Services /  GRC

Compliance Auditing & Certification

ISO 27001 and SOC 2, taken from first gap assessment to signed certificate.

The problem

An enterprise customer will not sign until you produce ISO 27001 or a SOC 2 report. Nobody internally has done this before. The quotes you have received describe a year of work and a stack of documents, and none of them tell you what your engineers will have to build.

The method.

01

Scope the certificate to the deal

Define the statement of applicability boundary: which product, which entity, which environments, which people. A tight, defensible scope certifies faster and still satisfies the customer asking. For SOC 2, select the Trust Services Criteria that the contract requires: Security is mandatory, Availability and Confidentiality often are, Privacy and Processing Integrity usually are not.

02

Gap assessment against the real control text

Every ISO 27001:2022 Annex A control and every applicable TSC point of focus is tested against evidence: MFA enforcement in the IdP, branch protection and review rules in the repository, encryption at rest settings, joiner-mover-leaver records, backup restore tests, supplier list. Findings are recorded with the artifact that proves or disproves them.

03

Build the management system, not just the documents

Clauses 4-10 are where first-time certifications fail: context and interested parties, risk assessment and treatment methodology, statement of applicability, internal audit programme, management review, corrective actions. We build these as running processes with owners and dates, because the auditor will ask for the records they generate.

04

Remediate with engineering, in engineering language

Gaps become tickets in your tracker, written as engineering work (enforce MFA on the admin console, turn on CloudTrail in all regions, add the leaver step to the offboarding checklist) with the control reference attached so the evidence trail is automatic.

05

Evidence period and internal audit

SOC 2 Type II requires an observation window, typically 3-12 months, during which controls must run and be seen to run. We operate the evidence collection through that window and perform the ISO internal audit and management review that the standard requires before the certification body arrives.

06

Sit the audit

Stage 1 and Stage 2 for ISO 27001, or the service-auditor fieldwork for SOC 2. We prepare the interviewees, run the evidence room, respond to auditor requests inside the day, and manage nonconformities and corrective actions through to closure.

The certificate is the start of the obligation, not the end of it. From the day it is issued the ROC keeps testing the same controls that were audited, so surveillance audits and the next Type II window find a system that has been running, not one being reassembled.

How long does ISO 27001 certification take?

For a company of 50-500 people starting from no formal management system, a realistic path is 3-4 months to build the ISMS and remediate gaps, followed by Stage 1 and Stage 2 audits by an accredited certification body. SOC 2 Type I can be issued at a point in time; SOC 2 Type II additionally requires an observation window, typically 3 to 12 months, during which the controls must operate.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international standard that certifies an information security management system, the process by which an organisation manages risk. SOC 2 is an attestation report, issued by a CPA firm, on whether specific controls were designed and operating effectively against the Trust Services Criteria. European and Asian customers usually ask for ISO 27001; North American customers usually ask for SOC 2. Companies selling to both generally end up with both, and much of the underlying control work is shared.

Does certification mean a company is actually secure?

No. Certification confirms that controls were designed and, at the time of audit, operating. It says nothing about the eleven months between audits, which is when controls drift: access reviews stop running, new systems land outside scope, tooling gets reconfigured. Continuous monitoring of the certified controls is what closes the gap between holding a certificate and being compliant.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.