ISO 42001 for cyber security firms: governing the AI you sell and use

Cyber firms sit in an awkward spot with AI: you sell AI-augmented services, you use AI in the SOC, and your clients now ask about both in the same questionnaire. ISO 42001 is the cleanest way to answer once, credibly.

Michael McCarroll 15 min read Updated June 2026

Why ISO 42001 matters for cyber security firms

For a 20–200 person cyber security firm turning over £2m–£20m, ISO 42001 has moved from a nice-to-have to a deal-shaping requirement. Enterprise cisos and public-sector procurement now ask for it by name in RFPs, and the absence of a credible answer is enough to lose the deal before a technical conversation ever happens.

The ICP this guide is written for: a 20–200 person B2B tech business turning over £2m–£20m, pursuing ISO 42001 (often alongside one or more of ISO 27001, ISO 20000-1, ISO 9001 and ISO 42001) without a dedicated full-time compliance manager. The founder, CTO, COO or Head of Ops usually owns it in practice.

  • You are past the stage where 'we take security seriously' answers a questionnaire
  • Your average enterprise sales cycle now includes an infosec assurance step
  • You cannot justify a £120k head to own compliance — but the work is real

Where firms in this sector typically start

Most cyber firms we speak to are somewhere between two familiar states: an experienced team who genuinely do the right things but cannot prove it to a buyer, and a team with a folder of policies written by someone external three years ago that no one has opened since.

Neither passes a modern audit or a modern buyer review. The starting point isn't 'implement everything' — it's a short, honest gap analysis against the standard, mapped to what already exists.

  • A 60–90 minute internal walkthrough of what already exists
  • A gap register scoped to the standard's mandatory clauses first, then Annex controls
  • An owner and a target certification window — 4–6 months is realistic for this sector

The minimum viable programme

Without a full-time compliance manager, the trap is trying to do everything. A minimum viable ISO 42001 programme for a 20–200 person cyber security firm turning over £2m–£20m is scoped, owned, and evidenced — not exhaustive.

The essential ingredients are the same across sectors: a defined scope, a leadership team that has signed off, a live risk register, the controls the standard requires, policies people actually read, and evidence produced as a by-product of doing the work rather than a separate reporting task.

  • Scope statement (single page, signed by the CEO)
  • Risk register with owners, treatment plans and review dates
  • Controls / Annex mapping showing what applies, what doesn't, and why
  • Policies drafted for adoption, not for a shelf
  • Evidence store linked directly to controls and audits
  • A calendar of internal audit, management review and improvement actions

Sector-specific pitfalls in cyber firms

Cyber firms almost always over-scope. The pentest arm, the SOC, the consultancy and the training business rarely need to be in the same certificate. Split by service line if the risk profiles genuinely differ; over-scoping is the single biggest reason cyber firms lose 6 months to certification.

The second pattern to avoid is treating the standard like a shopping list. The clauses that talk about leadership, planning, evaluation and improvement matter more than the controls themselves — those are what auditors actually test for maturity.

How ISO-STANDARD.app changes the economics

The reason a 20–200 person cyber security firm turning over £2m–£20m without a compliance manager historically failed to certify wasn't will — it was cost. A traditional consultancy-plus-spreadsheet programme runs £30k–£45k in year one. Most of that pays for policy drafting, spreadsheet maintenance and evidence chasing that a modern platform simply removes.

ISO-STANDARD.app ships a ready-to-adopt ISO 42001 workspace with the risk register, controls catalogue, policies, evidence store, internal audit programme and audit-ready exports already wired together. What remains is your organisation's genuinely unique work — scope, risk decisions, and evidence — which is where a founder or ops leader's time actually adds value.

  • Consultancy-led baseline: ~£30k–£45k in year one
  • Templates + spreadsheets baseline: ~£20k–£25k with heavy internal hours
  • ISO-STANDARD.app: from £39/month plus focused internal effort

A 90-day path to readiness

For a 20–200 person cyber security firm turning over £2m–£20m, a credible 90-day readiness path exists and is well-worn. Certification itself lands in months 4–6 depending on registrar availability.

  • Days 1–14 · Scope, leadership sign-off, gap analysis, register the workspace
  • Days 15–45 · Populate the risk register, adopt policies, assign control owners, close top-priority gaps
  • Days 46–75 · Collect evidence for each control, run the first internal audit, remediate findings
  • Days 76–90 · Management review, Stage 1 documentation submission, book Stage 2

Frequently asked questions

Do we really need ISO 42001 to sell into enterprise?
For a 20–200 person cyber security firm turning over £2m–£20m, yes — increasingly so. It's the fastest way to get through the infosec section of an RFP or vendor onboarding without a bespoke justification. Firms that don't have it either lose deals or spend disproportionate founder time answering questionnaires that a certificate would answer once.
Can we certify ISO 42001 without hiring a compliance manager?
Yes, and most firms in this ICP do exactly that. What you need is a nominated owner (typically the COO, CTO or Head of Ops) with 4–6 hours a week for the programme, an executive sponsor, and a platform that removes the spreadsheet and drafting work. A part-time fractional practitioner for 4–8 days total is often enough.
How long does it realistically take?
For a 20–200 person B2B tech firm with a tight scope and an integrated platform: 90 days to readiness, 4–6 months to certificate (governed by UKAS registrar availability). Longer programmes almost always suffer from over-scoping, not from complexity of the standard.
How much will it cost in year one?
All-in with ISO-STANDARD.app: roughly £8k–£15k for a small scope (registrar + platform + focused internal time). Traditional consultancy-plus-spreadsheet programmes for the same scope typically run £30k–£45k. Recertification and surveillance run £4k–£8k a year afterwards.
How does ISO 42001 fit if we're also pursuing ISO 27001 / ISO 9001 / ISO 42001?
Well, if you use one integrated management system. The clauses on leadership, planning, support, operation, evaluation and improvement are near-identical across ISO management system standards. Duplicated risk registers, audit programmes and policies are the biggest source of wasted effort — an integrated workspace collapses them into one.

Ship ISO 42001 without a full-time compliance manager

ISO-STANDARD.app packages the whole ISO 42001 programme — risk register, controls, policies, evidence, audits — into one workspace priced for a 20–200 person cyber security firm turning over £2m–£20m.

ISO-STANDARD.app ships a ready-to-adopt ISO 42001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →