Case study · SaaS / Professional Services · Oslo, Norway
ITSECOPS took an Oslo SaaS company from no formal security programme to a certification-ready ISO 27001 ISMS — risk register, Statement of Applicability, policies and internal audit — in one focused engagement.
The client
A growing SaaS provider in Oslo whose enterprise prospects had started sending security questionnaires it could not answer — and two RFPs required ISO 27001 outright.
The challenge
No ISMS, no risk register, policies scattered across wikis, and a small team that could not absorb a bureaucratic, template-dump approach to certification.
What we did
- Scoped the ISMS around the SaaS platform and the people who run it — not the whole company org chart.
- Ran the risk assessment and mapped treatments to the ISO/IEC 27001:2022 Annex A controls (all 93 dispositioned in the Statement of Applicability).
- Wrote policies people actually read: short, role-addressed, linked from the tools where work happens.
- Conducted the internal audit and management review, and prepared the team for the stage 1 / stage 2 certification audits.
- Cross-mapped the ISMS to NIS2 duties so the Norwegian digitalsikkerhetsloven angle is covered by the same evidence.
Results
- Certification-ready ISMS with a clean internal-audit report.
- Security questionnaires now answered from the SoA in hours, not weeks.
- One artefact set serving both ISO 27001 and NIS2 obligations.
FAQ
How long does ISO 27001 implementation take?
For a 20–100 person company: typically 3–6 months to certification-ready, driven mostly by how fast decisions get made, not by document volume.
ISO 27001 or NIS2 first for a Nordic company?
Do them together. NIS2 is law, ISO 27001 is proof — a well-scoped ISMS generates the evidence both require.
What does ISO 27001 consulting cost?
Far less than a failed audit cycle. See our readiness consulting page for the engagement model.