The Contract Is Ready. The Certificate Is What's Missing.
Enterprise procurement, public-sector tenders and investor due diligence all stop at the same question: are you certified?
Security questionnaires have quietly become the hardest gate in B2B sales. A buyer who likes your product still cannot sign until their risk team is satisfied, and a self-written answer no longer satisfies anybody. Independent certification is the shortest way past that gate.
Devtrios builds the management system, closes the gaps, trains your team and sits with you through the audit. We are engineers who ship software, so the controls we design fit how your business actually runs — rather than a folder of policies nobody follows.
- Gap analysis before you commit
- A system your team can actually run
- Audit support end to end
- Kept alive after certification
Standards we implement
Annex A controls in ISO 27001
Years a certificate lasts
Surveillance audits in between
The standards, not the sales pitch
Nobody Wakes Up Wanting an ISO Certificate
They want the deal that is stuck behind one. Certification is almost always a commercial problem wearing a compliance costume.
The deal that will not close
Your champion loves the product. Their security team sent a 200-question spreadsheet, and every answer you give is your own word for it. Weeks pass. The quarter ends.
Revenue already won, not yet banked
The tender you cannot enter
A framework or supply-chain opportunity lists ISO as mandatory. Your bid is filtered out before anyone reads what you actually proposed.
Excluded before you are evaluated
The diligence that stalls
An investor or acquirer raises governance. Uncertified operations read as unmanaged risk, and unmanaged risk gets priced into the terms you are offered.
Valuation and leverage, quietly lost
Pick the certificate your buyers keep asking for
Most companies need one to unblock a deal, then add others as they move upmarket. We run them as one programme so you write the policy once, not five times.
Information Security
The one enterprise buyers ask for by name. Proves you manage information risk in a repeatable, audited way.
How we do itISO/IEC 42001AI Management
The first certifiable AI governance standard. The clearest evidence available that you run AI responsibly.
How we do itISO 9001Quality Management
The most requested certificate in tendering. Shows you deliver the same result every time.
How we do itISO 14001Environmental Management
Increasingly scored in bids and ESG reviews. Shows environmental impact is measured and managed.
How we do itISO 22301Business Continuity
Answers the question regulators and enterprise buyers now ask: what happens when you go down?
How we do itStart with the one that is blocking revenue
There is no prize for collecting certificates. Pick the one your buyers are asking for, then add others as the shared foundation is already built.
| Standard | What it proves | Who asks for it | Typical time | |
|---|---|---|---|---|
| ISO/IEC 27001 | You manage information security risk in a repeatable, audited way | Enterprise security teams, SaaS buyers, regulated clients | 4–12 months | Details |
| ISO/IEC 42001 | Your AI systems are inventoried, risk-assessed and humanly overseen | Enterprise AI buyers, regulated sectors, procurement AI clauses | 4–10 months | Details |
| ISO 9001 | You deliver consistently and fix root causes when you do not | Public sector tenders, main contractors, framework operators | 3–9 months | Details |
| ISO 14001 | Environmental impacts are identified, measured and reduced | ESG-weighted bids, investors, sustainability scorecards | 4–9 months | Details |
| ISO 22301 | Critical services can be recovered inside a tested time window | Regulators, enterprise buyers with availability commitments | 4–10 months | Details |
Everything Between Deciding and Certified
Certification is not a document exercise. These are the stages that actually take the time, and we run all of them with you.
01 / 09
Scoping the Certificate
The single decision that sets the cost of everything after it.
We define which products, teams, systems and locations the certificate covers. Scope too wide and the programme drags for a year; scope too narrow and your buyer rejects the certificate. We scope it to the deals you are actually trying to win.
What the Next Few Months Actually Look Like
Ranges, not a single number. Where you land inside them depends almost entirely on what already exists on day one.
- Phase 01
Week 0 · free
Gap analysis
We assess what you already do against the standard, clause by clause and control by control, and hand back a prioritised plan with effort and dates. You own it whether or not you continue with us.
We doAssess, document, price the work
You doA few hours of interviews
- Phase 02
Weeks 1–3
Scope, risk and the paper foundation
Certification scope agreed, risk methodology set, risk register built, and the mandatory documents drafted — including the Statement of Applicability the auditor will scrutinise hardest.
