Framework / ISO 27001
ISO 27001 Readiness
ISO 27001 readiness and certification preparation.
DELIVERED THROUGH
A Cloudsapio vCISO engagement
engagement levels
Advisor · Consultant · Leader
TYPICAL TIMELINE
4–8 weeks to certification
tHE PROBLEM
A European customer has asked for certification
ISO 27001 is the standard buyers outside the US recognise. If your pipeline includes UK, EU, or enterprise accounts, someone will eventually ask for the certificate rather than a SOC 2 report.
ISO 27001 asks you to run a management system: a defined scope, a risk assessment you can defend, a Statement of Applicability, internal audits, management reviews, and evidence that the whole thing improves over time. Then an external certification body audits it in two stages.
We build it and run it with you until the certificate is issued.
WHAT YOU GET
Deliverables
Full ISO 27001:2022 readiness: scope definition, risk assessment, Statement of Applicability, gap analysis against Annex A, policy authoring, internal audit, and certification body liaison through Stage 1 and Stage 2.
01
Kickoff call and scope confirmation
02
Risk assessment methodology, risk register, and treatment plan
03
Statement of Applicability covering all 93 Annex A controls
04
Gap analysis against Clauses 4–10 and Annex A, with a prioritised roadmap
05
Policy and procedure authoring across every applicable Annex A domain
06
Stage 1 and Stage 2 audit support, including nonconformity response
fit
Who is this for
International-facing SaaS companies, businesses selling into the UK and EU, and organisations where SOC 2 alone is not enough.

The questions that come up on every first call.
-
How long does ISO 27001 take?
Four to eight months from kickoff to certificate for most companies without an existing programme. The main variables are your scope, how much documentation already exists, and how quickly your engineers can close technical gaps.
-
Should we do ISO 27001 or SOC 2?
SOC 2 is what US buyers ask for. ISO 27001 is what UK, EU, and most international buyers ask for. If your pipeline is mixed, we usually recommend starting with whichever is blocking revenue now and building the second on top, since the underlying controls overlap heavily.
-
Can we do both?
Yes, and it is cheaper than running them separately. Once the ISMS exists, most of the evidence a SOC 2 auditor wants is already produced. We scope combined engagements regularly.
-
How much of my team's time does this take?
Expect four to six hours a week from an engineering or ops lead during remediation, and one to two hours a month from you for risk decisions, management review, and sign-off. ISO 27001 requires documented leadership involvement, so some of your time is not optional.
-
Do we need a compliance platform?
Not to start. If you have Vanta, Drata, or ISMS.online, we work inside it. If you don't, we will tell you whether one is worth the cost at your size.
RELATED CAPABILITIES
Ready to move faster?
Too much to do,
too important to ignore.
Start with a 30-minute discovery call. If we're not the right fit, we'll tell you and point you in the right direction. If we are, we'll leave the call with a clear plan to get you up and running.