Metaluxo
COMPLIANCE

ISO 27001 and the frameworks your customers ask for

Certification is rarely the goal. Closing the deal is the goal, and certification is what stands between you and it. We build the management system, run the programme and stay with you through the audit, so the certificate reflects something your company actually does.

Book a free 30-minute consultation
~4 wksGAP ASSESSMENT
~9 mthsTYPICAL PATH TO STAGE 2
93ANNEX A CONTROLS
3 yrsCERTIFICATION CYCLE
REFERENCE

Which framework do you actually need?

Most companies arrive having been told a framework name by a customer, an investor or a regulator, and the first useful thing we can do is tell them whether it is the right one. The short answer: ISO 27001 and SOC 2 are things you choose in order to sell; GDPR, NIS2 and DORA are things that apply to you whether you choose them or not.

FRAMEWORK WHAT IT IS STATUS WHERE IT BITES TYPICAL TRIGGER
ISO/IEC 27001 2022 revision
A certifiable management system for information security — the ISMS — audited by an accredited certification body on a three-year cycle. VOLUNTARY Recognised globally, and the default expectation of European and UK enterprise buyers. An enterprise customer or a tender requires certification before signing.
SOC 2 Type I or Type II
An attestation report on your controls, issued by a licensed CPA firm. Type II covers an observation period rather than a point in time. VOLUNTARY Almost exclusively asked for by buyers in the United States. A US customer sends a security review and asks for your SOC 2.
GDPR Regulation (EU) 2016/679
Data protection law. Article 32 requires appropriate technical and organisational security measures; it does not certify anything. MANDATORY Any organisation processing personal data of people in the EU, wherever it is based. A supervisory authority, a customer DPA, or a breach.
Cyber Essentials NCSC-backed, via IASME
A UK baseline of five technical control themes, self-assessed or independently audited at Plus level. VOLUNTARY The UK — frequently required for public sector contracts and increasingly in UK supply chains. A UK government or large UK buyer names it in procurement.
NIS2 Directive (EU) 2022/2555
Security and incident-reporting obligations for essential and important entities, transposed into national law by each member state. MANDATORY Listed sectors above a size threshold — and their suppliers, contractually. You are in scope, or your in-scope customer passes the requirement down.
DORA Regulation (EU) 2022/2554
ICT risk management, incident reporting, resilience testing and third-party oversight for the financial sector. MANDATORY EU financial entities and their critical ICT providers, since 17 January 2025. You are a financial entity, or you supply one.
One does not substitute for another An ISO 27001 certificate does not make you GDPR compliant, and GDPR does not require ISO 27001. The overlap is real and worth exploiting — a single control set can serve several of these at once — but the scoping decisions differ, so it is worth planning deliberately rather than assuming. This table is a planning aid, not legal advice.
HOW IT WORKS

Gap analysis, remediation, certified

The path below is a typical ISO 27001 programme for a small cloud company: about nine months from first conversation to Stage 2.

MONTH 1 MONTHS 2–7 MONTH 9
WEEKS 1–4
01. Gap analysis What you have, what the standard expects, and the honest distance between them. Fixed scope, agreed before we start. YOU END UP HOLDINGA findings report, prioritised, with owners against each gap.
MONTHS 2–7
02. Remediation Policies written, controls implemented, evidence collected as we go rather than the week before audit. YOU END UP HOLDINGA working policy set, risk register and evidence trail.
MONTH 9, TYPICALLY
03. Audit & handover We sit with you through the audit, then hand over a system your team can actually run without us. YOU END UP HOLDINGStage 2 completed, and a programme your team owns.
No consultant can guarantee a certificate. What is committed here is the sequence, the scope and the dates — the certificate is issued by your auditor.
THE PROGRAMME

Nine months, and what happens in each of them

A reference path for a small cloud company. The real drivers are contracted hours and how quickly your team decides — a tight scope moves faster, a distracted team takes longer.

