" /> ISO 27001 Implementation: Oslo SaaS Case Study | ITSECOPS
Case study

ISO 27001 Implementation for an Oslo SaaS Company

Updated · Aug 2026 By ITSECOPS Free · No signup

Case study · SaaS / Professional Services · Oslo, Norway

ITSECOPS took an Oslo SaaS company from no formal security programme to a certification-ready ISO 27001 ISMS — risk register, Statement of Applicability, policies and internal audit — in one focused engagement.

The client

A growing SaaS provider in Oslo whose enterprise prospects had started sending security questionnaires it could not answer — and two RFPs required ISO 27001 outright.

The challenge

No ISMS, no risk register, policies scattered across wikis, and a small team that could not absorb a bureaucratic, template-dump approach to certification.

What we did

  • Scoped the ISMS around the SaaS platform and the people who run it — not the whole company org chart.
  • Ran the risk assessment and mapped treatments to the ISO/IEC 27001:2022 Annex A controls (all 93 dispositioned in the Statement of Applicability).
  • Wrote policies people actually read: short, role-addressed, linked from the tools where work happens.
  • Conducted the internal audit and management review, and prepared the team for the stage 1 / stage 2 certification audits.
  • Cross-mapped the ISMS to NIS2 duties so the Norwegian digitalsikkerhetsloven angle is covered by the same evidence.

Results

  • Certification-ready ISMS with a clean internal-audit report.
  • Security questionnaires now answered from the SoA in hours, not weeks.
  • One artefact set serving both ISO 27001 and NIS2 obligations.

FAQ

How long does ISO 27001 implementation take?

For a 20–100 person company: typically 3–6 months to certification-ready, driven mostly by how fast decisions get made, not by document volume.

ISO 27001 or NIS2 first for a Nordic company?

Do them together. NIS2 is law, ISO 27001 is proof — a well-scoped ISMS generates the evidence both require.

What does ISO 27001 consulting cost?

Far less than a failed audit cycle. See our readiness consulting page for the engagement model.

BOOK A FREE CONSULTATION

Need help applying this to your environment?

We turn compliance guides into shipped controls. Talk to an engineer.

Book a consultation