Standards & ISO readiness

Certification-ready, because the controls are in the system.

ISO 27001, ISO 9001 and SOC 2 preparation delivered by people who build software for a living. Controls designed into your pipeline and your cloud account, evidence generated as a by-product of the work, and no theatre staged for the week of the audit.

ISO 27001 · ISO 9001 · SOC 2Readiness, not certificationControls in the pipelineEvidence automated where possible
What this is, and is not

We prepare you for the audit. We do not issue the certificate.

Certification is granted by an accredited certification body after a formal audit — that is deliberately not us, and any consultancy claiming otherwise is worth walking away from. What we do is the engineering half: building the controls, the evidence and the working practices into how your teams already operate, so that when the auditor arrives there is nothing to stage.

ISO/IEC 27001

Information security management. Scope and risk assessment, the Statement of Applicability, Annex A controls that map to real engineering practice, and the evidence trail that proves they run.

ISO 9001

Quality management. Process documentation that matches reality, corrective action that actually closes, and management review that produces decisions rather than minutes.

SOC 2 readiness

For selling into the United States. Trust services criteria, control design, and the continuous evidence collection an observation window demands.

How readiness runs

Controls that live in the pipeline, not in a binder.

The difference between a certification that helps and one that hurts is whether the controls are part of the working system or a parallel exercise performed twice a year. We only build the first kind.

1

Gap assessment

Where you are against the standard today, control by control, with an honest severity on each. Usually less frightening than expected, and differently distributed.

2

Design

Controls mapped onto how your teams actually work — access review in your identity provider, change control in your pipeline, evidence generated as a by-product of doing the work.

3

Implement

Engineering work: logging, access management, backup and recovery testing, secure SDLC, supplier review, incident runbooks that have been rehearsed.

4

Evidence

Automated collection where possible, plus the internal audit and management review cycle the standard requires, running before the external auditor arrives.

Cloud and AI in scope

Most of the controls that trip organisations up now sit in cloud configuration and, increasingly, in AI systems: data residency, model and prompt versioning, retention, decision logging and human review points. We build the systems, so we can build the controls into them rather than describing them afterwards.

AI governance

Realistic timelines

For a small engineering organisation starting from a reasonable baseline, ISO 27001 readiness is typically a six to nine month exercise, with the certification audit after that. Anyone promising it in six weeks is selling you a binder, and the auditor will notice.

Straight answers

Questions we get asked

Can you certify us?

No, and no consultancy can. Certification is issued by an accredited certification body after an independent audit — keeping those roles separate is the entire point of the scheme. We prepare you, and we can help you select and work with a certification body.

Do we need to buy a compliance platform?

Sometimes they earn their cost, particularly for evidence collection at SOC 2. Often they become an expensive parallel universe that describes controls you do not really run. We will give you a straight opinion for your situation and we take no commission either way.

How long does ISO 27001 realistically take?

For a small engineering organisation with reasonable practices already, six to nine months of readiness work before the Stage 1 audit is a realistic plan. Less if your baseline is strong, considerably more if access management and logging need building from scratch.

A customer is demanding it by a specific date. What now?

Start with the gap assessment, because the answer to 'can we make that date' is a question of facts and a few weeks' work to establish. Frequently an interim option — a security summary, a signed control attestation, a scoped Stage 1 — keeps the deal alive while the real programme runs.

Start here

One free hour. No pitch, no obligation.

Bring the problem you are stuck on — an integration that keeps breaking, a cloud bill nobody can explain, an AI project that is all demo and no product, or a platform you are about to invest in. You will leave with a straight answer and a written summary, whether or not you ever work with us.

  • Architecture and integration review
  • AI feasibility — what will actually work, and what will not
  • AWS, Azure and Google Cloud cost and design
  • Business process audit and ISO readiness
  • Technical due diligence before you invest or acquire