DQM Group
DQM Group (DQM GRC), now part of GRC Solutions, is a UK-headquartered specialist data privacy, cyber security and GRC consultancy founded in 1996, offering privacy auditing, data seeding, ISO 27001, PCI DSS, Cyber Essentials, DORA and AI Governance services to enterprise and SMB clients across the UK, Ireland, Europe and the US.
- Company typePrivate
- Founded1996
- HeadquartersHigh Wycombe, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What DQM Group does
DQM Group, operating commercially as DQM GRC and now part of GRC Solutions, is a UK-based specialist data privacy, cyber security and governance, risk and compliance (GRC) consultancy founded in 1996. Its heritage services include data privacy consultancy, privacy auditing, data seeding and data subject rights testing, which have been integrated into GRC Solutions' broader portfolio covering ISO 27001, PCI DSS, Cyber Essentials, SOC 2, NIS2, DORA and AI Governance (EU AI Act, ISO 42001). The firm operates accredited roles including founding Cyber Essentials certification body, PCI QSA company, CHECK/CREST-accredited penetration testing provider, and NCSC Assured Cyber Security Consultancy.
The business combines professional services (consultancy, auditing, penetration testing, incident response, business continuity, DPO-as-a-Service, UK/EU GDPR Representative), a software and content portfolio (documentation toolkits for GDPR/ISO 27001/PCI DSS/Cyber Essentials, gap analysis tools across ISO 27001, GDPR, ISO 22301, ISO 27701 and DORA, plus an online shop), and a training stream (instructor-led courses and staff awareness e-learning across GDPR, CISSP, ISO 27001, ISO 22301, PCI DSS, DORA, AI and cyber security). Pricing is quote-based for professional services typically on multi-year engagements, with published pricing for toolkits and training courses via the online storefront.
Go-to-market is bifurcated between consultative enterprise sales for bespoke advisory and audit work, and self-serve e-commerce for toolkits, gap analysis tools, standards and e-learning aimed at SMBs and individual practitioners. The firm maintains operational presence in the UK, Ireland, mainland Europe and the United States, with the only named leader being Christine Andrews as Managing Director. As an acquired unit of GRC Solutions, DQM GRC no longer operates as an independent entity but contributes specialist privacy, auditing and data-seeding capabilities to the parent group's integrated GRC offering.
DQM Group firmographics
Firmographics- Name
- DQM Group
- Legal name
- DQM Group
- Website
- https://dqmgrc.com
- Company type
- Private
- Founded year
- 1996
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- DQM Group (DQM GRC), now part of GRC Solutions, is a UK-headquartered specialist data privacy, cyber security and GRC consultancy founded in 1996, offering privacy auditing, data seeding, ISO 27001, PCI DSS, Cyber Essentials, DORA and AI Governance services to enterprise and SMB clients across the UK, Ireland, Europe and the US.
- Ownership category
- akta.pro rank
DQM Group industry classification
Industry- Product category
- Data Privacy & GRC Compliance Services
- NAICS
- Custom Computer Programming Services (541511)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Privacy, Consent & Data Protection Management (BPAEAPAF)
- akta.pro secondary industries
- Privacy Governance & Consent Management (HDADAIAI), Regulatory Change Management (RCM) (HDADAIAG)
Keywords
Where DQM Group is headquartered
LocationHeadquarters
- HQ city
- High Wycombe
- HQ country
- United Kingdom
- HQ region
- Europe
Offices4 records
Markets served
DQM Group business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Professional Services: Consultancy services including data privacy consultancy, privacy auditing, cyber security, ISO 27001, NIS2, DORA compliance, incident response, and business continuity.
- Training Courses: Classroom and e-learning training courses covering GDPR, CISSP, ISO 27001, ISO 22301, Cyber Security, DORA, PCI DSS, AI governance, and staff awareness.
- Documentation Toolkits and Software: Pre-built documentation toolkits for GDPR, ISO 27001, PCI DSS, and Cyber Essentials compliance, sold as downloadable or accessible software products.
