
Sound familiar?
"Our US prospect won't sign without a SOC 2 Type II report and a pentest."
- Enterprise customers keep asking for ISO 27001 or SOC 2, and deals are slipping.
- We bought a compliance platform, but nobody has time to work through 300 tasks.
- Consultants we spoke to quoted months of paperwork that doesn't match how we work.
- We don't know which auditor to pick or what they'll actually check.
- Our engineers fear that compliance will slow down every release.
Built for
What we do
What's included in ISO 27001 & SOC 2 Readiness.
ISO 27001 Implementation
Scope, ISMS setup, risk assessment, risk treatment plan and Statement of Applicability for ISO/IEC 27001:2022, fitted to how you really work.
SOC 2 Type I & Type II Readiness
Mapping to the Trust Services Criteria, control design, a readiness check and support through the Type II observation period.
Security Policies & Procedures
A complete, readable policy set that satisfies both ISO 27001 and SOC 2, so you write each policy once.
Evidence Collection & Compliance Platforms
We set up and run Sprinto, Vanta or Drata (or a simple shared folder) and collect the evidence auditors ask for.
ISO 27001 Internal Audit
The internal audit required by clause 9.2, done by a team member independent of your implementation work, plus the management review.
Auditor Selection & Coordination
We help you choose an accredited certification body or CPA firm, prepare your team and support you through the audit itself.
Who delivers this
Senior security people, not juniors.
Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.
Principal Security Advisor
Leads this serviceA serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.
ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance
Security & Compliance Partner
AdvisesA hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.
GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC
Pricing
Transparent packages. Fixed quotes.
Your final quote is fixed after a 20-minute call — no surprise bills.
ISO 27001 Implementation
- Gap analysis and ISMS scope
- Risk assessment and Statement of Applicability
- Full policy and procedure set
- Staff security awareness session
- Independent internal audit and management review
- Support through Stage 1 and Stage 2 audits
SOC 2 Type I Readiness
- Trust Services Criteria scoping
- Control design and policy set
- Compliance platform setup and evidence
- Readiness assessment before the audit
- CPA firm selection and coordination
SOC 2 Type II / ISO + SOC 2 Programme
- ISO 27001 and SOC 2 controls built once, mapped to both
- Support through the SOC 2 Type II observation period
- Monthly evidence reviews and control checks
- Independent ISO 27001 internal audit
- Coordination with the certification body and CPA firm
- Pentest and vendor reviews planned in
Ongoing costs after launch
No surprises: here's everything you may pay every month, stated upfront.
Annual surveillance-audit support, or a vCISO retainer to keep controls running
See all ongoing plansCertification body / CPA auditor fees · compliance platform subscription
- —Certification-body fees for ISO 27001 Stage 1, Stage 2 and surveillance audits are paid directly by you to the accredited body.
- —CPA-firm fees for the SOC 2 Type I or Type II report are paid directly by you to the audit firm.
- —Compliance platform subscriptions (Sprinto, Vanta, Drata or similar) are paid directly by you.
- —A penetration test, often required as evidence, is quoted separately (see VAPT).
- —Security tools needed to meet controls (for example, device management or endpoint protection) are paid directly by you.
Want a quick estimate for your exact project? Try the cost estimator.
Process
From first message to launch.
Clear stages, a live preview link every week, and payments tied to milestones you approve.
- Step 01Weeks 1–2
Scoping & gap analysis
We agree scope, pick ISO 27001, SOC 2 or both, and show your gaps with a fixed-price plan.
- Step 02Weeks 3–10
Build the controls
Policies, risk assessment, technical fixes and platform setup, done alongside your team without stopping releases.
- Step 03Weeks 8–14
Evidence & internal audit
We collect evidence and run an independent internal audit and readiness check, then close any findings.
- Step 04Weeks 12–16+
External audit
Your certification body or CPA firm audits you. We prepare your team and support you through every session.
Technology
Tools we trust.
Our promises
Working with us is low-risk.
Fixed quote
A clear, fixed price after a 20-minute call. No surprise bills.
Pay in milestones
Projects: 40% to start, 30% on design approval, 30% at launch.
You own everything
Code, domain, ad accounts, WhatsApp number and data — in your name.
Weekly previews
See real progress on a live link every week, not just status updates.
30 days of free fixes
Anything not working as agreed after launch, we fix at no cost.
Talk to the builder
No account managers. You speak with the engineers doing the work.
FAQ
Questions, answered.
What decides the cost of ISO 27001 or SOC 2 readiness?+
Company size, the number of products, locations and cloud accounts in scope, how much is already in place and whether you want ISO, SOC 2 or both. Doing both together costs much less than two separate projects.
How long until we are audit-ready?+
Usually 8–16 weeks. A SOC 2 Type II report also needs an observation period, often 3–12 months, before the CPA firm can issue it. Many companies get a Type I report first to unblock deals.
Do you issue the ISO 27001 certificate or SOC 2 report?+
No. ISO 27001 certificates are issued only by accredited certification bodies, and SOC 2 reports only by licensed CPA firms. We do the implementation, readiness and internal audit, and coordinate with your chosen auditor. That separation is what makes the certificate credible.
Who does the internal audit if you also implement?+
ISO 27001 clause 9.2 requires internal auditors to be objective and impartial. So the internal audit is done by a member of our team who did not work on your implementation, and we can bring in an outside auditor if you prefer.
Do we need Sprinto, Vanta or Drata?+
Not always. They save time on evidence collection, especially for SOC 2 Type II. We help you decide, and set up whichever you choose. Subscriptions are paid directly by you.
Will you sign an NDA?+
Yes, before scoping starts. We work inside your systems and compliance platform where possible, so sensitive evidence stays with you.
What happens after the audit?+
ISO 27001 needs yearly surveillance audits and SOC 2 needs a fresh report each year. Our vCISO plans keep controls running and evidence fresh, so next year's audit is routine.
Often paired with
A senior security leader on a monthly plan: roadmap, policies, questionnaires and board reporting.
Manual and tool-based testing of web apps, mobile apps, APIs and cloud, with a free retest.
Find out where you stand: a security maturity check, gap analysis and a 90-day fix plan.
Let's scope your project.
One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.