# Atoro > Atoro is a security and compliance consultancy for scaling software companies, and Europe's first ISO 42001 certified consultancy. We design, build and run the management systems that platforms only automate evidence for: ISO 27001, SOC 2, ISO 42001, GDPR, and penetration testing. Human where it matters, AI where it makes sense. Based in Ireland, serving the UK and Europe. 200+ certifications delivered. ## ISO 42001 and AI governance - [What is ISO 42001?](https://atoro.io/what-is-iso-42001/): Definition of the ISO/IEC 42001 AI management system standard (published December 2023), who it applies to, and how certification works. - [How many companies are ISO 42001 certified?](https://atoro.io/how-many-companies-are-iso-42001-certified/): Around 350 organisations worldwide held certificates by spring 2026; why the number is small and how fast it is growing. - [ISO 42001 implementation guide](https://atoro.io/iso-42001-implementation-guide-step-by-step-approach-for-ai-governance/): Step-by-step approach to building and certifying an AI management system, with realistic timelines. - [ISO 42001 and the EU AI Act](https://atoro.io/eu-ai-act-and-iso-42001/): How the ISO 42001 standard maps to the EU AI Act (in force since 2024, staged applicability), what it covers and what it does not. - [Atoro: Europe's first ISO 42001 certified cyber compliance consultancy](https://atoro.io/atoro-becomes-europes-first-iso-42001-certified-cyber-compliance-agency/): Proof of Atoro's own ISO 42001 certification, audited by A-LIGN. - [AI governance for CTOs](https://atoro.io/responsible-ai-governance-what-ctos-need-to-know/): What AI governance consists of operationally and what enterprise buyers check. - [AI risk management](https://atoro.io/ai-risk-management-how-to-identify-and-mitigate-risks-in-ai-projects/): Identifying and mitigating risk in AI systems, and how it maps to ISO 42001 and the NIST AI RMF. ## SOC 2 - [SOC 2 Type 1 vs Type 2](https://atoro.io/soc-2-type-1-vs-type-2/): The difference between the two reports, when each is asked for, and the typical path. - [What is a SOC 2 audit?](https://atoro.io/what-is-a-soc-2-audit/): What a SOC 2 audit is, who performs it (licensed CPA firms), the Trust Services Criteria, and common delays to avoid. - [Preparing for your first SOC 2 audit](https://atoro.io/how-to-prepare-for-your-first-soc-2-audit-as-a-saas-startup/): Scoping, evidence, common first-audit failures, and working with the auditor. - [ISO 27001 vs SOC 2](https://atoro.io/iso-27001-vs-soc-2-which-certification-is-right-for-your-startup/): Which one a startup needs, by geography and buyer demand, and doing both on one control set. ## ISO 27001 - [ISO 27001:2022 explained](https://atoro.io/iso-27001-2022/): The current version of the standard: clause structure, the 93 Annex A controls in four themes, the 11 new controls, and how certification works. - [ISO 27001 for startups without a security team](https://atoro.io/iso-27001-for-startups-without-a-security-team/): What the standard demands of a small company and how to deliver it without headcount. ## GDPR and data protection - [GDPR compliance for small businesses](https://atoro.io/gdpr-compliance-for-small-businesses/): What actually applies at small scale, lawful bases, and the documents you genuinely need. - [Data protection by design](https://atoro.io/data-protection-by-design-integrating-gdpr-into-your-product-development/): Article 25 in practice, how privacy by design relates, and when a DPIA is triggered. ## Penetration testing - [Penetration testing for startups](https://atoro.io/penetration-testing-essential-startups/): When a startup needs a pen test, the types, what drives cost, and the compliance drivers. - [How to interpret penetration test results](https://atoro.io/how-to-interpret-and-act-on-penetration-test-results/): Reading a pen test report, severity ratings and CVSS, and acting on the findings that matter. ## Services - [Security and compliance services](https://atoro.io/services/): Index of Atoro's service lines for scaling software companies. - [ISO 42001 implementation](https://atoro.io/services/iso-42001-implementation/): Implement and certify an ISO 42001 AI management system, delivered by Europe's first certified consultancy. - [ISO 42001 internal audit](https://atoro.io/services/iso-42001-internal-audit/): Independent ISO 42001 internal audits from the first consultancy in Europe to pass one. - [ISO 27001 implementation](https://atoro.io/services/iso-27001-implementation/): Design, implement and certify an ISO 27001 information security management system on a fixed price and timeline. - [ISO 27001 internal audit](https://atoro.io/services/iso-27001-internal-audit/): Independent ISO 27001 internal audits your certification body accepts, embedded as you build. - [SOC 2 compliance](https://atoro.io/services/soc2-implementation/): SOC 2 implementation for software companies selling into US enterprise, alongside ISO 27001 on one control set. - [GDPR implementation](https://atoro.io/services/gdpr-implementation/): GDPR programmes for software companies: data mapping, lawful bases, RoPA, DPIAs, processor agreements and DSAR workflows. - [Penetration testing](https://atoro.io/services/penetration-testing-services/): Expert penetration testing with validated findings, audit-ready reporting and a retest included. - [TrustOps](https://atoro.io/services/trustops/): A managed security and compliance function, run for you: surveillance audits, evidence, questionnaires and vendor risk. - [Virtual CISO](https://atoro.io/services/virtual-ciso-services/): A named senior security leader backed by Atoro's full delivery team. - [Virtual DPO](https://atoro.io/services/virtual-dpo-services/): An outsourced Data Protection Officer with the privacy team behind the role: RoPA, DPIAs, DSARs and regulator contact. - [Drata partner](https://atoro.io/drata/): Official Drata partner in Ireland delivering the Compliance Accelerator Program (CAP): implementation, internal audit and managed compliance on Drata for the UK and EU. ## Proof - [Case studies](https://atoro.io/case-studies/): 13 client stories across ISO 27001, SOC 2, GDPR and penetration testing, including Heartpace, K15t, Prezly and Silktide. ## Contact - [Contact Atoro](https://atoro.io/contact/): Book a discovery call. Timeline and price in 30 minutes.