ISO 27001 readiness

ISO 27001 readiness and consulting for startups

An ISO 27001 readiness engagement gets your ISMS, risk register, and Annex A controls audit-ready before the certification body arrives. Xorabyte runs it for you, led by a practitioner who has owned SOC 2 and ISO 27001 compliance end to end for a company, scoping through auditor sign-off.

Who this is for

When ISO 27001 is the right framework

Startups selling into Europe, the UK, or other international markets where buyers ask for ISO 27001 by name.
Companies whose enterprise buyer asks for ISO 27001 instead of, or alongside, SOC 2.
Teams that already hold SOC 2 and want the second certificate without redoing the work they have already done.

Not sure which framework fits your buyers? See SOC 2 vs ISO 27001 for how the two compare on buyers, structure, timeline, and cost.

What readiness covers

What an ISO 27001 consultant handles

Scoping the Information Security Management System (ISMS): which parts of the business, systems, and locations the certification will cover.
Context and interested parties: the internal and external issues and stakeholder requirements that shape what the ISMS needs to address.
The risk assessment and risk treatment plan: identifying information security risks, then deciding how each one gets treated, reduced, or accepted.
The Statement of Applicability: the document mapping every one of the 93 Annex A controls to whether it applies to you, and why.
Annex A controls: all 93 controls across the 4 themes in ISO/IEC 27001:2022, organizational, people, physical, and technological, mapped to what you actually run.
Policies: the written security policies an auditor expects to see behind each control, matched to your actual environment, not pulled from a generic template.
Internal audit: a structured check that the ISMS is working as designed, run before the certification body ever shows up.
Management review: leadership sign-off on the ISMS’s performance, risks, and improvement plan, the way the standard requires.
Deliverables

You leave with a plan, not a binder

A gap list scored against the full Annex A control set, not a generic checklist.
A risk register with owners, treatment decisions, and a plan to close what is open.
A Statement of Applicability an auditor can review without follow-up questions.
A prioritized remediation plan with an owner and effort estimate per item.
An audit-ready ISMS: policies, evidence, and records that hold up under Stage 1 and Stage 2.

The certification audit: Stage 1 and Stage 2

ISO 27001 certification runs through an external audit in two stages. Stage 1 is a documentation review: the certification body checks that your ISMS scope, risk assessment, Statement of Applicability, and mandatory policies exist and hang together. Stage 2 is the implementation audit: the certification body checks that the controls in your Statement of Applicability are actually operating, with evidence to back it up.

The certificate itself is issued by an accredited certification body, not by Xorabyte. Xorabyte prepares you for both stages and stays with you through fieldwork, but the independent judgment that decides certification belongs to the certification body alone.

Timeline

It is 4 to 12 months for most startups, depending on size. A small, cloud-native team with clean access controls and an owner who can dedicate real time to the ISMS moves toward the faster end. A larger team, a wider scope, or controls that need to be built from nothing moves toward the slower end. The gap assessment itself runs a few weeks and ends with a dated, scored plan instead of a guess.

What an ISO 27001 consultant costs here

Engagements start with the Audit-Readiness Gap Assessment, a fixed-scope step at $6,000 to $9,000 USD: a scored view of where you stand against the full Annex A control set and a prioritized remediation plan. From there, most teams run the program on a monthly retainer through the certification audit rather than as a separate fixed-scope sprint. Growth runs $7,000 to $7,500 a month and Command runs $10,000 to $12,000 a month; both tiers include driving ISO 27001 to completion, not just maintaining what is already in place. See the pricing page for the full ladder.

Read next

The ISMS, Annex A, and what certification costs

ISO 27001 readiness FAQ

How long does ISO 27001 readiness take?

It is 4 to 12 months for most startups, depending on size, and depends on how much of the ISMS already exists. A small, cloud-native team with clean access controls can move faster than a company still writing its first security policy.

What does ISO 27001 readiness cost?

Engagements start with the Audit-Readiness Gap Assessment, $6,000 to $9,000 USD, a scored view of where you stand and a prioritized plan. From there, most teams run the program on a monthly retainer through the certification audit: Growth at $7,000 to $7,500 a month or Command at $10,000 to $12,000 a month, both of which include driving ISO to completion. See the pricing page for the full ladder.

ISO 27001 vs SOC 2: which one do I need?

ISO 27001 is a certificate, process-driven and recognized globally. SOC 2 is an audit report, evidence-driven and dominant with US enterprise buyers. Many startups selling internationally end up pursuing both, and the control overlap between them usually makes the second framework easier than the first.

Does Xorabyte issue the ISO 27001 certificate?

No. The certificate is issued by an accredited certification body after the Stage 1 and Stage 2 audits. Xorabyte does the readiness work before that: scoping, the risk assessment, the Statement of Applicability, Annex A implementation, and getting your evidence ready for the auditor to review.

Do we need a compliance platform for this?

No. We work inside the tools you already use, including a compliance platform such as Vanta or Drata if you have one. If you do not, we keep your risk register, Statement of Applicability, and evidence tracked for you and walk you through status every month.

Who runs the engagement?

Xorabyte is founder-led by Arif Mohamed, a senior security engineer who has taken a company through SOC 2 end to end, solo, on the company side: scoping through auditor sign-off. You work directly with that practitioner, not a bench.

Founder-led

Xorabyte is founder-led by Arif Mohamed, a senior security engineer who has taken a company through SOC 2 end to end: scoping, control implementation, evidence collection, and auditor management, personally and solo. With over six years across security and infrastructure, engagements are delivered by someone who has configured the VPCs, managed the cloud resources, and sat through the audit, not summarized someone else's report.

Earlier experience at ISA Cybersecurity, one of Canada's largest security firms. Based in the Greater Toronto Area, working remotely with startups across Canada and the US.

Start with a scoping call.

Tell us what triggered the ISO 27001 push. You leave the call with a clear path to certification.