ISO/IEC 27001 is the certifiable international standard for an Information Security Management System. IRM designs and implements your ISMS, runs the risk assessment and internal audit, and gets you audit-ready in 90 days.
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS): the policies, risk assessment, controls, and management review an organization uses to protect information, certified by an accredited certification body. The 2022 edition sets out the management system requirements in Clauses 4 to 10 and lists 93 Annex A controls across organizational, people, physical, and technological themes. Unlike SOC 2, which is an attestation report, ISO 27001 is a certificate, and it is the credential enterprise and international buyers most often require of a SaaS vendor.
ISO 27001 consulting is the work of getting a company from a set of informal security practices to a certifiable ISMS. IRM scopes the system, runs the gap assessment against all 93 Annex A controls and the Clause 4 to 10 requirements, performs the risk assessment and risk treatment, writes the Statement of Applicability, policies, and procedures, delivers the internal audit and management review a certification auditor asks to see, and manages the Stage 1 and Stage 2 audits. Most SaaS clients with a reasonable technical baseline reach audit-ready within 90 days.
The work is led by a Virtual CISO, so the same person who builds your ISMS also runs it month to month, answers customer security questionnaires with the certificate, and handles the annual surveillance audits. Companies that also need SOC 2 or ISO 42001 get one control set and one evidence library that serves all three; the management system clauses are identical between ISO 27001 and ISO 42001, and SOC 2 shares the large majority of the technical controls.
If every buyer who has asked for assurance is in North America and accepts a SOC 2 report, start with SOC 2. It is faster to a first report and the controls carry over to ISO 27001 later. ISO 27001 costs more to maintain than SOC 2 because of the annual surveillance audits and the three-year recertification cycle.
If no customer, investor, or regulator has asked for either, run the free gap assessment, fix the highest-risk controls, and revisit certification at the first enterprise or international deal. Tell us who is asking and for what, and we will tell you which framework to sequence first.
ISO 27001 demand tracks how many of your buyers are enterprise or outside North America. This is how we size engagements for the SaaS companies we work with.
| Stage | Typical ARR | What You Need | IRM Engagement |
|---|---|---|---|
| Pre-seed and bootstrapped | Under $1M ARR | A security policy set and a risk assessment that answer questionnaires credibly; certification is usually premature. | Free ISO 27001 gap assessment, then a Crawling tier sprint to close the top 10 gaps and issue the policy set. |
| Seed | $1M to $5M ARR | An operating ISMS aligned to ISO 27001:2022, without certifying yet, so enterprise procurement stops stalling. | Walking tier, 90 days to an operating ISMS with the SoA, risk register, and policies in place. |
| Series A and B | $5M to $25M ARR | ISO 27001 certification, often alongside SOC 2 Type II, plus a supplier risk program buyers will inspect. | Walking or Running tier, audit-ready in 90 days, Stage 1 and Stage 2 audits in months 4 to 6. |
| Growth and PE-backed | $25M+ ARR | Certified ISMS maintained across products and regions, surveillance audits passed, ISO 27001 plus SOC 2 plus ISO 42001 from one control set. | Running tier managed GRC program with a named vCISO and quarterly control reviews. |
This is the sequence we run to take a SaaS company from no formal ISMS to audit-ready. Stage 1 and Stage 2 certification audits with an accredited body typically follow in months 4 to 6.
ISO 27001 work is delivered as a monthly Virtual CISO subscription, so the certification project and the ongoing ISMS operation use the same engagement and the hours track the work.
From $4,250 per month
20 to 40 hours per month, sprint under 6 months. Excludes certification body audit fees and any compliance automation platform license.
Bootstrapped teams that only need the policy set and a first risk assessment start on the Crawling tier from $2,000 per month (15 to 20 hours). Companies running ISO 27001 with SOC 2 or ISO 42001, or maintaining a certified ISMS through surveillance audits, sit on the Running tier from $6,950 per month. Pre-packaged Cyber and AI bundles start at $4,950.
See all Pricing TiersAssess all 93 Annex A controls of ISO/IEC 27001:2022 (118 items with the Clause 4 to 10 requirements), score each gap on a 5x5 risk matrix, and download a remediation roadmap. Your answers stay in your browser.
Run the ISO 27001 Gap AssessmentBook a Free ConsultationBring the report to your free consultation and we will turn it into a scoped 90-day plan on the call. Related: SOC 2 compliance if your buyers are in North America, ISO 42001 consulting if you ship AI, and Fractional CISO services if you need the leadership as well as the certificate.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


