For a SaaS start-up selling to large companies, not having ISO 27001 rarely stops a sales conversation from starting. What it does is stall that conversation further down the line. The product generates interest, the conversation moves forward and, when the deal reaches procurement, a security questionnaire with hundreds of questions appears.

That is what Kloutit was experiencing. Kloutit is an artificial intelligence platform that helps online businesses recover the money they lose to chargebacks. As Adrian Algarra, CPO and co-founder, explains: “We work with very large companies, and in their procurement processes they either asked us directly whether we had ISO 27001, or they had us fill in huge documents about security.”

The good news is that certification does not have to become the project that paralyses your product team for months. Kloutit achieved it in one year, with no technical changes and only two people involved. In this article we look at what the standard actually requires of a SaaS start-up, where the weak points usually lie and how to organise the project so that it moves forward alongside the business.

Why large clients ask for ISO 27001

A large company that contracts a SaaS provider takes on a risk to its own data and, in many cases, to its customers’ data. Its procurement team needs to show that it has assessed that risk, and it has two ways of doing so: reviewing how you work question by question, or relying on a certification issued by an independent third party.

ISO 27001 fulfils exactly that role. It does not fully replace questionnaires, but it changes their nature: instead of asking the client to take your word for it, you provide a certificate verified by a certification body and a Statement of Applicability that summarises which controls you apply and why. Due diligence is then supported by a verifiable guarantee and no longer depends solely on your own answers.

This is especially relevant when your product handles sensitive data. In Kloutit’s case, the platform manages transactions and dispute evidence that may include personal and payment data belonging to its clients’ customers. The more sensitive the data, the higher the bar the buyer will set.

The real work is rarely technical: it is formalisation

There is a widespread belief that ISO 27001 forces you to rebuild your infrastructure. In a well-built technical start-up, the opposite is usually true: the foundations are already solid. Cloud infrastructure, good development practices, access control and a data processing agreement are common starting points.

What is almost always missing is the information security management system (ISMS). In other words, turning what the team already does implicitly into something explicit, documented and verifiable by an auditor. That includes defining the scope of the system, carrying out a structured risk assessment and treatment, drawing up the Statement of Applicability, writing proportionate policies and procedures, setting objectives and metrics, and completing at least one cycle of internal audit and management review before the certification audit.

Kloutit sums it up clearly: at a technical level, they did not have to change anything. The challenge lay in formalising and documenting what they already did, and doing so while continuing to ship product. Running at two speeds at once, the speed of the business and the speed of certification, is the real challenge for any start-up.

The basic controls that slip through when you are moving fast

A well-executed risk assessment does not only uncover complex risks. It often reveals gaps in controls that seem obvious and that, precisely for that reason, nobody has reviewed in depth.

The most common example in SaaS companies is work devices. Having every laptop enrolled in a mobile device management (MDM) solution, with policies applied, disk encryption and active antivirus, is something almost every technical team takes for granted. In practice, when a team grows quickly, it is easy for a device to remain unenrolled or for a configuration never to be verified. In the 2022 version of the standard, these aspects are mainly covered by control A.8.1 on user endpoint devices.

This was one of the areas where Kloutit recognised the value of an external perspective: getting these controls properly applied and, above all, documented so that the auditor could verify them.

Metrics that fit you, not those of a large corporation

The standard requires you to set security objectives and measure the performance of the ISMS. For many start-ups, this is one of the most puzzling parts: they know exactly what they want to protect, but not how to translate it into useful indicators.

The common mistake is copying dashboards designed for much larger organisations, which end up creating work without providing insight. Metrics need to be proportionate to the company’s size and risk level: the percentage of managed and encrypted devices, the time taken to revoke access after someone leaves, or the completion rate of periodic permission reviews are simple to measure and highly representative.

Kloutit knew what it wanted to protect, but not how to translate that into metrics for a management system. Having a set of indicators proposed to suit its size and risk level saved them, in their own words, “a huge amount of time and doubt”.

GDPR in parallel: records, impact assessments and sub-processors

ISO 27001 and the GDPR are not the same thing, but they reinforce each other. Using the certification project to consolidate your data protection framework is one of the most efficient decisions a start-up can make.

There are three elements that are particularly relevant for a SaaS company. The first is the record of processing activities, required by Article 30 of the GDPR, which means being clear about what data is processed, for what purpose and for how long. The second is data protection impact assessments (DPIAs), which are mandatory when processing is likely to result in a high risk to people’s rights. The third, and the one that tends to surprise most, is sub-processor management.

When a SaaS company processes data on behalf of its clients, it acts as a data processor. Every provider involved in that chain, whether cloud infrastructure, the database, a payment processor or an AI model provider, is a sub-processor. Article 28 of the GDPR requires the client’s prior authorisation and the same data protection obligations to be passed on to each sub-processor. In products that incorporate AI, you also need to know what information is sent to the model, where it is processed and with what safeguards, including whether the provider may use it to train its models.

