Readiness assessment
Two weeks. Establishes where you stand against ISO 27001, SOC 2 Type II, or both, what it takes to close the gaps, and the plan for the implementation.
Deliverables
- Gap analysis. Each ISO 27001:2022 and SOC 2 control rated present, partial or absent, with the evidence reviewed and the remediation required, prioritised by risk.
- Architecture map. Systems, data flows, trust boundaries and sub-processors on one diagram, in the form auditors and enterprise buyers request.
- Penetration test plan. Targets, test types, exclusions and rules of engagement, ready to send to testing firms for quotation.
- Implementation roadmap. Policies, infrastructure, pipeline, application and evidence automation work, sequenced by month, with ownership assigned.
- Proposal. Scope, start date and audit calendar for the implementation.
Scope and access
- Read-only access to the cloud accounts, source repositories, CI/CD pipelines and identity provider in scope.
- Existing policies, the most recent penetration test report and the most recent customer security questionnaire, where available.
- Interviews with the CTO, the head of sales, the lead engineer and the operations lead.
An NDA is signed before access is granted. No changes are made to any system. Access is revoked on the final day.
Timeline
| Day | Activity |
|---|---|
| 1 | NDA, access provisioning, kickoff |
| 2 to 5 | Interviews, inventory of cloud, code and identity, document review |
| 6 to 9 | Control mapping, architecture map, penetration test plan, roadmap |
| 10 | Readout to the founders, proposal delivered, access revoked |
If the implementation does not go ahead
You retain a prioritised, actionable report your team can execute independently.
Request the assessment.
marius@keibisoft.com · Telegram · LinkedIn
Reply within 24 hours. Start within two weeks, or within 48 hours for an urgency fee. All services.