We doDraft everything, run the risk workshops
You doDecisions on scope and risk appetite
- Phase 03
Weeks 3–12
Implementing the controls
The longest phase, and the one that varies most. Controls are built into your real systems rather than described in a document. Where gaps are technical, our engineers do the work alongside yours.
We doBuild, configure, evidence
You doAccess, and engineering time where it is unavoidable
- Phase 04
Concurrent
Training and awareness
Role-based training so the people an auditor will interview can answer confidently. We run a mock interview session before the audit so nobody meets these questions for the first time in the room.
We doDeliver training, run the dry run
You doGet your team in the room
- Phase 05
Min. 3 months in
Operate, internal audit, management review
The system has to run long enough to generate real evidence — most certification bodies expect around three months of operation before Stage 2. Meanwhile we run the mandatory internal audit and management review and close what they raise.
We doInternal audit, review, remediation
You doLeadership attendance at the review
- Phase 06
Then 30–60 days
Stage 1, Stage 2, certificate
Stage 1 reviews documentation and readiness. Stage 2, typically 30 to 60 days later, tests whether you genuinely operate the system. We prepare the evidence pack and are in the room for both.
We doPrepare evidence, manage the auditor, handle findings
You doBe available for interviews
Roughly four to six months is realistic if your practices are already mature; six to twelve is the common range for a UK SME starting from a normal baseline. Anyone quoting a fixed number of weeks before seeing your estate is guessing.
How a Certification Programme Actually Runs
It is not a linear project with an end date. It is a cycle you enter.
Scope & Gap
What the certificate covers, and the honest distance to it.
Design
Risk assessment, policies, and the controls that close each gap.
Implement
Controls built into your real systems, with your engineers.
Operate
The system runs long enough to generate the evidence an auditor needs.
Internal Audit
You find the findings first, while they are cheap.
Certify
Stage 1, Stage 2, and the certificate — then surveillance.
THEN BACK TO 01 — THEN IT KEEPS GOING
Where a Certificate Is Not Optional
We work wherever procurement has teeth. These are the sectors where the question is when you certify, not whether.
SaaS & Technology
Where enterprise security review is the single biggest drag on the sales cycle, and ISO 27001 is asked for by name.
Financial Services
Banking, payments and fintech, where supplier assurance is a regulatory expectation rather than a preference.
Health & Life Sciences
Patient and trial data carries obligations that buyers will not take on trust from an unaudited supplier.
Public Sector & Defence
Frameworks and tenders that list certification as a pass-or-fail eligibility criterion before scoring begins.
Retail & E-Commerce
Payment data, large supply chains, and sustainability criteria appearing in more and more supplier scorecards.
Professional & Legal
Client confidentiality, continuity obligations, and the quality assurance that panel appointments increasingly require.
Working across
You Probably Need This If Any of This Sounds Familiar
Tick what applies. Most companies come to us with three or four of these.
00 OF 06
Have a read — the gap analysis is free either way.
Fixed Scope. Fixed Fee. No Surprises.
Compliance consultancy has a reputation for open-ended day rates and a bill that grows with the project. We price the work after the gap analysis, when both of us know what it involves.
What you get
- A free gap analysis before you commit to anything
- A fixed implementation fee, quoted once the scope is known
- Senior consultants doing the work, not supervising juniors
- Documentation written for your business, never a template pack
- We attend Stage 1 and Stage 2 with you
- Support through the surveillance years, not just to the certificate
What we will not do
- Sell you a certificate — an accredited body issues that, independently
- Bill by the hour for work we should have scoped properly
- Promise certification in a number of weeks the standard does not allow
- Hand over a policy binder and disappear before the audit
- Take commission for recommending a certification body
- Claim an ISO certificate makes you compliant with a law it does not cover
Who actually issues the certificate — and why that matters
Devtrios is an implementation partner, not a certification body. Under ISO/IEC 17021-1, the accredited body that audits and certifies you must be independent of whoever helped build your management system — a body cannot certify a system it designed. Any consultancy telling you it will 'certify you' is either describing someone else's audit or offering a certificate your buyer may not accept.
