Skip to content

Service / Security & compliance

SOC 2 and ISO 27001 readiness, engineered into your product

SOC 2 and ISO 27001 readiness means getting your product, cloud and team ready for an independent auditor, with the controls built into the system rather than written into a policy pack. It is for UK SaaS companies and scale-ups that need SOC 2, ISO 27001 or both to win enterprise customers, and engagements start from £3,500.

I’m Arslan Zaheer, a UK-based independent consultant and Head of Engineering (AI & Cloud) at Magnus Infotech, with an MSc in Cyber Security and Forensic Information Technology from the University of Portsmouth. I was named Cybersecurity Engineer of the Year 2026 in the Corporate LiveWire Innovation & Excellence Awards, and I build controls as working code, not documents.

From £3,500NDA-readyLast updated 3 October 2026

Readiness, not audit: where I fit alongside your auditor

I am not an auditor and I don’t issue SOC 2 reports or ISO 27001 certificates. A SOC 2 report can only come from a licensed CPA firm, and ISO 27001 certification from an accredited certification body. My job is everything before that: finding the gaps, building the controls into your product and cloud, and organising the evidence so the audit has fewer surprises.

Keeping the two roles separate is good practice: the people who build your controls should not be the people who sign them off. I work alongside your chosen auditor, answer their technical questions during fieldwork, and help your team fix anything they raise.

Gap analysis

Every engagement starts with a gap analysis against the framework you need. I compare what you have today with what an auditor will expect to see, looking at the code, cloud accounts, CI/CD pipeline, access lists and your existing policies, not just interviews and questionnaires.

The gap analysis is useful on its own: it tells you how far you are from audit-ready and what to fix first, before you commit to an auditor or a timeline.

  • Scope: which products, systems, data and teams the audit will cover
  • Control-by-control status: in place, partly in place or missing
  • Evidence gaps, where a control exists but can’t yet be proved
  • A prioritised roadmap with effort estimates and owners

Engineering the controls (encryption, MFA, RBAC, logging, secure SDLC)

This is where an engineer-led approach differs from a policy-led one. Auditors test whether a control actually operates, so it needs to live in your product, your cloud and your delivery process, and it needs to produce evidence without someone collecting screenshots by hand.

I have done this work on a live platform: as Senior Backend, AI & Cybersecurity Engineer at Bodytrak, I implemented encryption, MFA and RBAC and worked on SOC 2 and ISO 27001 for a real-time industrial safety platform. I write the code myself or pair with your engineers, so the controls stay maintainable after I leave.

  • Encryption of data at rest and in transit, with key management you can explain to an auditor
  • MFA and single sign-on for staff, and for customers where the product needs it
  • Role-based access control in the application and least-privilege access in AWS, Azure or GCP
  • Audit logging and monitoring that records who did what, and alerts on what matters
  • A secure SDLC: code review, dependency and secrets scanning, protected branches and release sign-off in CI/CD
  • Backups, recovery testing, change management and vendor reviews

GDPR for engineering teams

UK GDPR is a legal framework, but a lot of the work lands on engineering. I don’t give legal advice; I work with your legal or privacy lead and turn their requirements into features, jobs and settings that actually run.

Much of this overlaps with SOC 2 and ISO 27001 controls, so it makes sense to plan them together.

  • A map of where personal data lives across databases, logs, backups and third-party processors
  • Data minimisation, retention rules and automated deletion
  • Subject access and erasure requests that can be fulfilled without manual database work
  • Data residency and international transfer settings in your cloud
  • Engineering input to DPIAs, including for AI features that process personal data

SOC 2 vs ISO 27001: which first for UK SaaS?

It depends on who you sell to. SOC 2 is an American attestation framework, and US buyers usually ask for it. ISO 27001 is an international standard for an information security management system, and UK and European enterprise buyers often ask for it instead.