- Certification Services: Cyber Essentials certification body services, penetration testing, and compliance audit services.
- Data Seeding Services: Specialist data seeding solutions and data subject rights testing services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Professional services engagement |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels4 records
DQM Group product offering
Product offeringCore offering
DQM Group (DQM GRC) provides specialist data privacy consultancy, privacy auditing, data seeding, and data subject rights testing services to organisations needing GDPR and broader regulatory compliance. It complements these services with documentation toolkits, gap analysis tools, training courses, e-learning, outsourced DPO and UK/EU representative services, Cyber Essentials certification, and accredited penetration testing including AI Red Teaming.
Product overview
DQM GRC, now part of GRC Solutions, is a specialist data privacy consultancy providing core services including data privacy consultancy, privacy auditing, data seeding, and data subject rights testing. Integrated into the broader GRC Solutions portfolio, the offering includes software toolkits (GDPR Documentation Toolkit, ISO 27001 Documentation Toolkit, PCI DSS Documentation Toolkit, Cyber Essentials Toolkit), gap analysis tools (ISO 27001, GDPR, Cyber Essentials, ISO 22301, ISO 27701, DORA), professional services (DPO as a Service, UK and EU Representative Services), certification services (Cyber Essentials Certification), and training offerings (instructor-led courses and e-learning for ISO 27001, DORA, Cyber Security, PCI DSS, GDPR, AI, and Business Continuity). Penetration testing services are also available including AI Red Teaming and ML/LLM testing.
Differentiator
Problem solved
Functional benefit
Products and services
- Data Privacy Consultancy Expert consultancy services helping organisations meet their data privacy objectives and legal obligations, including GDPR compliance.
- Privacy Auditing Independent audit services to assess and validate organisational compliance with data privacy regulations and frameworks.
- Data Seeding Specialist data services that support organisations in testing data processing workflows and maintaining data integrity.
- Data Subject Rights Testing Testing services that verify organisational processes for handling data subject requests function correctly in compliance with privacy regulations.
- GDPR Documentation Toolkit Pre-built templates and documentation resources to support GDPR compliance implementation and ongoing governance.
- ISO 27001 Documentation Toolkit Comprehensive template package for implementing and maintaining ISO 27001 information security management system documentation.
- PCI DSS Documentation Toolkit Documentation resources for achieving and maintaining PCI DSS compliance, including policies, procedures, and evidence templates.
- Cyber Essentials Toolkit Resources and templates to help organisations prepare for Cyber Essentials certification assessment.
- DPO as a Service Outsourced Data Protection Officer service providing dedicated privacy leadership and GDPR compliance oversight for organisations.
- UK Representative Service GDPR representative service for non-UK organisations required to have a representative in the United Kingdom.
- EU Representative Service GDPR representative service for non-EU organisations required to have a representative in the European Union.
- Cyber Essentials Certification Certification service guiding organisations through Cyber Essentials certification to meet government-backed cybersecurity requirements.
- GDPR Training Specialist training for GDPR compliance understanding and implementation across organisations.
- CISSP Training Professional certification training for the Certified Information Systems Security Professional credential.
- ISO 27001 Training Training programmes for ISO 27001 information security management system implementation and audit preparation.
- DORA Training Training for Digital Operational Resilience Act compliance and financial sector operational resilience requirements.
- Penetration Testing Services Independent CHECK and CREST accredited security testing including AI Red Teaming and ML/LLM testing, application security, red team assessments, purple teaming, IoT/OT security, cloud security, and infrastructure penetration testing.
Companies that use DQM Group
Customer profileSegments1 record
Ideal customer profiles1 record
DQM Group technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
DQM Group partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- GRC SolutionscoreDQM GRC has been acquired by GRC Solutions. DQM GRC's services including data privacy consultancy, privacy auditing, and data seeding are now delivered through GRC Solutions. This integration provides DQM GRC clients access to broader cyber security, information security, privacy, and risk management expertise.