- We build the system, prepare the evidence and support you through both audit stages
- An independent, accredited certification body runs Stage 1 and Stage 2 and issues the certificate
- We help you select that body and manage the relationship, at no markup
- Insist on accredited certification — UKAS in the UK, or the national equivalent — because unaccredited certificates get rejected in procurement
Engineers Who Certify, Not Auditors Who Guess
Most ISO consultancies have never built the systems they are writing policies about. We build software for a living, which changes what the controls look like.
Controls built into your stack◆No template packs◆Fixed scope, fixed fee◆Your team trained to answer◆We stay for surveillance
WE DO NOT JUST HAND YOU A FOLDER
Trusted by startups, enterprises, and governments worldwide










































































































The stack behind the platforms we build.
We choose tools for the outcome they deliver, not for the trend they follow.
Frontend
8 tools“Knowledgeable, professional, and responsive — Devtrios added real value at every step of our project and delivered exactly what we needed.”
Where Our Clients Rate Us 5 Stars
Our clients don't just work with us, they recommend us — 4.9 on Google, 5.0 on Clutch and GoodFirms. Every badge below links straight to the profile it comes from. Independent reviews keep pointing to the same three things: strong technical expertise, clear communication, and delivery you can rely on.
Recognised on
Verified reviewsFrequently Asked Questions
Everything you might want to know before we talk. Still unsure? A quick call clears it up.
Ask us anythingIt depends almost entirely on where you start. An organisation with mature security and IT practices can be certified in roughly four to six months. A UK SME starting from a standing start should plan for six to twelve months, and genuinely from-scratch programmes can run longer. One hard constraint is outside anyone's control: your management system usually has to have been operating for around three months before a Stage 2 audit, because the auditor needs real evidence to look at. Be sceptical of anyone promising a certificate in a handful of weeks.
There are two separate costs. The certification body charges its own audit fees, typically a few thousand pounds for an SME in year one plus surveillance fees each year after. Then there is the implementation work. For most UK SMEs, total year-one cost lands somewhere between £6,000 and £25,000 depending on headcount, scope and how much already exists. We quote implementation as a fixed fee after the gap analysis, so you are not buying a blank cheque.
No, and nobody who implements your system can. ISO/IEC 17021-1 requires the certification body to be independent of the consultancy that built the management system. We prepare you and support you through the audit; an accredited certification body assesses you and issues the certificate. We will help you choose one and we do not take a commission for it.
Whichever one is blocking revenue. For software and SaaS companies that is almost always ISO 27001, because it is the one enterprise security teams ask for by name. If you are bidding for public-sector or supply-chain work, ISO 9001 is the most commonly mandated. If you are shipping AI features into regulated industries, ISO 42001 is becoming the differentiator. We will tell you honestly on the first call.
The certificate is valid for three years, but it is not left alone in the meantime. There are surveillance audits at the end of year one and year two, and a full recertification audit in year three. If the system has been ignored, that first surveillance audit is where it shows. We offer ongoing support so the evidence keeps being generated as part of normal work.
Yes, and it is usually cheaper than doing them sequentially. ISO management system standards share a common structure, so the context, leadership, risk, competence, internal audit and management review requirements overlap heavily. Running ISO 27001 and ISO 9001 together, for example, means writing that shared layer once. Certification bodies can also run combined audits.
Not automatically, and anyone who says otherwise is overselling it. ISO/IEC 42001 is not currently a harmonised standard under the AI Act, so certification does not grant a presumption of conformity. What it does give you is third-party evidence of exactly the governance the Act expects — risk management, documentation, human oversight and lifecycle monitoring — which is a substantial head start on the technical documentation you will need.
Some involvement is unavoidable — auditors interview real staff and the controls have to live in your real systems. But the drafting, evidence gathering, audit management and the tedious parts sit with us. We aim to keep engineering time to focused sessions rather than an open-ended tax on your roadmap.
Find out what certification would actually take
A gap analysis tells you the real scope, the real timeline and the real cost before you commit to anything. It is free, and it is yours to keep even if you go elsewhere.
Start Your Next Project with Devtrios
Tell us about your idea or business needs. Our team will review your requirements and get back to you within one business day with a clear plan, timeline, and a free consultation call.



