Which standard should we start with?
For most organisations, ISO/IEC 27001: it is the one customers and tenders ask for most. It also builds the management system foundation the others extend. If AI is your product, ISO/IEC 42001 may come first. If your customers depend on your uptime, ISO 22301 may be the priority. The free introductory call exists to answer exactly this question for your situation.
Who do you work with?
Startups and growing companies, mostly between five and 250 people, in Ireland and across Europe. That focus is deliberate: smaller organisations get certified fastest when the consultancy is senior, direct and fixed-price, which is how we work. We are not an enterprise consultancy, so there are no procurement mazes and no junior-heavy delivery teams.
How long does ISO 27001 certification take?
It depends on your starting point, not on a template. A small company with modern cloud tooling and an engaged founder can be audit-ready in a few months, while organisations with more history take longer. Two parts of the timeline sit outside anyone's control: the certification body needs to schedule your Stage 1 and Stage 2 audits, and the standard expects evidence that your system has genuinely run. The gap analysis gives you a dated, honest plan rather than a promise.
What does certification cost?
Three components: our consultancy fee, the certification body's audit fees and any tooling you choose to adopt. Our fee is fixed after a scoping conversation, so you know the number before you commit, and we help you get comparable quotes from certification bodies. Try the cost calculator and we will send you a tailored estimate.
Can we do more than one standard at once?
Yes. It is often cheaper than doing them separately, because the standards share the same clause structure: one integrated management system can cover information security, AI governance and business continuity together, with one set of audits and one management review cycle.
Do you help with SOC 2?
Yes. We provide consultancy for SOC 2 readiness, including Type II: control design against the Trust Services Criteria, evidence collection and preparation for the examination. The attestation itself is issued by a licensed CPA firm, which mirrors the independence rule we apply to ISO work: we prepare you, an independent party examines you.
Do you audit or certify?
We are implementation consultants, by design. Certification is issued by accredited certification bodies, and audits come from someone independent of the building work, which is what makes your certificate worth having. We prepare you so thoroughly that the audit holds no surprises and connect you with independent audit specialists when you need them.
We have implemented a management system. What happens next?
Certification, in most cases. Once the system is built and has run long enough to produce real evidence, an accredited certification body examines it in two stages and, if satisfied, issues your certificate. We prepare you for that examination, help you choose the body and get comparable quotes.
Why does certification have to come from an external body?
Because the certificate's entire value is the independence of whoever issued it. Certification means an outside party with nothing at stake has confirmed your management system meets the standard. That is what lets a customer or tender panel accept the certificate instead of auditing you themselves.
Can we just certify ourselves?
You can declare that you conform to a standard, and nothing stops you designing a badge to go with it. The question is who would believe it. A self-issued certificate carries no independent assurance, so the tenders and enterprise customers that ask for certification will not accept it. Independence is the product; that is why accredited bodies exist.
What happens after we are certified?
Certification runs on a three-year cycle: surveillance audits in years one and two, then recertification. Between audits the management system has to keep running, through management reviews, objectives, internal audits and corrective actions. We stay involved as lightly or as closely as you want, from an annual health check to running the calendar with you. Internal audits must come from someone independent of us, which is why we refer that work out.
Do you only work with Irish organisations?
No. We are based in Co. Cork and work across Ireland, but the standards are international and most consultancy runs perfectly well remotely, with on-site days where they add value.