Blog

Practical guidance on ISO 27001, SOC 2, ISO 42001, GDPR and penetration testing for scaling software companies.

  • vCISO, Fractional CISO or Outsourced CISO: Providers for Software Companies

      Last reviewed: 7 August 2026. This list is refreshed quarterly; provider details and market facts are re-verified on each pass. What is a vCISO, and is it the same as a fractional or outsourced CISO? Yes, in practice they are the same service. A vCISO (virtual Chief Information Security Officer), also sold as a fractional CISO,…

  • How Much Does ISO 27001 Certification Cost? The Honest Breakdown

    Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 06-08-2026”. ISO 27001 certification cost is four separate lines, not one number: implementation effort, certification body fees, tooling, and your own team’s time. Published figures put certification body fees…

  • ISO 27001 Internal Auditors for Software Companies (UK, Ireland, Europe)

    Last reviewed 8 August 2026 by Daniyah Imran. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”. Short answer: anyone competent and demonstrably independent of the work audited can perform your ISO 27001 internal audit, your own staff, a peer arrangement, or an outsourced provider.…

  • Is an ISO 27001 Internal Audit Mandatory?

    Last reviewed 8 August 2026 by Daniyah Imran. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”. Clause-text notice: ISO/IEC 27001 is a paywalled standard. Clause language below is drawn from the ISO/IEC Harmonized Structure (HS) template and corroborating certification-body guidance, paraphrased and reconstructed, so…

  • The SOC 2 Compliance Checklist That Reflects How Audits Actually Work

    Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 06-08-2026”. There is no official SOC 2 compliance checklist. The AICPA publishes Trust Services Criteria, your organisation designs controls that meet them, and a licensed CPA firm examines those…

  • SOC 2 Requirements, Explained: Trust Services Criteria, Controls and Evidence

    Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 06-08-2026”. SOC 2 does not have a fixed requirements list. It has criteria: the AICPA Trust Services Criteria, defined in TSP Section 100 (2017, with revised points of focus…

  • How Much Does SOC 2 Cost? Auditor Fees, Readiness and the Real Total

    Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 06-08-2026”. The real cost of SOC 2 is three separate lines, and the auditor quote is only one of them. You pay for readiness work to design and implement…

  • SOC 2 in the UK and Ireland: Who Does the Readiness, Who Does the Audit

    Last reviewed 8 August 2026 by Tom McNamara. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”. If you run a software company in the UK or Ireland and a US enterprise buyer has just asked for your SOC 2 report, here is the short…

  • ISO 42001 Internal Auditors: Who Can Audit Your AI Management System?

    Last reviewed 7 August 2026 by Mahrukh Fatima. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”. The short answer: anyone competent and independent can perform your ISO 42001 internal audit, your own trained staff, or an external party acting on your behalf. ISO/IEC 42001’s…

  • How Much Does ISO 42001 Certification Cost? What Is Known So Far

    By Mahrukh Fatima, AI Governance Manager at Atoro. Certified Lead Auditor, ISO 42001. No one publishes a fixed ISO 42001 certification cost, because the standard is under three years old (published December 2023) and the accredited certification market around it is younger still. No certification body publishes a fixed rate card; Schellman, the first accredited…