Kloutit acknowledges that sub-processor management was unfamiliar territory, and that the support helped them understand it and set it up properly. Today, when a client asks about security, they can explain transparently what data they process, for what purpose, that it resides in the European Union and that they work with a small number of identified and controlled sub-processors.

How to organise the project so it does not slow down the product

The main concern for any start-up considering ISO 27001 is that the process will eat up weeks of the product team’s time. Avoiding that depends less on the standard and more on how the work is organised.

The first key decision is to limit who is involved. At Kloutit, only two people from the team took direct charge of the project, so the rest stayed focused on the product. The second is to work to a steady cadence: meetings every two weeks, which became weekly as the audit date approached. The third is to turn the standard into specific, well-defined tasks, rather than confronting the team with a mountain of open-ended work.

Finally, there is the documentation workload. It is the heaviest part of the process and the part where the internal team adds least value by starting from scratch. Working with a partner who takes on that burden and translates the standard into plain language allows security to progress in parallel with development. In Adrian Algarra’s words: “What surprised us most, in a good way, was how little it slowed the team down compared with what we had feared at the start.”

What changes once you have the certificate

Certification is not the end of the road. The certificate is valid for three years, with annual surveillance audits, and the ISMS has to stay alive: risks reviewed, metrics updated, internal audits and management reviews.

In return, the impact should be felt exactly where there was most friction: security questionnaires answered with greater confidence and speed, smoother due diligence processes and access to larger clients and more demanding sectors. That is what Kloutit expects, as its certification is still recent. As Kloutit puts it, rather than opening the door, certification removes the biggest obstacle once they are inside.

There is also a less visible but equally important benefit: the company ends up better organised internally. Defined policies, orderly access management and clear ownership are the foundation for growing with credibility.

Want to get ISO 27001 certified without slowing down your business?

At PrivaLex Partners we support start-ups and growing companies on their path to ISO 27001, combining two complementary pillars, legal and technical, to deliver an end-to-end compliance framework. We take on the weight of the management system and the documentation, translate the standard into specific tasks and guide you through to the audit, so your team can stay focused on the product.

Beyond ISO 27001, we work on GDPR, ISO 27701, ISO 42001, ENS, NIS2, DORA and the AI Act, so you can address several obligations through a single governance framework.

Book a call with our team and tell us where you are. We will tell you what you are missing to get certified and how to get there on time.

It depends on the scope, the starting point and the resources dedicated to it. Kloutit achieved it in one year, a tight timeframe for a company that handles payment dispute data. As well as preparing the documentation, the ISMS must have been operating long enough to generate evidence, including at least one internal audit and one management review, before the ISO/IEC 27001 certification audit.

Not necessarily. In technical start-ups with solid foundations, the work usually focuses on formalising and documenting what the team already does well. In Kloutit’s case, no technical changes were needed. The risk assessment typically reveals a few basic controls to strengthen, such as the management and encryption of work devices.

The main elements include the ISMS scope, the information security policy, the risk assessment and treatment methodology and results, the Statement of Applicability, security objectives and evidence of their monitoring, and the results of the internal audit and management review. On top of these come the policies and procedures required by the applicable controls, always proportionate to the size of the company.

No. ISO 27001 certifies an information security management system, while the GDPR has its own obligations, such as the record of processing activities, impact assessments and the management of processors and sub-processors. The two frameworks reinforce each other and are best addressed together. For privacy management there is a specific standard, ISO/IEC 27701.

When a SaaS company processes data on behalf of its clients it acts as a data processor, and every provider involved in that chain (infrastructure, database, payment processors or AI models) is a sub-processor. Article 28 of the GDPR requires the client’s prior authorisation and the same data protection obligations to be passed on to each sub-processor. With AI, you also need to control what data is sent to the model, where it is processed and whether the provider may use it for training. The EDPB guidelines on controllers and processors are a useful reference.

As few as possible, provided they have decision-making authority. At Kloutit only two people from the team took direct charge of the project, which allowed the rest to stay focused on the product. The key is a steady meeting cadence, specific and well-defined tasks, and a partner who takes on the weight of the documentation framework.

The certificate is valid for three years, with annual surveillance audits and a recertification audit at the end of the cycle. The ISMS must be kept alive: risks reviewed, metrics updated, and regular internal audits and management reviews. Companies that treat it as an ongoing system reach each audit without surprises.

We support start-ups and SaaS companies throughout the process: risk assessment, management system design, metrics definition, GDPR framework consolidation and audit preparation, with a methodology designed not to slow down the product team. You can see how we did it with Kloutit in the case study or request your free risk assessment.