Under attack? Get emergency help now

GRC & Compliance

ISO 27001 readiness for a growing SaaS company

Gap assessment to certification-ready in one quarter, unblocking enterprise deals stalled in security review.

Client

B2B SaaS provider (anonymised)

Duration

1 quarter

0

Major non-conformities

1 quarter

Gap to audit-ready

93

Controls documented

The challenge

Enterprise prospects were demanding ISO 27001 certification. The company had informal practices but no ISMS, risk register, or documented controls.

What we did

  • Annex A control gap assessment across all applicable domains
  • Asset and risk register built with business-owner interviews
  • Review of existing vendor, access, and change-management practices

Key findings

High

No formal risk treatment process or management review cadence.

High

Access reviews and offboarding performed ad hoc, with orphaned accounts found.

Medium

Supplier due-diligence undocumented for critical processors.

Remediation

  • ISMS scope, policy set, and Statement of Applicability drafted
  • Quarterly access review and structured offboarding checklist implemented
  • Internal audit and management review cycles run before the external stage 1