Blog

Practical guidance on ISO 27001, SOC 2, ISO 42001, GDPR and penetration testing for scaling software companies.

  • GDPR Certification: What Exists, What Does Not, and What Buyers Accept

    There is no official GDPR certificate. No EU body issues one, no company can hold one, and any provider selling a “GDPR certified” badge is selling something the regulation does not recognise. What exists instead: approved certification schemes under Article 42 (Europrivacy is the first), ISO 27701 as the certifiable privacy management standard, and the evidence…

  • ISO 42001 Internal Audit: What the Standard Requires

    Target queries: “iso 42001 internal audit requirements” · “iso 42001 clause 9.2” · “who audits an AI management system” Last reviewed: 28 August 2026. This page is refreshed quarterly; the next scheduled review is November 2026. Volatile facts are date-stamped where they appear. The direct answer: ISO/IEC 42001:2023 clause 9.2 requires your organisation to run internal audits of its…

  • UK GDPR vs EU GDPR: What Is Actually Different

    UK GDPR and EU GDPR are substantively near-identical, because UK GDPR is retained EU law. Comply with one properly and you are most of the way to the other. The differences that create real work are administrative: a second representative, second transfer contracts, a second regulator, an annual ICO fee and fines in a different…

  • ISO 42001 Certification Bodies: Who Is Actually Accredited (and Who Is Not)

      Byline: Mahrukh Fatima Last reviewed: 30 August 2026. This list is refreshed quarterly against the accreditation bodies’ own registers. As of 07-08-2026, 15 verified certification bodies hold a tier-1-verifiable accreditation to certify organisations against ISO/IEC 42001, across six accreditation bodies: ANAB (United States), UKAS (United Kingdom), RvA (Netherlands), JAS-ANZ (Australia and New Zealand), SAC (Singapore) and IAS (United…

  • Drata Partners in the UK and Ireland: Who They Are and How to Choose

    Last reviewed: 7 August 2026. This list is refreshed quarterly; partner tiers, review counts and other volatile details are date-stamped as of 07-08-2026. Quick answer: If you have chosen Drata and need help implementing it in the UK or Ireland, the question that matters is who will actually run your programme and where they sit.…

  • ISO 27001 Consultants for Software Companies: How to Choose, Who to Consider

    Last reviewed: 7 August 2026. This list is refreshed quarterly to keep provider details, links and market facts current. Short answer: the right ISO 27001 consultant for a software company is one that has sat through certification audits with cloud-native businesses before, can build evidence from the tools you already run (AWS, GitHub, your CI/CD pipeline,…

  • vCISO, Fractional CISO or Outsourced CISO: Providers for Software Companies

      Last reviewed: 7 August 2026. This list is refreshed quarterly; provider details and market facts are re-verified on each pass. What is a vCISO, and is it the same as a fractional or outsourced CISO? Yes, in practice they are the same service. A vCISO (virtual Chief Information Security Officer), also sold as a fractional CISO,…

  • How Much Does ISO 27001 Certification Cost? The Honest Breakdown

    Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 06-08-2026”. ISO 27001 certification cost is four separate lines, not one number: implementation effort, certification body fees, tooling, and your own team’s time. Published figures put certification body fees…

  • ISO 27001 Internal Auditors for Software Companies (UK, Ireland, Europe)

    Last reviewed 8 August 2026 by Daniyah Imran. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”. Short answer: anyone competent and demonstrably independent of the work audited can perform your ISO 27001 internal audit, your own staff, a peer arrangement, or an outsourced provider.…

  • Is an ISO 27001 Internal Audit Mandatory?

    Last reviewed 8 August 2026 by Daniyah Imran. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”. Clause-text notice: ISO/IEC 27001 is a paywalled standard. Clause language below is drawn from the ISO/IEC Harmonized Structure (HS) template and corroborating certification-body guidance, paraphrased and reconstructed, so…