FROM FIRST CONVERSATION TO STAGE 2 REFERENCE PATH, NOT A PROMISE
MONTH 1 Gap assessment Fixed scope, agreed before we start. Findings, owners and an honest view of the date.
MONTHS 2–3 Scope and risk What the ISMS covers, the risk method your team can repeat, and the Statement of Applicability.
MONTHS 3–6 Controls and policies Implemented against how you actually work, with evidence collected as we go.
MONTHS 7–8 Internal audit Training, management review, and Stage 1. Nothing reaches Stage 2 untested.
MONTH 9 Stage 2 We sit through the audit and handle the findings. The body issues the certificate, not us.
Certification then runs on a three-year cycle with annual surveillance audits. We support those too. Start with a gap assessment →
01

ISO 27001, end to end

For most clients this is the whole engagement. We lead the build of the information security management system rather than handing over a template pack and a checklist:

Scope. Deciding what the ISMS covers, which is the decision that most affects cost, effort and whether the certificate satisfies your customer.
Risk assessment and treatment. A method your team can repeat next year without us.
Statement of Applicability. Justified inclusions and exclusions across the Annex A controls, written to survive questioning.
Controls and policies. Implemented against how you actually work, not copied from a generic set.
Evidence and records. Assembled as we go, not reconstructed in a panic three weeks before Stage 2.
Awareness training and management review. The clauses companies routinely forget until the auditor asks.
Certification body selection. We help you choose an accredited body and understand what you are paying for.
Stage 1 and Stage 2. We stay through both audits and handle the findings.
Surveillance. Certification runs on a three-year cycle with annual surveillance audits. We support those too.
On timelines: a small cloud-based company can reach Stage 2 in around nine months. Treat that as a reference point, not a promise. The real drivers are how many hours are contracted and how quickly your team answers questions and makes decisions. A committed team with a tight scope moves considerably faster. A distracted one takes far longer.
02

Start with a gap assessment

Most engagements begin with a fixed-scope gap assessment, typically around four weeks. It covers your high-level security position and your cloud infrastructure, and it produces a clear answer to the question most companies are actually asking: how far are we, what will it take, and is the deadline realistic.

That output is useful whether or not you continue with us. If someone else is cheaper for the implementation, you will still know exactly what you are buying.

03

SOC 2 Type II readiness

We prepare companies for SOC 2 Type II reports scoped to the Security criterion, which is what enterprise buyers in the United States almost always ask for.

To be precise about the boundary: a SOC 2 report can only be issued by a licensed CPA firm. We are not that firm and never will be. We define the scope, design and implement the controls, prepare the evidence for the observation period and get you into a state where the audit is a formality rather than a discovery exercise.

04

GDPR, from the security side

We advise on the technical and organisational measures required under Article 32 of the GDPR: access control, encryption, logging, backup and restoration, supplier controls, and the security elements of breach detection and response.

We do not act as your Data Protection Officer, we do not act as an Article 27 representative, and we do not run your wider data protection programme. Those are roles for lawyers and privacy specialists. We work alongside your legal team or privacy counsel and cover the security half properly, rather than covering all of it thinly.

05

Internal audits, where we did not build the ISMS

ISO/IEC 27001:2022 requires that internal auditors be selected so as to ensure the objectivity and impartiality of the audit (clause 9.2.2). We take that seriously: we do not audit a management system we designed and built.

Where another party built your ISMS, or you built it in-house, we act as your contracted internal auditor. You get an audit that finds real nonconformities before the certification body does, which is the entire point of the exercise.

06

Other frameworks we work with

NIS2 (Directive (EU) 2022/2555), including the case where you fall outside its scope by size but inherit the requirements through an in-scope customer.
UK Cyber Essentials, the NCSC-backed baseline delivered through IASME, frequently required for UK government contracts and increasingly used in UK supply chains.
ISO 13485 environments, where we support the information security requirements that sit alongside a medical device quality management system, working with your quality team.

