Certification and compliance consulting that passes the audit
We prepare the documentation, implement the controls and take your company through ISO/IEC 27001, ISO/IEC 42001, SOC 2, cloud and privacy standards. Big-4 quality of deliverables at pragmatic prices, from an international team with offices in Astana, London and Sheridan, Wyoming.
Clients in Cyprus, the United Kingdom, Lithuania, Poland, Malta, the Netherlands, Germany, Italy, Switzerland, France, Estonia, the UAE, the USA and Kazakhstan.
ISO/IEC 42001:2023 certificate obtained for our client
The first international standard for governing how a company builds and uses AI. In August 2026 we took a software development company in Limassol, Cyprus through a full ISO/IEC 42001 certification with an IAS-accredited certification body. The scope covers AI use across software development and internal business functions.
ISO/IEC 42001 is becoming the reference point for AI governance in Europe: it maps onto EU AI Act obligations, answers enterprise customers' due-diligence questions about AI, and sits naturally next to an existing ISO/IEC 27001 system.
- AI management system documentation: policy, roles, risk and impact assessments, Statement of Applicability
- Controls for data, models, suppliers and AI used in operations, aligned with ISO/IEC 27001 where you already have it
- Staff training and internal audit, then support through the certification audit
- Certificate issued by an accredited body and listed in the international registry
CERTIFICATE
Artificial Intelligence Management System
Governance, management and use of Artificial Intelligence technologies across software development activities and internal business functions, in accordance with the Statement of Applicability.
- Client
- Software development company, Limassol, Cyprus
- Certified since
- 27 August 2026
- Valid until
- 27 August 2029
- Certification body
- IAS-accredited management systems certification body
Services
Documentation, implementation and certification support
Every engagement ends with a certificate from an accredited body, a complete document set your team can actually run, and trained people inside the company.
Information Security Management System
- Gap audit against ISO/IEC 27001:2022
- Complete ISMS document package, risk and business continuity documentation
- Training for ISMS owners, certification audit, closing of non-conformities
- Original certificate and entry in the international online registry
AI Management System
- AI policy, roles, risk and impact assessments, Statement of Applicability
- Controls for data, models, suppliers and AI in operations
- Integration with an existing ISO/IEC 27001 system
- Certification by an accredited body
Type I and Type II readiness for service companies
- Scope and Trust Services Criteria selection
- Preliminary assessment, control design and implementation
- Documentation of processes and evidence
- Selection of a licensed AICPA auditor, support through the external audit
Cloud services and personal data protection
- Assessment of cloud infrastructure security and personal data policy
- ISMS package for the cloud solution, risk analysis, policies and procedures
- Certificates for ISO/IEC 27017:2015 and ISO/IEC 27018:2019
- Compliance with privacy legislation, including GDPR
Information security assessment for automotive suppliers
- Registration of each office in the ENX registry
- Internal audit and gap analysis, documentation aligned with VDA ISA
- Selection of an accredited Assessment Office
- Assessment report and confirmation of compliance on the ENX portal
Quality Management System
- Documentation audit and full QMS document package
- Business continuity documentation
- Two internal auditor certificates for your staff
- Certification audit, quality marks, registry entry
Quality Management System for medical devices
- QMS document package and medical device risk management
- Post-market surveillance procedures
- Employee training and two internal auditor certificates
- Certification audit and registry entry
How we work
From gap audit to certificate, typically in 3 to 6 months
Smaller companies with established processes move faster. Larger or more complex organizations take longer. The stages are the same.
- Gap auditWe review what you already have against the standard and agree the scope.
- DocumentationPolicies, procedures, risk assessments and records, written for your company, not from a template.
- Implementation and trainingControls go live, responsible people are trained, internal auditors are certified.
- Certification auditWe select an accredited body, organize the audit and sit next to your team throughout.
- Non-conformities and beyondFindings are closed, the certificate is issued and listed in the registry. We stay on for surveillance audits.
Selected clients
Companies we have certified
ISO/IEC 27001 projects from our casebook.

Software development, QA, deployment and maintenance

Software architecture, embedded, web, mobile, cloud

Online gaming platforms

Software development and AI solutions

Social rating and anti-fraud software

Full software development cycle

Business software development

Software development, testing and support

Full software development cycle

Fintech software development and maintenance

Software testing and auditing

Full cycle of software development

Information systems analysis, design and development

Software development, testing and support

Software development, support and maintenance

Aviation software

Software design, development and technical support

Payment systems software and integration

ERP and CRM consulting and development

Full software development cycle

Virtual currency exchange development

Cloud, virtualization and information security services

Cloud platform development and support

Software engineering for financial services

BIM design and software plug-ins

Business travel and expense management platform

Software development, testing and support

Security operations center services

Software development, IT consulting and education
Questions we hear most
What certification actually changes
What problems does it solve?
An ISO/IEC 27001:2022 certificate removes barriers to international tenders and enterprise customers. It formally confirms your level of information security, which makes contracts easier to win and due diligence shorter.
How long does it take?
Preparation (gap analysis and planning), implementation, internal audit and the certification audit usually take from a few months up to a year. Smaller organizations with established processes finish faster.
What are the risks of not being compliant?
Higher chance of data leaks, downtime, lawsuits, fines, lost customer trust and reputational damage, all of which hit profitability and long-term stability directly.
What ROI can be expected?
Avoided losses from incidents and fines, lower recovery costs, streamlined operations, new contracts and brand value, often lower insurance premiums, minus the total certification investment.
What does it cost?
Initial assessment and consulting, implementation of technical and organizational measures, certification audit fees and ongoing compliance. A detailed budget is tailored to each organization.
What changes inside the company?
Formal ISMS scope and security policy, asset inventory, risk assessment and treatment, core controls (access, logging, backup, patching, encryption), incident response and supplier procedures, regular training and internal audits.
Request a scope and quote
Tell us what your customers are asking for
Which standard, how many people and offices are in scope, and when you need the certificate. We come back within one business day with a scope, a timeline and a budget.
The form opens WhatsApp with your message prefilled, so it reaches a consultant directly. Nothing is stored on this website.
Start with a free consultation
Tell us which standard your customers are asking for and where your company operates. We will come back with a scope, a timeline and a budget within one business day.