Case Study — Technology / Compliance
ISO 27001:2022 Certification for a SaaS Fintech: 8 Months, Zero Non-Conformities
A Series B fintech offering BNPL infrastructure to mid-market retailers needed ISO 27001:2022 certification to close an enterprise deal with a Tier-1 bank. Starting from scratch, eNeoteric delivered certification-ready ISMS documentation, trained the team, and guided them to Stage 2 audit success in 8 months.
The Challenge
The client's VP of Engineering had no prior ISO 27001 experience. They had 38 staff, a cloud-native AWS stack, and a 90-day deadline set by the prospective bank customer. Their initial self-assessment had identified over 120 control gaps across the Annex A requirements.
The engagement needed to be delivered remotely (team split between Bengaluru and Pune), and the ISMS had to be proportionate to a fast-moving startup — no over-engineering with controls that would be dropped within 6 months of certification.
Our Approach
- Month 1: Gap assessment — Structured interviews across engineering, HR, finance, and operations. Produced a prioritised gap register with effort estimates for each of the 93 applicable controls.
- Month 2–4: ISMS design — Information security policy suite (18 policies), risk register, asset inventory, Statement of Applicability (SoA), and ISMS scope documentation. All adapted to the client's AWS / GitHub / Jira / Slack toolchain.
- Month 5–6: Control implementation — Supported implementation of technical controls (CloudTrail audit logging, GuardDuty, WAF, MFA enforcement, S3 encryption), physical controls (clean-desk, visitor policy, equipment disposal), and HR controls (background checks, NDA, security awareness training).
- Month 7: Internal audit — eNeoteric conducted a full internal ISMS audit, issued 6 minor observations, and supported corrective action closure before the Stage 1 audit.
- Month 8: Stage 1 + Stage 2 audit support — Accompanied the client through both audits, provided real-time guidance during Stage 2, and managed all auditor queries.
Key Outcomes
- ISO 27001:2022 certificate issued by a UKAS-accredited certification body in month 8
- Zero major non-conformities; 2 minor observations raised and closed before certificate issue
- 18-policy security policy suite + risk register maintained in Notion for ongoing ISMS management
- Security awareness training completed by 100% of staff (including contractors)
- Enterprise deal signed with the Tier-1 bank within 2 weeks of certificate issue
Outcomes & Impact
The client's Series C fundraise included ISO 27001 as a due diligence checkpoint. The certificate, achieved 2 months ahead of the bank's deadline, also opened conversations with two additional enterprise customers who had ISO 27001 as a vendor prerequisite.
The ISMS built during this engagement has since been maintained internally, with eNeoteric conducting the annual internal audit and supporting each surveillance audit.
“We had 90 days and zero ISO 27001 experience. eNeoteric ran the whole thing — documentation, training, internal audit, Stage 2 support. We hit the bank's deadline with 2 months to spare and closed the deal.”VP EngineeringSeries B BNPL Fintech, Bengaluru
Related services
Get in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.