Metaluxo
COMPLIANCE

Compliance for startups and SMEs, in plain English

What ISO 27001, SOC 2 and GDPR actually ask of a ten-person company — which parts genuinely apply at your size, and which can wait until they do.

ISO 27001 A management system, not a checklist. It asks you to decide what matters, write it down, and prove you follow it.
SOC 2 An auditor’s opinion on controls you claim to operate, over a window of time. Evidence collected as you go, or not at all.
EU GDPR Law, not certification. Lawful basis, records, and a defensible answer when someone asks what you hold and why.

Why bother this early

Because the first enterprise deal, the first funding round and the first breach all ask the same questions — and the answers take months to build, not days.

How a consultant helps

You get the judgement of someone who has run these projects before, without hiring for a role you can’t yet keep busy.

Start with a gap analysis
WHAT WE DO

Working with a small team

1 Unblock the deal in front of you. The questionnaire or security review currently holding up a contract, answered honestly and quickly — usually the reason anyone calls in the first place.
2 Decide what you actually need. ISO 27001, SOC 2, both or neither. A straight recommendation before you commit budget to a certification your buyers were not asking for.
3 Build the minimum credible programme. Policies, access control, logging and vendor management sized for your headcount rather than copied from a bank and quietly ignored.
4 Run the certification. Evidence, internal audit and auditor liaison through to the certificate, without pulling your engineers off the roadmap for a quarter.
5 Keep it alive. A reporting rhythm light enough that the programme survives your next hire, your next round and your next customer without a rebuild.
If a certification is not the fastest route to the outcome you want, we will say so. A gap analysis that ends in “not yet, and here is why” is still a useful answer.
WHAT GETS ASKED

What buyers and investors actually ask for

The questionnaire Two hundred questions from a buyer’s security team, usually arriving with a deadline attached to a signature.
A certificate ISO 27001 or a SOC 2 report — increasingly a procurement gate rather than a differentiator.
GDPR answers A data processing agreement, a sub-processor list, and a clear account of what you hold and on what basis.
Test evidence A recent penetration test and a vulnerability management process that shows findings are actually closed.
COMMON QUESTIONS

Startups & SMEs, in short

Do we need ISO 27001 or SOC 2?
Possibly neither. ISO 27001, SOC 2, both or neither is a straight recommendation made before you commit budget to a certification your buyers were not asking for.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is a management system, not a checklist — it asks you to decide what matters, write it down and prove you follow it. SOC 2 is an auditor’s opinion on controls you claim to operate, over a window of time, with evidence collected as you go.
Why start on compliance this early?
Because the first enterprise deal, the first funding round and the first breach all ask the same questions, and the answers take months to build rather than days.
INSIGHTS · STARTUPS & SMES Writing for this sector
All insights →
The first pieces for this sector are in preparation. Ask Roberto directly in the meantime — vciso@metaluxo.com.
How we help

What Startups & SMEs usually need

Compliance & ISO 27001Gap assessment to Stage 2, about nine monthsVirtual CISOPart-time security leadership, 30–40 hrs a monthEmergency responseTwelve-hour response, notification clocks handled
Send us a message
Message us Book now