Fixed-price packages

ISO 27001 support, from readiness review to internal audit.

Quaesta provides fixed-scope ISO 27001 services for startups and SMEs that need a practical route to certification, stronger customer assurance, or independent internal audit support.

PackageFrom £1,950

ISO 27001 Readiness Snapshot

Best for: Early-stage teams that need to understand what certification would involve.

  • 90-minute discovery workshop
  • Scope discussion
  • High-level maturity review
  • Certification effort estimate
  • Prioritised next steps
View package details →
PackageFrom £3,950

Gap Analysis & Certification Roadmap

Best for: Startups and SMEs preparing seriously for ISO 27001.

  • Scope review
  • Policy and evidence review
  • Risk and SoA maturity review
  • Control gap assessment
  • Prioritised remediation roadmap
  • Executive readout
View package details →
PackageFrom £9,500

Certification Coaching

Best for: Teams that will implement the ISMS themselves but want expert support.

  • Implementation roadmap
  • Coaching workshops
  • Risk assessment guidance
  • Statement of Applicability review
  • Evidence review checkpoints
  • Stage 1 and Stage 2 readiness support
View package details →
PackageFrom £3,950

Vanta / Drata Readiness Review

Best for: Teams using a compliance platform who want independent assurance before audit.

  • Platform configuration review
  • Evidence completeness review
  • Control mapping review
  • Risk register and SoA review
  • Audit-readiness score
  • Remediation plan
View package details →
PackageFrom £4,950

Outsourced Internal Audit

Best for: Certified or certification-ready organisations that need an objective internal audit.

  • Audit plan
  • Document and evidence review
  • Control testing
  • Stakeholder interviews
  • Findings report
  • Corrective action recommendations
View package details →
PackageFrom £750 / month

Annual ISMS Assurance Retainer

Best for: Certified organisations that want to stay ready for surveillance and continuous improvement.

  • Quarterly ISMS reviews
  • Risk register and SoA review
  • Surveillance audit preparation
  • Management review support
  • Supplier / security questionnaire allowance
  • Internal audit planning
View package details →
Differentiator · ISO 42001

AI Governance & ISO 42001 Readiness

For AI and SaaS businesses, Quaesta extends information security governance into responsible AI controls and ISO 42001 readiness.

Bespoke advisory →

What is not included unless agreed

To keep delivery focused and fixed-price, Quaesta does not provide unlimited implementation, technical remediation, penetration testing, certification-body fees, legal advice, or guaranteed certification outcomes. The client remains responsible for implementing controls, approving risk decisions, maintaining evidence and operating the ISMS.

Not sure which package fits?

Book an ISO readiness call