Which framework do you actually need?
Most companies arrive having been told a framework name by a customer, an investor or a regulator, and the first useful thing we can do is tell them whether it is the right one. The short answer: ISO 27001 and SOC 2 are things you choose in order to sell; GDPR, NIS2 and DORA are things that apply to you whether you choose them or not.
Gap analysis, remediation, certified
The path below is a typical ISO 27001 programme for a small cloud company: about nine months from first conversation to Stage 2.
Nine months, and what happens in each of them
A reference path for a small cloud company. The real drivers are contracted hours and how quickly your team decides — a tight scope moves faster, a distracted team takes longer.
ISO 27001, end to end
For most clients this is the whole engagement. We lead the build of the information security management system rather than handing over a template pack and a checklist:
Start with a gap assessment
Most engagements begin with a fixed-scope gap assessment, typically around four weeks. It covers your high-level security position and your cloud infrastructure, and it produces a clear answer to the question most companies are actually asking: how far are we, what will it take, and is the deadline realistic.
That output is useful whether or not you continue with us. If someone else is cheaper for the implementation, you will still know exactly what you are buying.
SOC 2 Type II readiness
We prepare companies for SOC 2 Type II reports scoped to the Security criterion, which is what enterprise buyers in the United States almost always ask for.
To be precise about the boundary: a SOC 2 report can only be issued by a licensed CPA firm. We are not that firm and never will be. We define the scope, design and implement the controls, prepare the evidence for the observation period and get you into a state where the audit is a formality rather than a discovery exercise.
GDPR, from the security side
We advise on the technical and organisational measures required under Article 32 of the GDPR: access control, encryption, logging, backup and restoration, supplier controls, and the security elements of breach detection and response.
We do not act as your Data Protection Officer, we do not act as an Article 27 representative, and we do not run your wider data protection programme. Those are roles for lawyers and privacy specialists. We work alongside your legal team or privacy counsel and cover the security half properly, rather than covering all of it thinly.
Internal audits, where we did not build the ISMS
ISO/IEC 27001:2022 requires that internal auditors be selected so as to ensure the objectivity and impartiality of the audit (clause 9.2.2). We take that seriously: we do not audit a management system we designed and built.
Where another party built your ISMS, or you built it in-house, we act as your contracted internal auditor. You get an audit that finds real nonconformities before the certification body does, which is the entire point of the exercise.
Other frameworks we work with
We do not work on US-specific regimes such as HIPAA, HITRUST or FedRAMP. If that is what your buyer requires, you need a specialist in that market and we will say so early.
Why not a platform, a template pack or a big firm
Questions we get asked
Book a free 30-minute consultation
Tell us which framework, which customer is asking for it, and what date you are working towards. We will tell you whether that date is achievable and what it would take.
compliance@metaluxo.com