Fixed-price packages
ISO 27001 support, from readiness review to internal audit.
Quaesta provides fixed-scope ISO 27001 services for startups and SMEs that need a practical route to certification, stronger customer assurance, or independent internal audit support.
ISO 27001 Readiness Snapshot
Best for: Early-stage teams that need to understand what certification would involve.
- —90-minute discovery workshop
- —Scope discussion
- —High-level maturity review
- —Certification effort estimate
- —Prioritised next steps
Gap Analysis & Certification Roadmap
Best for: Startups and SMEs preparing seriously for ISO 27001.
- —Scope review
- —Policy and evidence review
- —Risk and SoA maturity review
- —Control gap assessment
- —Prioritised remediation roadmap
- —Executive readout
Certification Coaching
Best for: Teams that will implement the ISMS themselves but want expert support.
- —Implementation roadmap
- —Coaching workshops
- —Risk assessment guidance
- —Statement of Applicability review
- —Evidence review checkpoints
- —Stage 1 and Stage 2 readiness support
Vanta / Drata Readiness Review
Best for: Teams using a compliance platform who want independent assurance before audit.
- —Platform configuration review
- —Evidence completeness review
- —Control mapping review
- —Risk register and SoA review
- —Audit-readiness score
- —Remediation plan
Outsourced Internal Audit
Best for: Certified or certification-ready organisations that need an objective internal audit.
- —Audit plan
- —Document and evidence review
- —Control testing
- —Stakeholder interviews
- —Findings report
- —Corrective action recommendations
Annual ISMS Assurance Retainer
Best for: Certified organisations that want to stay ready for surveillance and continuous improvement.
- —Quarterly ISMS reviews
- —Risk register and SoA review
- —Surveillance audit preparation
- —Management review support
- —Supplier / security questionnaire allowance
- —Internal audit planning
AI Governance & ISO 42001 Readiness
For AI and SaaS businesses, Quaesta extends information security governance into responsible AI controls and ISO 42001 readiness.
What is not included unless agreed
To keep delivery focused and fixed-price, Quaesta does not provide unlimited implementation, technical remediation, penetration testing, certification-body fees, legal advice, or guaranteed certification outcomes. The client remains responsible for implementing controls, approving risk decisions, maintaining evidence and operating the ISMS.