ISO 27001 readiness for SaaS
Most companies do not fail ISO 27001 because they lack documents. They fail because evidence is scattered, ownership is unclear, risks are outdated, and nobody can explain what is actually working.
Kellwick turns ISO 27001 preparation into a clear, testable readiness system. No fake templates. No 80-page policy packs nobody uses. Just a practical readiness review, a clear evidence map, and a focused plan to close the gaps before the auditor sees them.
Can you prove these 5 things?
Already on a compliance platform?
A compliance platform collects evidence continuously. It cannot decide whether your scope, risks, Statement of Applicability and control ownership actually make sense - or whether the human process behind each green check is real. That judgement is exactly what an auditor tests.
Why this becomes expensive late
You can be 30-60 days from an audit and still not know what evidence you can actually defend. By then, the fixes look like exactly what they are.
You probably do not have an ISO 27001 problem. You have an evidence problem. Your policies may exist. Your risk register may exist. Your access reviews may exist. But can you prove they work?
If not, you are not ready. You are guessing.
The questions behind every control
Quick readiness check
Not ready to talk? Get the ISO 27001 readiness checklist - a low-commitment first step before booking a call.
What actually blocks a certification - or a regulator
These are the blockers we find most often. None of them are exotic - which is exactly why they are missed until an auditor is in the room. The same gaps fail ISO 27001 Stage 1 and leave you exposed under DORA.
We do not guarantee outcomes and we are not a certification body. What we do is find these before the auditor does - while there is still time to fix them cheaply.
Not ready for a full review?
Start with a 2-day Mini Gap Review.
Scoped and priced on a short call. We hand back your top Stage 1 blockers and the single next step that matters most.
You do not need another folder of templates. You need a clear answer to four questions.
What is required?
What evidence proves it?
Who owns it?
What is missing?
That is the work. Walk into audit week knowing what you can prove.
Before Kellwick
That sentence is expensive.
After Kellwick
What you receive
A clear summary of where you stand now.
A control-by-control map of what evidence exists, what is weak, and what is missing.
A practical list of gaps ranked by risk and audit impact. No noise, no theoretical consulting language.
A short execution plan for the next 2-6 weeks.
A direct review call to walk through findings and prepare the team for likely audit questions.
Want the exact structure? See sample deliverables.
Evidence map preview
| Control area | Expected evidence | Common gap | Kellwick output |
|---|---|---|---|
| Access control | User access review | No owner, no date, no approval | Mapped evidence + remediation note |
| Supplier risk | Vendor register + risk rating | Critical vendors unassessed | Tiered register + review plan |
| Change / release | Ticket, review, test, deploy | Emergency changes not recorded | Traceable change evidence |
| Statement of Applicability | Justified applicability + evidence | Marked implemented, no proof | SoA reconciled to reality |
| Management review | Minutes with real decisions | Meeting held, no decisions | Review pack with action log |
The process
You share what you already have: policies, scope, risk register, SoA, access reviews, supplier records, incident and change records, internal audit notes, management review and evidence folders.
We review it against ISO 27001 readiness expectations and build a practical evidence map. This is where most problems become visible.
A clear report, gap register, evidence map and remediation plan. You know what to fix before audit pressure starts.
What usually breaks during audit prep
Book this if
Independent advisory for regulated technology teams
Fixed-scope, evidence-based delivery, with a clear separation from certification bodies. We prepare you for the audit; we do not run it.
Kellwick is an independent advisory practice, not a certification body.
The service ladder
Start where you are and step up as you go. Figures and typical ranges live on the pricing page, confirmed after a readiness call.
1-2 working days
Fast, fixed-scope entry; your top Stage 1 blockers surfaced quickly.
See the Mini Gap Review5-10 working days
Full clauses 4-10 plus Annex A, delivered as a scored gap register.
See the Readiness Assessment3-6 weeks
Hands-on gap closure with your team before the audit.
See the Remediation SprintMonthly retainer
Keep the ISMS audit-ready between certification cycles.
See ISMS MaintenanceSee full scope and figures on the pricing page.
This is for you if
This is not for you if
Why Kellwick
Kellwick is an independent advisory practice built around practical ISO 27001 readiness for regulated technology teams. Delivery is fixed-scope and evidence-based, with a clear separation from certification bodies - we prepare you for the audit; we do not run it.
That matters because ISO 27001 is not only a documentation exercise. It touches how teams build, access, change, monitor, approve, review and respond. A good readiness review understands the system behind the evidence.
FAQ
No. Kellwick does not issue ISO 27001 certificates. Certification comes from an accredited certification body. Kellwick helps you prepare before that stage.
No serious advisor should guarantee that. The goal is to reduce avoidable audit risk, expose weak areas early, and help your team prepare evidence properly.
No. This works best when you already have some material and need a structured review. If you are starting from zero, we can still help - the first step becomes scope, risk and core ISMS setup.
A Mini Gap Review can be done in 1-2 days when materials are ready. A full readiness assessment runs 5-10 working days depending on scope, evidence quality, number of systems and team availability.
No. We help your team see what is missing and what needs to be fixed. Control ownership should stay inside the company.
Templates do not prove readiness. Evidence, ownership, review history and operational consistency prove readiness. We focus on what an auditor or serious customer will expect you to show.
From the blog
Inference logs that capture customer inputs can contain PII, confidential business data or legally privileged material. ISO 27001 requires you to classify what you keep, control who reads it, and align retention with your DPA commitments.
Read →AI SaaS GRCLLM API vendors process customer data on your behalf. If they are not on your sub-processor register with a current DPA and assurance evidence, enterprise buyers will find that gap before you do.
Read →AI SaaS GRCISO 27001 does not certify model behaviour, bias or EU AI Act compliance. But it answers the information-security questions enterprise buyers gate on: access, sub-processors, data handling and documented evidence.
Read →Find out before the audit.
Kellwick is an independent advisory practice. We are not a certification body and do not issue ISO certifications. Certification decisions are made only by accredited certification bodies.