Recent moves7 records
Expansion highlights6 records
DQM Group competitors and assessment
Company assessmentBroad incumbents
- BigID: Data intelligence and privacy platform with data mapping, DSAR automation and consent management. Targets the same compliance buyers with a tech-led approach that competes with DQM's privacy governance services and gap analysis tools.
- TrustArc: Privacy management and consent platform offering technology-driven GDPR and CCPA compliance tooling. Overlaps with DQM's documentation toolkits and GDPR gap analysis products at a significantly larger enterprise footprint.
- OneTrust: Largest-scale privacy, security and GRC software platform globally. Overlaps with DQM's toolkits and consultancy at the privacy programme management layer but competes primarily through software rather than services.
Direct peers
- Schellman & Co: US-based compliance and audit firm offering SOC 2, ISO 27001, PCI DSS and HITRUST assessments. Comparable as a multi-framework compliance auditor that competes for similar enterprise attestation work, particularly in the US where DQM is also active.
- NCC Group: Global cyber security and assurance firm providing source code review, penetration testing and compliance services. Comparable as a security testing and standards-compliance peer serving UK and international clients.
- Bridewell: UK-headquartered cyber security and compliance consultancy delivering managed security, penetration testing, ISO 27001 and PCI DSS services that directly overlap with DQM's cybersecurity and certification practice.
- IT Governance Ltd: UK-based GRC solutions provider with an almost identical portfolio (GDPR, ISO 27001, PCI DSS, Cyber Essentials, training and toolkits). DQM's social media handles are all IT Governance-branded, strongly suggesting IT Governance is a sibling under the same GRC Solutions parent.
- DPO Centre: UK-based outsourced Data Protection Officer service provider. A like-for-like peer to DQM's 'DPO as a Service' line, addressing the same GDPR-driven need for fractional privacy leadership.
- Securys: UK data privacy and information security consultancy offering GDPR, DPIA and DPO services. Directly comparable as a UK-headquartered specialist privacy consulting firm competing for the same mid-market mandates.
Emerging players
- Vanta: Compliance automation platform for SOC 2, ISO 27001, HIPAA and related frameworks. An emerging software-led competitor to DQM's documentation toolkits and gap analysis offerings, automating the audit-readiness workflow the firm performs manually.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks6 records
Key highlights7 records
Customer concentration
DQM Group social profiles
Digital presenceDQM Group compliance and trust
Trust signalCompliance2 records
DQM Group financial estimates
Financial estimateRevenue estimate
Valuation estimate
DQM Group leadership team
Management profileNumber of profiles
Profiles1 record
DQM Group funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
DQM Group M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about DQM Group
What does DQM Group do?
DQM Group (DQM GRC) provides specialist data privacy consultancy, privacy auditing, data seeding, and data subject rights testing services to organisations needing GDPR and broader regulatory compliance. It complements these services with documentation toolkits, gap analysis tools, training courses, e-learning, outsourced DPO and UK/EU representative services, Cyber Essentials certification, and accredited penetration testing including AI Red Teaming.
Is DQM Group a public or private company?
DQM Group is a private company. It is classified as corporate owned and is currently acquired.
When was DQM Group founded?
DQM Group was founded in 1996. It employs 11 to 50 people.
Where is DQM Group based?
DQM Group is headquartered in High Wycombe, United Kingdom, in the Europe region.
How does DQM Group make money?
Five revenue lines are on record. Professional Services are the primary driver. The others are training Courses, documentation Toolkits and Software, certification Services and data Seeding Services.
Who are DQM Group's main competitors?
Broad incumbents on record are BigID, TrustArc and OneTrust. Direct peers are Schellman & Co, NCC Group, Bridewell, IT Governance Ltd, DPO Centre and Securys. Vanta is listed as an emerging player.
Does DQM Group have an API?
No public API is recorded for DQM Group.
What industry is DQM Group in?
DQM Group's product category is Data Privacy & GRC Compliance Services. Its primary akta.pro industry code is BPAEAPAF, Privacy, Consent & Data Protection Management, with a secondary code of HDADAIAI, Privacy Governance & Consent Management. Its NAICS code is 541511 and its SIC code is 7370.