For a UK SaaS company with US customers in the pipeline, SOC 2 usually comes first. Many companies start with a Type 1 report on control design, then move to a Type 2 report covering a period of operation. If your pipeline is mainly UK and EU, ISO 27001 often comes first. Because the two frameworks overlap heavily, I design controls once and map them to both, so adding the second later doesn’t mean starting again.

What you get

  • A gap analysis against SOC 2, ISO 27001 or both, with a prioritised roadmap
  • A control matrix mapping each control to the system, owner and evidence that proves it
  • Controls engineered into your product and cloud: encryption, MFA, RBAC, logging and secure SDLC
  • Practical security policies that describe what your team actually does
  • A risk register and threat model you can keep up to date
  • An evidence pack organised the way your auditor will ask for it
  • Support during audit fieldwork to answer technical questions and close findings

How it works

  1. Step 01 · Weeks 1–2

    Gap analysis

    NDA, then a review of your code, cloud, processes and policies against the framework. You get the gap report and a prioritised roadmap with a fixed or capped price for the next stage.

  2. Step 02 · Depends on the gaps

    Engineer the controls

    I build or pair on the technical controls, write policies that match how you work, and set up evidence collection that needs as little manual effort as possible.

  3. Step 03 · Before the audit window

    Pre-audit review

    A mock walkthrough of each control and its evidence, so issues are found by us rather than by your auditor.

  4. Step 04 · During fieldwork

    Audit support

    Your licensed auditor or certification body runs the audit. I answer technical questions and help your team close any findings.

Proof

  • “He’s played a key role in driving our efforts toward SOC 2 and ISO 27001 compliance, and improving our software security capabilities.”

    Leon Marsh

    Founder CEO · Board Director, Advisor & NED

  • “Particularly impressed by Arslan’s initiative in implementing robust security measures for SOC 2 and ISO 27001 standards.”

    Matthew Mammana

    Programme & Operations Manager

  • “He has been instrumental in leading key security initiatives that have significantly strengthened our company’s overall security posture.”

    Sam Tszho Ho

    Head of AI and Platform

Price

From £3,500. For the gap analysis and roadmap. Control engineering is scoped and priced in writing. Every engagement starts with a free 1-hour intro call, and you get a written scope with a fixed or capped price before any work starts.

FAQ

How much does SOC 2 readiness cost for a UK SaaS company?

My readiness work starts from £3,500 for a fixed-scope gap analysis and roadmap. Engineering the controls is priced separately once we know the gaps, as a fixed or capped price agreed in writing. The auditor’s fee is separate and paid directly to the audit firm.

Can you certify us for ISO 27001 or issue our SOC 2 report?

No. ISO 27001 certificates are issued by accredited certification bodies, and SOC 2 reports by licensed CPA firms. I prepare you for that audit and support you through it, which keeps the builder and the assessor independent of each other.

How long does it take to get SOC 2 ready?

It depends on where you start, which is why the gap analysis comes first and ends with a realistic plan. A Type 2 report also covers an observation period agreed with your auditor, so the controls must be running before that period starts. You get a timeline you can share with customers who are waiting.

Do we need a compliance automation platform?

Not always. These platforms help collect evidence and track policies, but they don’t build the controls for you. If you already use one, I work with its control list and fix what it flags in your code and cloud; if you don’t, I’ll tell you honestly whether it is worth the cost at your stage.

We’re a small team. Is it too early for SOC 2?

Not if enterprise prospects are already sending you security questionnaires. Controls are easier to build in early than to retrofit later. If a full audit is not yet worth it, the gap analysis alone gives you honest answers for questionnaires and a plan to show buyers.

Does this cover the AI features in our product?

Yes. Auditors and enterprise buyers increasingly ask how AI features handle customer data. I can add controls for model access, prompt injection and data leakage to your readiness work, then test them with an AI red-team assessment.

Let’s talk about what you’re building.

Book a free 1-hour intro call, or send a short brief and I’ll reply with a proposed scope within two working days.