Komplyo blog

Certification and audit

ISO 27001 and SOC 2 are voluntary, and most companies start one because a customer or an investor asked for it. This section compares the two standards, documents what a certification cycle actually costs and how long it takes, and describes how nonconformities raised in an audit are handled. The figures quoted apply to organisations under 250 people.

Get the security policy template

An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.

No spam. Unsubscribe in one click.