ISO 27001 · Vanta/Drata Assurance · Internal Audit
ISO 27001 certification support for startups and SMEs.
Quaesta helps growing businesses become audit-ready through senior-led gap analysis, certification coaching and outsourced internal audit.
Whether you are preparing for your first ISO 27001 certification, using Vanta or Drata and need independent assurance, or responding to enterprise procurement pressure, we give you a clear path from current state to credible evidence.
UK-based · Founder-led · ISO 27001, ISMS assurance and AI governance support

When ISO 27001 becomes urgent
Built for the moment security becomes a growth requirement.
Enterprise customer asking for ISO 27001
Turn procurement pressure into a clear certification roadmap.
Vanta or Drata in place, but not audit-ready
Validate whether your platform evidence, risk register, controls and Statement of Applicability are genuinely ready for audit.
Security questionnaires slowing sales
Build the management-system evidence needed to answer customers with confidence.
Internal audit or surveillance audit approaching
Get independent, structured assurance before your certification body does.
Fixed-price engagements
Six ways we help, with clear price anchors.
ISO 27001 Gap Analysis & Roadmap
Understand where you stand today, what is missing, and what needs to happen before certification.
Certification Coaching
Structured ISO 27001 support for teams that want to implement the ISMS themselves with expert guidance and challenge.
Vanta / Drata Readiness Review
Independent review of your platform configuration, evidence, risk register, SoA and audit readiness.
Outsourced Internal Audit
Objective ISO 27001 internal audit support before certification, surveillance or recertification.
Annual ISMS Assurance
Ongoing quarterly support to keep your ISMS operating, evidenced and ready for surveillance.
AI Governance & ISO 42001 Readiness
For AI and SaaS businesses, Quaesta can help extend security governance into responsible AI controls and ISO 42001 readiness.
Why Quaesta
Credible assurance, without a bloated consultancy project.
Quaesta is designed for organisations that need credible security assurance without a bloated consultancy project. We combine ISO 27001 structure with commercial pragmatism, helping teams understand what auditors, enterprise customers and investors will expect to see.
Senior-led, not template-led
Every engagement is run by an experienced practitioner — no junior associates writing your policies.
Fixed-scope packages
Clear deliverables, clear price anchors, no open-ended retainers.
Evidence-focused
Practical work that auditors, enterprise customers and investors will recognise.
Built for startups and SMEs
Calibrated for growing teams under commercial pressure, not for global enterprises.
Strong fit for SaaS and AI
Deep experience with technology, professional services and AI-enabled businesses.
Works alongside Vanta and Drata
We integrate with the compliance platforms you already use — and tell you honestly where the gaps remain.
Ready to become audit-ready?
Most readiness programmes run over 8 to 16 weeks. Start with a 30-minute scoping call.