For growing international companies

Certification and compliance consulting that passes the audit

We prepare the documentation, implement the controls and take your company through ISO/IEC 27001, ISO/IEC 42001, SOC 2, cloud and privacy standards. Big-4 quality of deliverables at pragmatic prices, from an international team with offices in Astana, London and Sheridan, Wyoming.

Clients in Cyprus, the United Kingdom, Lithuania, Poland, Malta, the Netherlands, Germany, Italy, Switzerland, France, Estonia, the UAE, the USA and Kazakhstan.

200+certification projects completed
40+companies certified, from software to fintech
10+countries across Europe, the Gulf and North America
New in 2026

ISO/IEC 42001:2023 certificate obtained for our client

The first international standard for governing how a company builds and uses AI. In August 2026 we took a software development company in Limassol, Cyprus through a full ISO/IEC 42001 certification with an IAS-accredited certification body. The scope covers AI use across software development and internal business functions.

ISO/IEC 42001 is becoming the reference point for AI governance in Europe: it maps onto EU AI Act obligations, answers enterprise customers' due-diligence questions about AI, and sits naturally next to an existing ISO/IEC 27001 system.

  • AI management system documentation: policy, roles, risk and impact assessments, Statement of Applicability
  • Controls for data, models, suppliers and AI used in operations, aligned with ISO/IEC 27001 where you already have it
  • Staff training and internal audit, then support through the certification audit
  • Certificate issued by an accredited body and listed in the international registry
Management system certificate

CERTIFICATE

ISO/IEC 42001:2023

Artificial Intelligence Management System

Governance, management and use of Artificial Intelligence technologies across software development activities and internal business functions, in accordance with the Statement of Applicability.

Client
Software development company, Limassol, Cyprus
Certified since
27 August 2026
Valid until
27 August 2029
Certification body
IAS-accredited management systems certification body
Documentation, implementation and audit support by RatingLab. Client details are disclosed on request.

Services

Documentation, implementation and certification support

Every engagement ends with a certificate from an accredited body, a complete document set your team can actually run, and trained people inside the company.

ISO/IEC 27001:2022

Information Security Management System

  • Gap audit against ISO/IEC 27001:2022
  • Complete ISMS document package, risk and business continuity documentation
  • Training for ISMS owners, certification audit, closing of non-conformities
  • Original certificate and entry in the international online registry
ISO/IEC 42001:2023

AI Management System

  • AI policy, roles, risk and impact assessments, Statement of Applicability
  • Controls for data, models, suppliers and AI in operations
  • Integration with an existing ISO/IEC 27001 system
  • Certification by an accredited body
SOC 2

Type I and Type II readiness for service companies

  • Scope and Trust Services Criteria selection
  • Preliminary assessment, control design and implementation
  • Documentation of processes and evidence
  • Selection of a licensed AICPA auditor, support through the external audit
ISO/IEC 27017 · 27018

Cloud services and personal data protection

  • Assessment of cloud infrastructure security and personal data policy
  • ISMS package for the cloud solution, risk analysis, policies and procedures
  • Certificates for ISO/IEC 27017:2015 and ISO/IEC 27018:2019
  • Compliance with privacy legislation, including GDPR
ENX TISAX

Information security assessment for automotive suppliers

  • Registration of each office in the ENX registry
  • Internal audit and gap analysis, documentation aligned with VDA ISA
  • Selection of an accredited Assessment Office
  • Assessment report and confirmation of compliance on the ENX portal
ISO 9001:2015

Quality Management System

  • Documentation audit and full QMS document package
  • Business continuity documentation
  • Two internal auditor certificates for your staff
  • Certification audit, quality marks, registry entry
ISO 13485:2016

Quality Management System for medical devices

  • QMS document package and medical device risk management
  • Post-market surveillance procedures
  • Employee training and two internal auditor certificates
  • Certification audit and registry entry

How we work

From gap audit to certificate, typically in 3 to 6 months

Smaller companies with established processes move faster. Larger or more complex organizations take longer. The stages are the same.

  1. Gap auditWe review what you already have against the standard and agree the scope.
  2. DocumentationPolicies, procedures, risk assessments and records, written for your company, not from a template.
  3. Implementation and trainingControls go live, responsible people are trained, internal auditors are certified.
  4. Certification auditWe select an accredited body, organize the audit and sit next to your team throughout.
  5. Non-conformities and beyondFindings are closed, the certificate is issued and listed in the registry. We stay on for surveillance audits.

Selected clients

Companies we have certified

ISO/IEC 27001 projects from our casebook.

Itransition Group

Software development, QA, deployment and maintenance

Andersen

Software architecture, embedded, web, mobile, cloud

Softswiss

Online gaming platforms

Scorum

Software development and AI solutions

C-Score

Social rating and anti-fraud software

Altezio

Full software development cycle

Credentially

Business software development

Docfield

Software development, testing and support

SoftTeco

Full software development cycle

HES FinTech

Fintech software development and maintenance

a1qa

Software testing and auditing

Cogniteq

Full cycle of software development

Oxagile

Information systems analysis, design and development

XOR

Software development, testing and support

Virtual Nomad

Software development, support and maintenance

Awery Aviation Software

Aviation software

Anfimau Industry Solutions

Software design, development and technical support

Kate media

Payment systems software and integration

Extengi

ERP and CRM consulting and development

Wedia

Full software development cycle

BITEEU

Virtual currency exchange development

Noventiq

Cloud, virtualization and information security services

ActiveCloud

Cloud platform development and support

Finteco

Software engineering for financial services

PMTech

BIM design and software plug-ins

Raketa

Business travel and expense management platform

Artezio

Software development, testing and support

JB Works

Security operations center services

Neckarwiese

Software development, IT consulting and education

Questions we hear most

What certification actually changes

What problems does it solve?

An ISO/IEC 27001:2022 certificate removes barriers to international tenders and enterprise customers. It formally confirms your level of information security, which makes contracts easier to win and due diligence shorter.

How long does it take?

Preparation (gap analysis and planning), implementation, internal audit and the certification audit usually take from a few months up to a year. Smaller organizations with established processes finish faster.

What are the risks of not being compliant?

Higher chance of data leaks, downtime, lawsuits, fines, lost customer trust and reputational damage, all of which hit profitability and long-term stability directly.

What ROI can be expected?

Avoided losses from incidents and fines, lower recovery costs, streamlined operations, new contracts and brand value, often lower insurance premiums, minus the total certification investment.

What does it cost?

Initial assessment and consulting, implementation of technical and organizational measures, certification audit fees and ongoing compliance. A detailed budget is tailored to each organization.

What changes inside the company?

Formal ISMS scope and security policy, asset inventory, risk assessment and treatment, core controls (access, logging, backup, patching, encryption), incident response and supplier procedures, regular training and internal audits.

Request a scope and quote

Tell us what your customers are asking for

Which standard, how many people and offices are in scope, and when you need the certificate. We come back within one business day with a scope, a timeline and a budget.

The form opens WhatsApp with your message prefilled, so it reaches a consultant directly. Nothing is stored on this website.

By sending you agree to our privacy policy. We reply in English or Russian.

Start with a free consultation

Tell us which standard your customers are asking for and where your company operates. We will come back with a scope, a timeline and a budget within one business day.

+44 7452 348554
London office. Calls and messages in English and Russian.