyone handling data on their behalf.

Safeguards, business associate agreements, access control and audit logging. We have built for home care, neurology and behavioural health, so this is familiar ground.

PCI DSS

Anyone taking card payments.

Scope reduction first. The cheapest way through PCI is almost always to handle fewer card numbers, not to secure more of them.

Accessibility

The one that
reaches everybody.

ADA compliance is a legal requirement, and making the internet accessible is about levelling the playing field for a fifth of the world's population. It is also, of everything on this page, the requirement most likely to arrive as a letter from somebody's attorney.

Litigation support, included

If a client's compliance is challenged, our litigation support package is provided at no extra cost. It covers professional audits, reports and accessibility documentation, along with our own attention for the duration — because the moment you need that material is the worst possible moment to start assembling it.

There is a tax credit

Section 44 of the IRS code covers half of eligible access expenditures from the previous tax year, up to an expenditure limit of $10,250, with no credit on the first $250. It does not cover everything and it does not apply to every business, but it is routinely left unclaimed by companies that qualify.

What it actually costs

An audit, the development and design work to close what the audit finds, and ongoing maintenance. The spread is wide because it depends entirely on how big the site is and how much was ignored on the way here. We would rather tell you the number after looking than before.

Then it has to stay true

Accessibility is not a project that finishes. Every redesign, every new template and every content editor is a chance to undo it, which is why the monitoring matters more than the certificate. A managed layer handles the session-level adjustments; the rest we fix at the source.

Not sure which of
these applies to you?

That is the normal starting position, and it is the question we are best at answering. We have spent over 20 years building and looking after websites for law firms, healthcare providers and financial companies, so most of these requirements are familiar ground. Tell us what you sell and who you sell it to, and we will tell you what you are actually on the hook for.

Start a conversation info@oryan.com