Contents
Context
A Series B fintech serving European mid-market customers was hitting a recurring objection in late-stage enterprise sales: prospects required both ISO 27001 certification and a SOC 2 Type 2 report. The engineering team had decent security hygiene but had grown organically rather than against a framework, and the leadership team had no appetite for a security programme that consumed engineering attention for a full year.
The brief: get certified against both frameworks, in parallel, in six months, with minimum disruption to engineering velocity.
The dual-framework strategy
Most compliance consultancies recommend tackling frameworks sequentially — ISO 27001 first, then SOC 2 (or vice versa) — because each requires its own evidence collection, control documentation, and audit cycle. The sequential approach minimises risk per cycle but maximises total cost.
We started with a control-mapping exercise: every ISO 27001 Annex A control was mapped against every SOC 2 Trust Service Criteria control, with each mapping classified into one of three categories — direct overlap (~60% of controls), partial overlap requiring minor adaptation (~25%), or framework-specific (~15%).
The result was a single control catalogue covering both frameworks, with most controls satisfying both. Evidence collected for ISO would also satisfy SOC; policies written for SOC would also satisfy ISO. Effort scaled at roughly 1.35× a single framework instead of 2×.
The six-month programme
Months 1–2 — Gap assessment and programme design. Current-state baseline against the unified control catalogue. Output was a prioritised gap register with each gap tagged by framework, by effort, and by impact.
Months 2–4 — Control implementation. Policy documentation, procedure design, and (critically) evidence-collection automation. We invested heavily in building tooling that would generate audit evidence automatically from existing systems — CI/CD pipelines, IAM logs, vulnerability-management platforms — so that ongoing compliance would not require ongoing human effort.
Month 5 — Internal audit and readiness review. A full mock audit run against both frameworks. Identified a small number of remaining gaps, all closed before the external auditors started work.
Month 6 — External audits. ISO 27001 certification audit ran in parallel with the SOC 2 Type 2 observation period close. ISO certification was issued cleanly on first attempt. The SOC 2 report was issued with one minor exception relating to a control that had been adjusted mid-observation period.
Outcomes beyond the certificate
The most durable outcome of the engagement was not the certifications — those are checkboxes — but the evidence-collection automation, which now generates ~80% of audit-required evidence without human intervention.
Two enterprise contracts that had been stalled on compliance were closed within thirty days of the ISO certification announcement. The client retained 8bytes on a quarterly post-certification retainer covering surveillance audit support, evidence collection oversight, and policy reviews against framework updates.
Tags