- A customer or tender has made ISO 27001, SOC 2, C5 or ISO 9001 a condition of doing business
- A supplier audit is announced, or a security questionnaire has arrived that you cannot honestly answer
- Your certificate expired, or the transition to ISO 27001:2022 was missed
- You are entering a regulated customer segment, or the German-speaking market
- Or you are certified and know the system is not actually running
- One entity, one standard, one primary service or product line
Certification & Customer-Audit Readiness
ISO 27001, SOC 2 or C5 built into the way you work, from gap to certificate.
- 14–18 weeks
- ~32–36 consulting days
- From 900,000 HUF + VAT
- Independent of the certification body
The problem
A customer just made the certificate a condition of the contract.
Certification has quietly become a revenue gate. No certificate, no contract, no tender — and increasingly no place on a larger company’s supplier list, because their own obligations now flow down to you. The deadline arrives with the requirement.
So someone buys a policy template pack, and it describes a company that is not yours. Auditors interview staff; a system nobody follows fails at Stage 2, or survives as an annual emergency that costs the same every year and protects nothing. The certification body quoted for the audit only. The consultant quoted for "an ISMS" with no end date.
And if your ISO 27001 certificate is still on the 2013 edition, it expired in October 2025 — which means you are uncertified while believing you are certified.
Who it's for
- Managing directors, CTOs and heads of delivery in software companies; CFOs when certification gates revenue
- Software houses, IT service providers, SaaS operators and B2B suppliers to banks, insurers, telecoms and the public sector
- The security or quality owner is the working counterpart; process owners across the scope participate
- Two standards at once, multi-entity scopes, or regulated-product development are quoted individually
What happens
Seven steps, fourteen to eighteen weeks.
- Intake and scope One week. Sponsor kick-off, the standard confirmed, customer requirements collected — and the scope workshop, which matters more than anything that follows: a small honest scope certifies, a large ambitious one multiplies findings.
- Readiness assessment One to two weeks. Every requirement and control of the chosen standard rated, the triggering questionnaire or supplier audit triaged, and a verdict with a dated plan to Stage 1 and Stage 2.
- Scope Statement One week. Standard, scope statement, gaps in scope, processes, MSP boundary and the target audit window against your customer’s deadline. From here scope changes only by written change order.
- Risk and control design Four weeks. The risk method and register, the Statement of Applicability or equivalent control set, the policy set in your vocabulary, the control responsibility matrix, and the security requirements you pass on to your own suppliers.
- Control embedding and evidence Four to six weeks. Controls into your process descriptions as steps with owners and evidence points, the awareness plan run, and the first evidence collected — because an auditor samples evidence, not intentions.
- Internal audit Two weeks. We audit you to the same method the certification body will use, and the findings go into corrective actions rather than into a drawer.
- Management review and hand-over The review held and minuted against the standard’s required inputs, the evidence pack indexed, and a written verdict on whether you are ready for Stage 1.
ISO 27001 is the default lens; SOC 2, BSI C5 and ISO 9001 are selectable at the start and change the gap workbook, not the shape of the engagement. Premium adds implementation support, an awareness session, certification-body selection, a mock audit, and our presence beside you at Stage 1 and Stage 2.
What you get
A management system, not a binder.
A proposed scope with the reasoning behind it, every requirement and control rated with the finding to expect, and a dated plan to certification.
Standard, management-system scope, gaps in scope, processes, MSP boundary, deliverables and the audit window. The scope baseline.
The method the standard requires, and the working register: assets, threats, current controls, residual risk, treatment, owner — approved at a minuted management review.
Every Annex A control with its applicability decision, justification, status, owner and evidence reference — or the equivalent control set for SOC 2, C5 or ISO 9001.
Written in your words and mapped to the processes that execute them, because the auditor will ask your staff about them and staff cannot follow a document written for someone else’s company.
A real internal audit to ISO 19011 with findings and corrective actions, the minuted management review, the evidence index with first evidence collected, a questionnaire response library, and the ready-for-Stage-1 verdict.
Packages
- Entry — certification readiness assessment The scope workshop, a full gap assessment against your chosen standard, the triggering questionnaire triaged, and an honest verdict with a plan and a timeline. 900,000 HUF + VAT.
- Standard — built to readiness Everything on this page, up to and including the internal audit and management review. 5,000,000 HUF + VAT, fixed price.
- Premium — through Stage 1 and Stage 2 Standard plus implementation support, an awareness session, certification-body selection, a mock audit, and our presence at the certification audit with nonconformity responses. Quoted individually.
- Custom Two standards in one programme, multi-entity or multi-site scopes, regulated-product development, SOC 2 Type 2 examination support. Quoted individually.
Certification body or CPA fees are paid by you and are not included. Clients who completed NIS2 Audit Readiness receive a 15% credit against Standard, because a large part of the control set overlaps.
- The managing director or a delegate as sponsor, and an information-security or quality owner as counterpart
- Existing documentation, customer requirements and any prior audit reports
- Your MSP contractually required to cooperate and provide evidence
- Process owners’ participation — controls that are embedded without them are controls nobody runs
- The certification body contracted in time for the audit window in the Scope Statement
- Not the certification audit itself — that is the certification body or an accredited CPA, and we are deliberately independent of them
- Not a template pack: policies written for your company, because auditors interview your staff
- Not security tooling procurement
- Not hands-on technical implementation — Premium coordinates it; your IT or MSP executes
- Not certification maintenance after the certificate — surveillance-audit readiness is available separately
Next step
Find out what the scope should be first.
Most failed certifications are scoping failures, decided in the first week and paid for in the twentieth. The readiness assessment settles the scope, tells you what a certificate would take, and answers this year’s questionnaires on the way.