# Atoro > Atoro is a security and compliance consultancy for scaling software companies, and Europe's first ISO 42001 certified consultancy. We design, build and run the management systems that platforms only automate evidence for: ISO 27001, SOC 2, ISO 42001, GDPR, and penetration testing. Human where it matters, AI where it makes sense. Based in Ireland, serving the UK and Europe. 200+ certifications delivered. ## ISO 42001 and AI governance - [What is ISO 42001?](https://atoro.io/what-is-iso-42001/): Definition of the ISO/IEC 42001 AI management system standard (published December 2023), who it applies to, and how certification works. - [How many companies are ISO 42001 certified?](https://atoro.io/how-many-companies-are-iso-42001-certified/): Around 350 organisations worldwide held certificates by spring 2026; why the number is small and how fast it is growing. - [ISO 42001 implementation guide](https://atoro.io/iso-42001-implementation-guide-step-by-step-approach-for-ai-governance/): Step-by-step approach to building and certifying an AI management system, with realistic timelines. - [ISO 42001 and the EU AI Act](https://atoro.io/eu-ai-act-and-iso-42001/): How the ISO 42001 standard maps to the EU AI Act (in force since 2024, staged applicability), what it covers and what it does not. - [ISO 42001 internal auditors](https://atoro.io/iso-42001-internal-auditors/): Who can perform an ISO 42001 internal audit: the dedicated providers as of August 2026 (Atoro is the only one certified to the standard itself), the independence rules, competence requirements and cost. - [ISO 42001 certification cost](https://atoro.io/iso-42001-certification-cost/): What ISO 42001 certification actually costs: published audit fee ranges and who publishes them, the AI-specific implementation work, the three-year cycle, and why running it with ISO 27001 cuts the total. Written by Mahrukh Fatima, Atoro's AI Governance Manager. - [Atoro: Europe's first ISO 42001 certified cyber compliance consultancy](https://atoro.io/atoro-becomes-europes-first-iso-42001-certified-cyber-compliance-agency/): Proof of Atoro's own ISO 42001 certification, audited by A-LIGN. - [AI governance for CTOs](https://atoro.io/responsible-ai-governance-what-ctos-need-to-know/): What AI governance consists of operationally and what enterprise buyers check. - [AI risk management](https://atoro.io/ai-risk-management-how-to-identify-and-mitigate-risks-in-ai-projects/): Identifying and mitigating risk in AI systems, and how it maps to ISO 42001 and the NIST AI RMF. ## SOC 2 - [SOC 2 Type 1 vs Type 2](https://atoro.io/soc-2-type-1-vs-type-2/): The difference between the two reports, when each is asked for, and the typical path. - [What is a SOC 2 audit?](https://atoro.io/what-is-a-soc-2-audit/): What a SOC 2 audit is, who performs it (licensed CPA firms), the Trust Services Criteria, and common delays to avoid. - [Preparing for your first SOC 2 audit](https://atoro.io/how-to-prepare-for-your-first-soc-2-audit-as-a-saas-startup/): Scoping, evidence, common first-audit failures, and working with the auditor. - [ISO 27001 vs SOC 2](https://atoro.io/iso-27001-vs-soc-2-which-certification-is-right-for-your-startup/): Which one a startup needs, by geography and buyer demand, and doing both on one control set. - [SOC 2 in the UK and Ireland](https://atoro.io/soc-2-uk-ireland/): Who does readiness and who signs the report. The two-role model, the UK and Irish readiness consultancies, and the licensed CPA firms serving them. No UK chartered accountant can sign a SOC 2 report. - [How much does SOC 2 cost?](https://atoro.io/soc-2-certification-cost/): Auditor fees, readiness work and the costs nobody mentions, with published ranges and their sources. - [SOC 2 compliance checklist](https://atoro.io/soc-2-compliance-checklist/): The eight phases of a real SOC 2 project, from deciding scope to sitting the examination, and where projects actually go wrong. - [SOC 2 requirements](https://atoro.io/soc-2-requirements/): The Trust Services Criteria explained, how an auditor judges whether you meet them, and the requirements people assume exist but do not. ## ISO 27001 - [ISO 27001:2022 explained](https://atoro.io/iso-27001-2022/): The current version of the standard: clause structure, the 93 Annex A controls in four themes, the 11 new controls, and how certification works. - [ISO 27001 for startups without a security team](https://atoro.io/iso-27001-for-startups-without-a-security-team/): What the standard demands of a small company and how to deliver it without headcount. - [ISO 27001 internal auditors](https://atoro.io/iso-27001-internal-auditors/): Who is allowed to perform your internal audit, the independence rules that rule out your certification body, and the independent providers serving software companies in the