Startups & scale-ups — ISO/IEC 27001:2022

ISO 27001 for startups, sized for the team you actually have.

No 200-page policy library, no compliance hire. A lean ISMS built around your real stack and shipping cadence, with evidence captured automatically so certification stops blocking deals.

What you'll walk away with

  • A scoped ISMS proportionate to a 5–100 person company — not an enterprise template.
  • Risk assessment, treatment plan and Statement of Applicability your auditor accepts.
  • Policies drafted with AI from your real context, then reviewed by a practitioner.
  • Evidence, controls and access reviews running in the platform from day one.
  • Stage 1 and Stage 2 support so certification lands before the deal deadline.

What's included

Two-week gap analysis

Where you stand against clauses 4–10 and Annex A, with a prioritised plan mapped to your funding and sales timeline.

AI-drafted policy set

Guided prompts fill your policies from your actual systems and processes; you review and approve rather than write from scratch.

Risk register that fits

A workable methodology for a small team — top risks, owners, treatment, review cadence. No 300-line spreadsheet.

Evidence automation

Evidence requests, control health reviews and access reviews run on schedule so audit prep is a week, not a quarter.

Internal audit & management review

The two things startups always miss, delivered independently and documented for the certification body.

Stage 1 & Stage 2 coaching

We sit with you through the audit, handle findings and close corrective actions afterwards.

How we work

  1. Step 1

    Week 0–2

    Scope, context, gap analysis and a certification date you can commit to in sales conversations.

  2. Step 2

    Week 2–8

    ISMS build: policies, risk assessment, SoA, supplier and asset registers — implemented in the platform, not in Word.

  3. Step 3

    Week 8–14

    Operate the system: evidence, control reviews, internal audit, management review, corrective actions.

  4. Step 4

    Certification

    Stage 1 documentation review, Stage 2 audit support, then a light-touch surveillance rhythm your team can sustain.

ISO 27001 for startups FAQ

We're 12 people. Is ISO 27001 realistic?
Yes. Scope is yours to set — most early-stage companies certify a single product and its supporting operations. Four to six months is typical when leadership is engaged and evidence is captured as you go.
Do we need a full-time compliance hire?
No. The platform automates evidence, reviews and reminders, and fractional practitioner support covers the specialist work. Most startups certify with one part-time internal owner.
Will this slow down engineering?
The controls are designed around how you already build. Expect a few hours a month from engineering for access reviews and evidence, not a parallel process.
Can we start before we're funded to do the whole thing?
Yes. Start with the gap analysis and the platform, close the highest-risk gaps yourself, and bring in consultancy days only where they buy time.

Talk to us about ISO 27001 for startups

Share a few details and we'll come back within one working day with a proposed scoping call and indicative timeline.

We reply within one working day. No sales pressure.