We do not work on US-specific regimes such as HIPAA, HITRUST or FedRAMP. If that is what your buyer requires, you need a specialist in that market and we will say so early.

07

Why not a platform, a template pack or a big firm

Compliance automation software Collects evidence well. It cannot scope your ISMS, make a risk decision on your behalf or sit across the table from an auditor.
A template policy pack Costs very little and fails at Stage 2, because auditors examine whether policies are implemented, not whether they exist.
A large consultancy Produces a thorough report and then leaves before the difficult part.
WHAT WE DO NOT DO Being told you need someone else is part of what you are paying for
Not a certification body Only an accredited body issues an ISO 27001 certificate, and only a licensed CPA firm issues a SOC 2 report. No consultant can guarantee either.
Not your DPO We cover the security half of GDPR properly rather than the whole of it thinly. Data protection officer and Article 27 representative are roles for privacy specialists.
Not US-specific regimes We do not work on HIPAA, HITRUST or FedRAMP. If that is what your buyer requires, you need a specialist in that market and we will say so early.
FAQ

Questions we get asked

Which compliance framework does our business need? Whichever one your buyer, investor or regulator is actually asking for — start there, not with the most thorough option. If a European enterprise customer is blocking the deal, that is usually ISO 27001. If the customer is American, it is usually SOC 2. GDPR, NIS2 and DORA are not choices: they apply or they do not, and the gap assessment establishes which.
SOC 2 or ISO 27001 first? Follow the revenue. Certify against whatever is blocking the deal in front of you, then add the second one on top of the control set you have already built. Running both together is usually more efficient than running them separately, because the controls overlap substantially.
Does GDPR require ISO 27001? No. GDPR requires appropriate technical and organisational measures under Article 32; it names no standard and issues no certificate. An ISMS built to ISO 27001 is a credible way to demonstrate those measures, which is why the two are often mentioned together, but one is a law and the other is a voluntary standard.
How long does ISO 27001 certification take? Around nine months is a reasonable planning assumption for a small cloud-based company, but it varies widely with contracted hours, scope and how quickly your team responds. We give you a realistic date after the gap assessment, not before.
Can you guarantee we pass the audit? No, and nobody honestly can. Only an accredited certification body issues the certificate. What we can do is make sure nothing reaches Stage 2 that we have not already tested ourselves.
Do you issue SOC 2 reports? No. Only a licensed CPA firm can. We handle readiness and preparation so the audit goes smoothly.
Will you run our internal audit if you built the ISMS? No. The standard requires objectivity and impartiality in internal auditing, and auditing our own work would compromise that. We help you appoint someone independent.
Do you work with Vanta, Drata or similar platforms? We are platform agnostic. We will work inside whichever tool you already pay for, and we will tell you honestly if the subscription is not earning its keep at your size.
Can you do ISO 27001 and SOC 2 at the same time? Yes, and it is usually more efficient than running them separately, since the control sets overlap substantially. The scoping decisions differ, so this is worth planning deliberately rather than assuming.
We already failed an audit. Can you help? Yes. Remediating a failed or stalled certification attempt is a common starting point, and the gap assessment is where we begin.
RELATED SERVICES Virtual CISO → Emergency response → Startups & SMEs →

Book a free 30-minute consultation

Tell us which framework, which customer is asking for it, and what date you are working towards. We will tell you whether that date is achievable and what it would take.

compliance@metaluxo.com
FIRST CALL 30 MIN
That did not go through. Please write to compliance@metaluxo.com directly — we will still reply within a working day. Thank you — your message is on its way. Roberto replies within one working day. No slide deck, no discovery call chain — one conversation with Roberto.
Who it is for

Sectors we do this in

FintechPayments and financial data companies under DORA and ICT risk rulesHealthcare & HealthTechSpecial category patient data, NIS2 duties and hospital procurement reviewsStartups & SMEsBlocked enterprise deals, security questionnaires and investor due diligence
Send us a message
Message us Book now