Blog
Practical guidance on ISO 27001, SOC 2, ISO 42001, GDPR and penetration testing for scaling software companies.
GDPR Certification: What Exists, What Does Not, and What Buyers Accept
There is no official GDPR certificate. No EU body issues one, no company can hold one, and any provider selling a “GDPR certified” badge is selling something the regulation does not recognise. What exists instead: approved certification schemes under Article 42 (Europrivacy is the first), ISO 27701 as the certifiable privacy management standard, and the evidence…
ISO 42001 Internal Audit: What the Standard Requires
Target queries: “iso 42001 internal audit requirements” · “iso 42001 clause 9.2” · “who audits an AI management system” Last reviewed: 28 August 2026. This page is refreshed quarterly; the next scheduled review is November 2026. Volatile facts are date-stamped where they appear. The direct answer: ISO/IEC 42001:2023 clause 9.2 requires your organisation to run internal audits of its…
UK GDPR vs EU GDPR: What Is Actually Different
UK GDPR and EU GDPR are substantively near-identical, because UK GDPR is retained EU law. Comply with one properly and you are most of the way to the other. The differences that create real work are administrative: a second representative, second transfer contracts, a second regulator, an annual ICO fee and fines in a different…
ISO 42001 Certification Bodies: Who Is Actually Accredited (and Who Is Not)
Byline: Mahrukh Fatima Last reviewed: 30 August 2026. This list is refreshed quarterly against the accreditation bodies’ own registers. As of 07-08-2026, 15 verified certification bodies hold a tier-1-verifiable accreditation to certify organisations against ISO/IEC 42001, across six accreditation bodies: ANAB (United States), UKAS (United Kingdom), RvA (Netherlands), JAS-ANZ (Australia and New Zealand), SAC (Singapore) and IAS (United…
Drata Partners in the UK and Ireland: Who They Are and How to Choose
Last reviewed: 7 August 2026. This list is refreshed quarterly; partner tiers, review counts and other volatile details are date-stamped as of 07-08-2026. Quick answer: If you have chosen Drata and need help implementing it in the UK or Ireland, the question that matters is who will actually run your programme and where they sit.…
ISO 27001 Consultants for Software Companies: How to Choose, Who to Consider
Last reviewed: 7 August 2026. This list is refreshed quarterly to keep provider details, links and market facts current. Short answer: the right ISO 27001 consultant for a software company is one that has sat through certification audits with cloud-native businesses before, can build evidence from the tools you already run (AWS, GitHub, your CI/CD pipeline,…
vCISO, Fractional CISO or Outsourced CISO: Providers for Software Companies
Last reviewed: 7 August 2026. This list is refreshed quarterly; provider details and market facts are re-verified on each pass. What is a vCISO, and is it the same as a fractional or outsourced CISO? Yes, in practice they are the same service. A vCISO (virtual Chief Information Security Officer), also sold as a fractional CISO,…
How Much Does ISO 27001 Certification Cost? The Honest Breakdown
Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 06-08-2026”. ISO 27001 certification cost is four separate lines, not one number: implementation effort, certification body fees, tooling, and your own team’s time. Published figures put certification body fees…
ISO 27001 Internal Auditors for Software Companies (UK, Ireland, Europe)
Last reviewed 8 August 2026 by Daniyah Imran. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”. Short answer: anyone competent and demonstrably independent of the work audited can perform your ISO 27001 internal audit, your own staff, a peer arrangement, or an outsourced provider.…
Is an ISO 27001 Internal Audit Mandatory?
Last reviewed 8 August 2026 by Daniyah Imran. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”. Clause-text notice: ISO/IEC 27001 is a paywalled standard. Clause language below is drawn from the ISO/IEC Harmonized Structure (HS) template and corroborating certification-body guidance, paraphrased and reconstructed, so…