top of page

About Us

Get to know AKRUP — our expertise, our team, and the commitment that underpins every project we deliver.

Managing Director

Anya Krupina

  • ISO 27001, AIMS, information security, ISMS, ISO 27001  certification, ISO 27002, ISO 27005, TISAX,

With over a decade of experience in information security and regulatory compliance, Anya founded AKRUP to help organisations achieve and maintain leading standards such as TISAX, ISO 27001 and CMMC.

Her combined background in law and information security enables her to deliver practical, compliance-driven solutions that meet both regulatory and business needs.

Anya also conducts TISAX and ISO 27001:2022 audits for certification bodies across the UK, EU, and US.

Mum edited and cropped.png

Director

Ildar Kelly

  • ISO27002, information security management system, ISO 27001  controls, ISO 27001 Implementation

Since joining AKRUP in 2018, Ildar has supported organisations across multiple sectors in achieving compliance with key standards, including TISAX, ISO 27001, and ISO 42001.

He has guided companies from initial gap analysis through to successful certification, ensuring practical, audit-ready results.

In addition to consultancy work, Ildar also conducts independent ISO 27001 and TISAX audits for leading certification bodies such as BSI and A-LIGN.

Ildar cropped and edited.png

Senior Consultant

Steven Kelly

  • ISO27001 auditor, ISO 27001  audit, ISO 27001 consulting, ISO 27001 consultants, ISO27001 consultant

A Royal Navy veteran with over 30 years of experience in the oil and gas industry, Steven brings extensive operational and compliance expertise to AKRUP.

He supports clients in the automotive sector, helping them implement and maintain standards such as TISAX, ISO 27001:2022, and ISO 9001:2015, ensuring efficient and audit-ready compliance across their operations.

dad edited.png

FAQs - Frequently Asked Questions

We’ve created this section to help you quickly find the information you need — whether you’re exploring how we work, what to expect from our consultancy, or how to get started.

If you can’t find the answer you’re looking for, please don’t hesitate to contact us directly — our team is always happy to help.

Do you only deliver services remotely?

Yes — all of our consultancy services are delivered remotely.


This approach allows us to offer greater flexibility, faster response times, and more efficient project delivery for clients worldwide. Remote delivery also means no travel costs, no scheduling delays, and full access to our consultants whenever you need support.

We use secure collaboration tools, structured project workflows, and clear communication channels to ensure the same high level of quality you would expect from on-site consultancy — without any of the logistical limitations.

If an on-site visit is ever required for a specific reason, we can discuss this on a case-by-case basis, but our standard delivery model is fully remote.

How much does it cost?

Our pricing varies depending on the scope of the project, the size and complexity of your organisation, and the timelines you are working with. Because every engagement is different, we provide tailored quotes rather than fixed, one-size-fits-all pricing.

Once we understand your requirements, we’ll outline a clear proposal with transparent costs, expected timelines, and deliverables—so you know exactly what to expect before any work begins.

If you’d like an estimate, feel free to contact us and we’ll be happy to discuss your project in more detail.

Do we need to invest in technology?

No — you don’t need to purchase any new technology to work with us.All of our consultancy services are designed to integrate with the tools and systems you already use.

 

We focus on improving processes, governance, and compliance, not selling or requiring additional software or hardware.If we identify optional tools that could make your operations more efficient, we’ll let you know — but there is absolutely no obligation to invest in anything new.

 

Our goal is to keep the process simple, practical, and cost-effective.

Can we fail the audit?

Yes — it is possible to fail an audit if required controls or processes are not in place. However, our clients have never experienced this.


AKRUP currently maintains a 100% success rate, with every organisation we’ve supported achieving their required certification or label.

Our approach is designed to identify gaps early, guide you through remediation, and ensure you are fully prepared before any formal audit takes place. With the right preparation and our support throughout the process, you can approach your audit with confidence.

How long does it take?

The timeline varies depending on the size and complexity of your project, as well as how quickly you want to achieve certification. Some organisations move through the process in a matter of weeks, while larger or more complex engagements can take longer.

Once we understand your goals and timeframes, we’ll provide a tailored project plan with clear milestones so you always know what to expect.

 

Our remote delivery model also allows us to progress work efficiently and adapt to your preferred pace.

What is the impact on our processes?

There is no negative impact on your existing processes.


Our consultancy approach is designed to work around how your organisation already operates. We align our work with your current workflows, minimise disruption, and ensure that any improvements we recommend integrate smoothly into your existing structure.

Our goal is to enhance what you already have in place—not to add unnecessary complexity or force major process changes. You can expect a smooth, low-impact experience from start to finish.

CMMC, NIST 800 171, cybersecurity maturity model, cyber security maturity model, cyber security maturity models, NIST SP 800 171, cyber security maturity assessment, cybersecurity maturity assessment, CMMC certification, cybersecurity maturity model certification, cyber maturity assessment, defence cyber certification, DoD CMMC, CMMC level 2 certification, CMMC level 1 certification, CMMC self assessment, CMMC CCP, CMMC CUI, CMMC FCI, DoD software certification, DoD cybersecurity standards, DoD accreditation process, NIST 800 171 assessment, cyber security NIST 800 171, DoD information assurance certification, CMMC consultant, CMMC advisory, CMMC RP, CMMC 2.0 for defense contractors, CMMC consultancy, self assessment NIST 800 171, CMMC advisor,
Balck and white Akrup logo_edited.png
bottom of page