What you'll walk away with
- A scoped ISMS proportionate to a 5–100 person company — not an enterprise template.
- Risk assessment, treatment plan and Statement of Applicability your auditor accepts.
- Policies drafted with AI from your real context, then reviewed by a practitioner.
- Evidence, controls and access reviews running in the platform from day one.
- Stage 1 and Stage 2 support so certification lands before the deal deadline.
What's included
Two-week gap analysis
Where you stand against clauses 4–10 and Annex A, with a prioritised plan mapped to your funding and sales timeline.
AI-drafted policy set
Guided prompts fill your policies from your actual systems and processes; you review and approve rather than write from scratch.
Risk register that fits
A workable methodology for a small team — top risks, owners, treatment, review cadence. No 300-line spreadsheet.
Evidence automation
Evidence requests, control health reviews and access reviews run on schedule so audit prep is a week, not a quarter.
Internal audit & management review
The two things startups always miss, delivered independently and documented for the certification body.
Stage 1 & Stage 2 coaching
We sit with you through the audit, handle findings and close corrective actions afterwards.
How we work
- Step 1
Week 0–2
Scope, context, gap analysis and a certification date you can commit to in sales conversations.
- Step 2
Week 2–8
ISMS build: policies, risk assessment, SoA, supplier and asset registers — implemented in the platform, not in Word.
- Step 3
Week 8–14
Operate the system: evidence, control reviews, internal audit, management review, corrective actions.
- Step 4
Certification
Stage 1 documentation review, Stage 2 audit support, then a light-touch surveillance rhythm your team can sustain.
ISO 27001 for startups FAQ
- We're 12 people. Is ISO 27001 realistic?
- Yes. Scope is yours to set — most early-stage companies certify a single product and its supporting operations. Four to six months is typical when leadership is engaged and evidence is captured as you go.
- Do we need a full-time compliance hire?
- No. The platform automates evidence, reviews and reminders, and fractional practitioner support covers the specialist work. Most startups certify with one part-time internal owner.
- Will this slow down engineering?
- The controls are designed around how you already build. Expect a few hours a month from engineering for access reviews and evidence, not a parallel process.
- Can we start before we're funded to do the whole thing?
- Yes. Start with the gap analysis and the platform, close the highest-risk gaps yourself, and bring in consultancy days only where they buy time.
Talk to us about ISO 27001 for startups
Share a few details and we'll come back within one working day with a proposed scoping call and indicative timeline.
