Home All services
Start a project → Call Now

ISO 27001 case study · B2B SaaS

ISO 27001 certification in eight months — because the client owned the work.

A SaaS company kept losing enterprise deals at the buyer's security review. We ran its ISO 27001 program, from the first gap assessment to a certification audit it passed on the first attempt.

  • Certified eight months after the first gap assessment
  • Audit passed on the first attempt
  • An owner inside the company for each control
Illustration: a sample ISO/IEC 27001 program layout listing clauses 4 to 10 and the four Annex A control groups, each marked gap assessed, owner assigned or evidence tracked

In brief

The client
A B2B SaaS company that sells its software to enterprises. We keep its name private.
The problem
Enterprise deals kept stalling at the buyer's security review. Without an ISO 27001 certificate, the company couldn't stay in those conversations.
The result
Certification eight months after the first gap assessment, with the certification audit passed on the first attempt.

The challenge

What stood between the company and a certificate.

The gap to the standard was one problem. The time of the people who would have to close it was the other.

ISO 27001 is the international standard for an information security management system (ISMS): the policies, controls and records a company uses to manage its security risks. An independent certification body audits the company against it and decides whether to issue the certificate.

  • An unknown gap. Nobody knew how far the company was from the standard. Only a gap assessment, a structured check against each requirement, could measure it.
  • Controls that fit. The controls, meaning the safeguards and routines the standard asks for, had to match how the company actually operates. Then they had to be proven in operation.
  • People to do the work. The timeline depended on internal owners committing to the work.

What we did

A project plan with owners and dates, not a policy pack.

A policy pack (a folder of templates with the company's name filled in) produces documents, but auditors want evidence that controls are operating. That evidence comes from people inside the company doing the work week after week, so we ran the program as a project with owners and dates.

Gap assessment

We assessed the company against ISO 27001, requirement by requirement, to measure the distance to certification.

Control design, with owners

We designed the controls around how the company works. Each control got an owner inside the company: one of the client's own staff, not us.

Evidence and audit preparation

We tracked evidence collection against those owners and dates. Then we prepared the company for the certification audit.

The impact

Certified on the first attempt.

The company now has ISO 27001 certification to show at the enterprise security reviews where its deals had been stalling. The figures are the client's own, as reported to us.

8 months
from the first gap assessment to certification
1st
attempt pass at the certification audit
In-house
control owners: the company's own people, not an outside consultant

The hard part

Why eight months held.

The timeline held for one reason, and it wasn't us. The client committed internal owners, and those owners did the work.

If you are planning ISO 27001

  • Commit owners first. Each control needs a named person inside your company. Their time decides the timeline more than anything a consultant does.
  • Without them, expect longer. Where a company can't commit people, the same program takes considerably longer. We say that at the start, not halfway through.

We don't issue certificates. An independent certification body runs the audit and makes that call. Our job is getting the company ready for it.

Related services

Where to start if your deals stall at the same review.

Start with the question your buyers are asking.

More case studies: bank security assessment, patient care management app, hotel management platform and logistics operations platform. Or see every case study.

Let's talk

Losing deals at the security questionnaire?

Tell us which certificate your buyers ask for and who on your side can own the work. We reply within one working day.