How we work

From uncertainty to audit readiness.

Every ISO 27001 journey depends on scope, maturity, ownership and existing evidence. For focused startups and SMEs, readiness programmes commonly run over 8 to 16 weeks. Quaesta provides the structure, challenge and assurance needed to move from uncertainty to audit readiness.

Step I

Scope & commercial drivers

We clarify why ISO 27001 matters, what needs to be in scope, and which customers, investors or procurement requirements are driving the deadline.

Step II

Gap analysis & evidence review

We assess your current ISMS, policies, risk process, controls, evidence and platform configuration if using Vanta, Drata or similar.

Step III

Roadmap & coaching plan

We turn the findings into a prioritised implementation roadmap with clear ownership, evidence requirements and certification milestones.

Step IV

ISMS build support

Your team implements. Quaesta coaches, reviews, challenges and helps ensure the ISMS is practical, risk-based and auditable.

Step V

Audit readiness

We review evidence, support management review preparation, challenge the Statement of Applicability and prepare the team for Stage 1 and Stage 2.

Step VI

Sustain & improve

After certification, Quaesta can support internal audit, surveillance preparation and annual ISMS assurance.

Begin with a scoping conversation.

Book an ISO readiness call