By company size

Your first certificate, without the detours

Reach your first certificate on the shortest defensible path

A deal is waiting on a certificate you do not have yet, and nobody on the team has done this before. We run the whole thing — scope, controls, evidence, audit — so the shortest path is also one that survives scrutiny.


Where you are

The constraints at this stage

What tends to be true when companies come to us at this size.

A deal is blocked on a certificate

Procurement will not move without SOC 2 or ISO 27001, and the timeline you were given is shorter than the one you would pick. The fastest route matters, but only if it still holds up in the audit.

Nobody owns security yet

Security sits with whoever has time — usually a founder or the first infrastructure hire. That works until a customer sends a 200-question assessment and expects a named owner to answer it.

Runway is the real constraint

A full-time security hire is not the right first spend at this stage, and every week your engineers spend on evidence collection is a week they are not shipping.


How the engagement works

What actually happens

The same four beats every time, scoped to what this stage needs.

Scope honestly

We work out the smallest defensible scope that satisfies the buyer actually asking. Over-scoping the first certificate is the most common and most expensive mistake at this stage.

Close the gaps

A gap assessment against the target framework, then a prioritised plan. Our specialists write the policies and stand up the controls rather than handing you a template pack.

Collect evidence as you go

Evidence is captured while controls run, not reconstructed the week before fieldwork. This is what keeps engineering involvement measured in hours rather than sprints.

Through the audit

We manage the auditor relationship, sit in the fieldwork, and answer the findings. You are not left translating between your stack and their checklist.


Proof

Track record

Across every engagement we have run, at every size.

0+

Companies Secured

Zero

Failed Audits

4-8

Weeks to Compliance

0+

Team Certifications


What you walk away with

The artefacts

Everything below is a thing you own at the end, not a promise about the process.

  • A defensible scope statement and asset inventory
  • The full policy set, written for how your team actually works
  • Risk assessment and treatment plan, with a Statement of Applicability for ISO 27001
  • Implemented controls with evidence collection running against them
  • Internal audit and management review records
  • A completed audit, and the certificate or attestation report at the end of it
  • Security questionnaire answers your sales team can reuse

Related

Where to go next

The problems this stage usually arrives with, and the services behind them.


Questions

What people ask at this stage

Most first-time engagements run four to eight weeks to audit readiness, depending on scope and how much already exists. ISO 27001 then adds the certification body's own two-stage audit; SOC 2 Type II adds an observation window, typically three months, that cannot be compressed.
Ask the buyer who is blocking the deal. North American customers usually name SOC 2; European, Indian and Middle Eastern customers usually name ISO 27001. If nobody has specified, ISO 27001 is the broader foundation and SOC 2 is cheaper to add afterwards than the reverse.
Materially less than doing it yourselves, because we write the policies and run the evidence collection. Engineers are needed for access to systems, technical control decisions and remediation — not for assembling documentation.
No, and at this stage it is rarely the right first spend. A vCISO gives you a named accountable owner for board, customer and auditor conversations without the cost of a full-time executive.

Get the certificate the deal is waiting on.

Tell us which framework the buyer asked for and when they need it. A 30 minute call is usually enough to tell you what it takes and what it costs.