End-to-end ISO 27001 implementation and certification support. From gap analysis to passing your Stage 2 audit — we guide East African organisations through every step, without the bloated consulting retainers.
ISO/IEC 27001:2022 is the internationally recognised standard for establishing, implementing, and continually improving an Information Security Management System (ISMS). Certification signals to clients, investors, and regulators that you manage information security systematically and rigorously.
Most enterprise procurement teams require ISO 27001. Certification unlocks RFPs you currently cannot bid on.
Series A–C investors increasingly expect ISO 27001 as evidence of operational maturity and risk management.
A properly implemented ISMS identifies and remediates your highest-risk areas before attackers find them.
We handle the methodology, documentation, and audit preparation. Your team keeps building your product.
For most East African organisations, 6–9 months is realistic from kick-off to certificate. Smaller organisations with simpler IT environments can move faster (4–6 months). Larger or more complex organisations may need 9–12 months. We set a realistic timeline during gap analysis and hold to it.
No. SecureZaidi functions as your external ISMS implementation team. We handle all the expertise — gap analysis, policy writing, risk assessment, internal audit, and audit support. Your team provides context and approvals; we do the heavy lifting.
Total cost depends on your organisation's size, complexity, and current security maturity. Our fees cover the implementation engagement. Certification body fees (typically $3,000–$8,000 USD for SMEs) are separate. We provide a fixed-fee proposal after the initial gap assessment.
The 2022 update restructured Annex A from 114 controls across 14 domains to 93 controls across 4 themes, and added 11 new controls. If you're starting fresh, we implement 27001:2022 from day one. If you're transitioning from 2013, the transition deadline was October 2025 — we can help you assess your gap.
Yes — and there are significant overlaps. ISO 27001 controls around access management, data handling, and vendor management directly support Kenya DPA compliance. We routinely run joint programmes that achieve both certifications efficiently, reducing duplicated effort by around 40%.
Book a 15-minute scoping call. We'll review your current posture, estimate your gap, and give you a realistic timeline and cost — no commitment required.