iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 consultants for SaaS and cloud businesses

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 8 min read
3 primary sources cited on this page. How we check what is on this site

For a SaaS business the certificate is almost always a sales document before it is a security one. It arrives because an enterprise buyer’s vendor-risk team asked for it, which means the thing that matters most is not whether you have it but what the scope on it says.

The questionnaire arrives before the certificate does

For most SaaS companies the sequence is not “get certified, then sell”. It is a security questionnaire landing mid-deal, a two-week turnaround, and someone in engineering losing a fortnight to a spreadsheet. The certificate is what you buy so that the next one is cheaper.

It is worth being realistic about how much cheaper. A certificate does not end questionnaires. Enterprise vendor-risk teams still send them, and they still contain questions the certificate does not answer: where data is processed and stored, who your sub-processors are, what your recovery time objective is, whether you have had a breach. What changes is that a large block of the questionnaire — governance, risk management, access control, incident response, staff training, supplier management — can be answered from evidence that already exists, by whoever owns the ISMS, rather than reconstructed by an engineer each time.

That reframes the business case in a way finance teams find easier to accept. The return is not a certificate on a website. It is the difference between a fortnight of senior engineering time per enterprise deal and an afternoon of it, multiplied by however many of those deals you expect.

Two practical notes. Keep a current sub-processor list, with what each one does and where: it is asked for in almost every questionnaire and it is also an Annex A supplier control, so it is one artefact doing two jobs. And keep the answers themselves somewhere versioned, because the inconsistency between two questionnaires answered six months apart by different people is what turns a routine review into a call.

The scope on the certificate is what your customer reads

A certificate names what was audited. For a product company that is the single most consequential decision in the whole exercise, and it is taken early, usually before anyone has explained what it will mean.

Certify the company and everything is in: the marketing team, the finance system, the office. The headcount is your whole payroll, so the audit-day band is higher and the audit costs more. Certify the product — the platform, the engineers who build it, the systems it runs on — and the headcount is smaller, the audit is shorter, and the certificate says exactly the thing your customer wanted to know.

The failure mode is a scope drawn narrowly to save money that then excludes something the customer assumed was covered. Support, for instance: if your support team can see customer data and support is outside the scope, a vendor-risk reviewer who reads the schedule will notice. Draw the scope around what the customer is buying, not around what is cheapest to audit.

The cloud control that did not exist before 2022

A.5.23, information security for use of cloud services, is one of the controls introduced in the 2022 edition. In the previous edition cloud was handled as ordinary supplier risk; now it has its own control covering the acquisition, use, management and exit from cloud services.

Exit is the part that catches SaaS businesses, because it is the part nobody has thought about. An auditor asking how you would leave your primary cloud provider is not expecting a migration plan with dates. They are expecting evidence that the question has been considered and that the dependency is understood, and “we would be in serious trouble” delivered confidently, with a documented assessment behind it, is a better answer than a fictional plan.

The related trap is the shared responsibility boundary. Your cloud provider’s own certificate covers the provider’s controls, not yours. You cannot inherit compliance from it, and an auditor will ask which controls you rely on them for, how you assured yourself of that, and what you do that they do not.

Multi-tenancy, environments, and real data in the wrong place

Two technical questions come up in almost every SaaS audit and both are worth settling before Stage 1 rather than during it.

Tenant separation. How is one customer’s data kept from another’s, and how do you know it works? The answer is architectural and the evidence is usually a test. A team that can show an automated test proving cross-tenant access fails is in a much stronger position than one relying on an assertion about how the code is written.

Production data in non-production environments. A.8.11, data masking, is another of the new controls, and this is where it lands. Copying a production database into staging to reproduce a bug is common, understandable, and hard to defend to an auditor if it is undocumented and unbounded. Either stop doing it, or have a controlled, time-limited, approved process for when it happens.

ISO 27001 and SOC 2 are not the same shape

Most UK SaaS companies selling into the United States meet both, and they are frequently described as interchangeable. They are not, and the difference decides which one you should do first.

ISO 27001 certifies a management system: it asks whether you have a process for identifying and treating information security risk, and whether it is running. It is audited by an accredited certification body and the output is a certificate. SOC 2 is an attestation by an accountancy firm about controls against the Trust Services Criteria over a period, and the output is a report that the reader has to read.

Practically: a European or UK enterprise buyer usually asks for ISO 27001; a United States buyer usually asks for SOC 2. If both are coming, the controls overlap heavily and the evidence is largely reusable, which is the strongest case for a compliance platform that handles both. What does not transfer is the management system itself — the risk assessment, the Statement of Applicability and the management review have no SOC 2 counterpart.

What this does not change

Whatever sits on top, the arithmetic underneath is the same for every sector. Audit days come from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) and are a function of the people inside your scope, your sites and your complexity. Surveillance is one third of the initial audit every year and recertification is two thirds in year three. Your certification body cannot be your consultant, and cannot do the internal audit clause 9.2 requires.

Work out the cost for your headcount, or see the full audit-day table.

Common questions

Can the scope cover just our product rather than the whole company?

Yes, and for a product business it is usually the right answer. The scope is your decision under clause 4.3 and a narrower one is legitimate, cheaper to audit and faster. The constraint is honesty: the scope is printed on the certificate, procurement teams read it, and a scope that excludes something your customer assumes is covered is worse than no certificate. Draw it around what the customer is buying.

Does our cloud provider's certification cover us?

No. Your provider's certificate covers your provider's controls. You cannot inherit compliance, and this is one of the more expensive misunderstandings in the area. What their certificate does is help you evidence your own supplier controls, and A.5.23 in the 2022 edition asks specifically about how you acquire, use, manage and exit cloud services — all of which are your responsibilities, not theirs.

Should we do SOC 2 or ISO 27001 first?

Follow the customer who asked. A UK or European enterprise buyer almost always means ISO 27001; a US buyer almost always means SOC 2. If both are on the horizon, the control evidence overlaps heavily and doing them close together is materially cheaper than doing them years apart. What does not carry over is the management system — the risk assessment, Statement of Applicability and management review have no SOC 2 equivalent, so ISO 27001 is the larger structural change.

We are fully remote. What happens to the physical controls?

They still apply and they still need reasoning about, which is the part remote-first companies tend to skip. The physical theme has 14 controls in the 2022 edition. Homes are premises for this purpose: equipment siting, clear desk and screen, and secure disposal of devices all have a remote answer. Excluding the whole theme because there is no office is the finding; excluding specific controls with a stated justification is the requirement.

How long does this take for a 30-person SaaS company?

The binding constraints are the same as for anyone: an internal audit under clause 9.2 and a management review under clause 9.3 have to have happened, and both need the management system to have been running long enough to produce something to examine. What SaaS companies often have in their favour is that a lot of the technological theme is already in place and evidenced in CI and infrastructure tooling. What they most often lack is the management-system machinery, which is where the time goes.

Sources cited on this page

  1. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  2. ISO/IEC 27002:2022, Information security controls
  3. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Get a costed answer, not a call-back to discuss pricing

Five questions, all of them click-only. Your details are the last step, never the first.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now