How we work
From uncertainty to audit readiness.
Every ISO 27001 journey depends on scope, maturity, ownership and existing evidence. For focused startups and SMEs, readiness programmes commonly run over 8 to 16 weeks. Quaesta provides the structure, challenge and assurance needed to move from uncertainty to audit readiness.
Scope & commercial drivers
We clarify why ISO 27001 matters, what needs to be in scope, and which customers, investors or procurement requirements are driving the deadline.
Gap analysis & evidence review
We assess your current ISMS, policies, risk process, controls, evidence and platform configuration if using Vanta, Drata or similar.
Roadmap & coaching plan
We turn the findings into a prioritised implementation roadmap with clear ownership, evidence requirements and certification milestones.
ISMS build support
Your team implements. Quaesta coaches, reviews, challenges and helps ensure the ISMS is practical, risk-based and auditable.
Audit readiness
We review evidence, support management review preparation, challenge the Statement of Applicability and prepare the team for Stage 1 and Stage 2.
Sustain & improve
After certification, Quaesta can support internal audit, surveillance preparation and annual ISMS assurance.