ISO 27001 and SOC 2 consultancy

Certification is a build job, not a paperwork job. Our engineers build the controls into your systems and our in-house lawyer writes the policies and agreements, so the evidence exists before the auditor arrives. Then we keep it current, year after year.

Most firms will tell you to hire a developer to build your platform and a separate ISO 27001 consultant to get your business certified. We do both: the same team builds the platform and takes your business through its own audit.

What we work to

  • ISO/IEC 27001, information security
  • SOC 2, the security report US and enterprise buyers ask for
  • UK GDPR
  • HIPAA, for products handling US patient data
  • Telecoms rules in the UK, the US and Canada

How ISO 27001 implementation runs

  1. Scope.

    We agree what the certificate covers and what it doesn't.

  2. Gap review.

    We compare where you are with what the standard asks.

  3. Controls and policies.

    Engineers change the systems; our lawyer writes the documents.

  4. Evidence.

    Collected as you work, not reconstructed the week before.

  5. Audit.

    An independent accredited body of your choosing examines it. We sit beside you.

  6. Keeping it.

    Continuous monitoring, the yearly surveillance audits and recertification.

We prepare you. Someone independent certifies you.

We never certify you ourselves and we never sell a badge. The certificate is worth having because an independent, accredited body issues it.

Proof

CX Assist went from first build to live, ISO/IEC 27001:2022 certified and SOC 2 Type 1 attested within 18 months. Its SOC 2 Type 2 audit is under way.

Read the CX Assist case study

Questions

How long does ISO 27001 take?

It depends on where you start. The free systems review gives you an honest estimate before you commit to anything.

Are these your own certifications?

They belong to CX Assist, the platform we built and took through them. We bring the same engineers and the same lawyer to yours.

What happens after the certificate?

It needs keeping. ISO/IEC 27001 has a surveillance audit every year and recertification every three, and SOC 2 Type 2 reports on a rolling period. We run all of it as an ongoing service.

Find out what your systems should be doing.

A free call with Paul Hanner, then a written summary of what we'd keep, change and build first.

Book a free systems review