A questionnaire arrives
A large customer sends a security questionnaire the founders can't answer, and the deal waits.
Security · Fractional CISO
Enterprise buyers, banks and investors ask for proof. We design the controls, write the policies, prepare the evidence and stay with you through the audit, alongside the independent firm that issues the report.
A large customer sends a security questionnaire the founders can't answer, and the deal waits.
A Series A lead or a partner bank asks how customer data is handled and who is accountable for it.
Your compliance platform reports gaps the team can't close on its own.
Readiness work typically takes six to twelve weeks for a company of up to fifty people on modern cloud infrastructure, and less where basic controls are already in place. A SOC 2 Type I report can follow soon after. A Type II report covers an observation period, usually three to twelve months, set with your audit firm. ISO 27001 certification follows a two-stage audit by an accredited body.
Timelines depend on scope and on how much is already in place. You get an honest estimate after the gap assessment, before you commit to the rest.
Readiness work typically takes six to twelve weeks for a company of up to fifty people on modern cloud infrastructure, and less where basic controls are already in place. A Type I report can follow soon after. A Type II report covers an observation period, usually three to twelve months, set with your audit firm. We give you an honest estimate after the gap assessment.
A Type I report covers whether controls are designed and in place at a point in time. A Type II report covers whether they operated effectively over a period, usually several months. Many enterprise buyers ask for Type II; a Type I can unblock a deal sooner.
U.S. enterprise buyers usually ask for SOC 2. Customers in Europe and elsewhere often ask for ISO 27001. We help you pick the one your buyers ask for first, and build controls that serve both.
No. SOC 2 reports are issued by licensed CPA firms, and ISO 27001 certificates by accredited certification bodies. Independence rules keep the auditor from designing the controls it examines, which is the work we do.
Often, yes. Platforms collect evidence and monitor controls. We design the control environment, write the policies and answer customers and banks in their own terms, and we work inside the platform you already use.