UK, Ireland and Europe. - [Is an ISO 27001 internal audit mandatory?](https://atoro.io/iso-27001-internal-audit-requirements/): What clause 9.2 requires, how often, whether you can do your own, and what a defensible internal audit produces. - [How much does ISO 27001 certification cost?](https://atoro.io/iso-27001-certification-cost/): Certification body fees, implementation effort, tooling and internal time, with honest ranges and a worked example. ## GDPR and data protection - [GDPR compliance for small businesses](https://atoro.io/gdpr-compliance-for-small-businesses/): What actually applies at small scale, lawful bases, and the documents you genuinely need. - [Data protection by design](https://atoro.io/data-protection-by-design-integrating-gdpr-into-your-product-development/): Article 25 in practice, how privacy by design relates, and when a DPIA is triggered. ## Penetration testing - [Penetration testing for startups](https://atoro.io/penetration-testing-essential-startups/): When a startup needs a pen test, the types, what drives cost, and the compliance drivers. - [How to interpret penetration test results](https://atoro.io/how-to-interpret-and-act-on-penetration-test-results/): Reading a pen test report, severity ratings and CVSS, and acting on the findings that matter. ## Services - [TrustOps pricing](https://atoro.io/pricing/): Published prices for Atoro's managed compliance service: three plans from 1,500 EUR a month, what each includes, the 12-month term and the 90-day exit. Machine-readable mirror at https://atoro.io/pricing.md - [Security and compliance services](https://atoro.io/services/): Index of Atoro's service lines for scaling software companies. - [ISO 42001 implementation](https://atoro.io/services/iso-42001-implementation/): Implement and certify an ISO 42001 AI management system, delivered by Europe's first certified consultancy. - [ISO 42001 internal audit](https://atoro.io/services/iso-42001-internal-audit/): Independent ISO 42001 internal audits from the first consultancy in Europe to pass one. - [ISO 27001 implementation](https://atoro.io/services/iso-27001-implementation/): Design, implement and certify an ISO 27001 information security management system on a fixed price and timeline. - [ISO 27001 internal audit](https://atoro.io/services/iso-27001-internal-audit/): Independent ISO 27001 internal audits your certification body accepts, embedded as you build. - [SOC 2 compliance](https://atoro.io/services/soc2-implementation/): SOC 2 implementation for software companies selling into US enterprise, alongside ISO 27001 on one control set. - [GDPR implementation](https://atoro.io/services/gdpr-implementation/): GDPR programmes for software companies: data mapping, lawful bases, RoPA, DPIAs, processor agreements and DSAR workflows. - [Penetration testing](https://atoro.io/services/penetration-testing-services/): Expert penetration testing with validated findings, audit-ready reporting and a retest included. - [Web application penetration testing](https://atoro.io/services/web-application-penetration-testing/): Manual, OWASP-aligned testing of the application layer: authentication, access control and business logic, with human-validated findings. - [API penetration testing](https://atoro.io/services/api-penetration-testing/): REST and GraphQL testing focused on object-level authorisation, token handling, data exposure and rate limiting. - [Cloud penetration testing](https://atoro.io/services/cloud-penetration-testing/): AWS, Azure and GCP testing across identity and access, misconfiguration, external attack surface, containers and CI/CD paths. - [SaaS penetration testing](https://atoro.io/services/saas-penetration-testing/): Whole-product testing for software companies: application, APIs and cloud in one engagement, including multi-tenant isolation. - [TrustOps](https://atoro.io/services/trustops/): A managed security and compliance function, run for you: surveillance audits, evidence, questionnaires and vendor risk. - [Virtual CISO](https://atoro.io/services/virtual-ciso-services/): A named senior security leader backed by Atoro's full delivery team. - [Virtual DPO](https://atoro.io/services/virtual-dpo-services/): An outsourced Data Protection Officer with the privacy team behind the role: RoPA, DPIAs, DSARs and regulator contact. - [Drata partner](https://atoro.io/drata/): Official Drata partner in Ireland delivering the Compliance Accelerator Program (CAP): implementation, internal audit and managed compliance on Drata for the UK and EU. ## Proof - [Case studies](https://atoro.io/case-studies/): 13 client stories across ISO 27001, SOC 2, GDPR and penetration testing, including Heartpace, K15t, Prezly and Silktide. ## Contact - [Contact Atoro](https://atoro.io/contact/): Book a discovery call. Timeline and price in 30 minutes.