ISO 27001, without losing product momentum.

Your customers need confidence in your security. Your team needs a manageable path to certification.

I build and manage your information security management system, prepare your team, and coordinate the certification audit. Clear responsibilities, practical policies, and support through both audit stages.

What the engagement costs

You want the job done right, but you also need to control the budget. We're transparent. Here are the numbers.

Auditor & gap analysis

I bring an independent auditor I work well with, so we can get straight to preparing your team.

Internal audit (dry run)
$20,000
ISO certification
$25,000

Reuben’s time

50–100 hours of hands-on security leadership, covering the custom services below.

Hourly rate
$250/hr
Estimated fees
$12,500–$25,000

Penetration testing

A penetration tester for multiple engagements, with time to address findings and test again.

Multiple engagements
$5,000

Build the system behind the certification.

A complete ISO 27001 engagement, from gap analysis and risk assessment to your certification audit. I tailor your ISMS, policies, and preparation to the way your company operates.

Readiness & roadmap

Assess what you already have and define the path to certification.

  • ISO 27001 readiness assessment
  • Prioritized security improvement plan
  • Quarterly reviews and adjustments

ISMS & policies

Create an information security management system that fits your organization.

  • ISMS design and documentation
  • Policies aligned to applicable Annex A controls
  • Risk assessment and treatment plan

Testing & audit partners

Bring the right specialists into the engagement and coordinate their findings.

  • Multiple penetration testing engagements
  • ISO 27001 gap analysis
  • Independent Stage 1 and Stage 2 audits

Team training

Give people the knowledge and responsibilities to maintain the security program.

  • Policy rollout and training
  • Security awareness sessions
  • Software development process improvements

Audit management

I coordinate with the certification body and help your team prepare for the audit.

  • Representation during the audit process
  • Documentation and evidence coordination
  • Meeting recordings available to your team

Handover & ongoing support

Keep your security program running after the audit, with clear ownership and practical guidance.

  • Staff guidance on maintaining the program
  • Responsibilities and recurring tasks documented
  • Ongoing fractional CISO support available

Your fractional CISO: Reuben Firmin.

I’ve managed security while leading engineering teams. At ExecVision, I owned the SOC 2 program alongside architecture and product delivery, taking the company from prototype through acquisition.

I understand what an audit asks of a small team. I handle the coordination, turn broad requirements into specific tasks, and keep you involved in the decisions that need your input.

See my experience and background
Reuben Firmin

Security leadership, in clients’ words.

Client experiences from SOC 2 programs and broader security engagements.

Francois Huet

Francois Huet

Head of Engineering, Cadence OneFive

"We maintained laser focus on product delivery without compromising our compliance requirements."

"Navigating SOC 2 certification is a complex and time-consuming process that diverts critical technical resources from core product development. Reuben transformed this challenge by strategically managing the certification journey, streamlining mundane tasks, and identifying cost-effective solutions while minimizing team disruption. Thanks to his expertise, we maintained laser focus on product delivery without compromising our compliance requirements."

David Stillman

David Stillman

CEO, ExecVision

"Reuben ran our SOC 2 compliance program for 5 years in a row. We always had a clean audit."

"At ExecVision, Reuben ran our SOC 2 compliance program for 5 years in a row. We always had a clean audit. Our security posture was reliably strong enough that our Fortune 100 Fintech clients were satisfied that we were compliant with their requirements."

Lucas Gray

Lucas Gray

Head of Engineering, Alloy Health

"We now feel more secure and better prepared thanks to his guidance."

"We had an excellent experience working with Reuben on our company's security initiatives. He provided a comprehensive list of security recommendations tailored to our needs. His expertise helped us formulate and implement security best practices, and his security awareness presentation to our team was engaging and highly informative. We now feel more secure and better prepared thanks to his guidance. I highly recommend Reuben for any organization looking to strengthen their cybersecurity posture."

Questions about ISO 27001

What is ISO 27001?

ISO/IEC 27001 is an international standard for information security management systems, often called an ISMS. It sets requirements for managing information security risks and continually improving the way your organization handles them.

How is it different from SOC 2?

ISO 27001 certification assesses your information security management system against the standard. SOC 2 is an independent examination and report on controls relevant to specified trust services criteria.

Start with what your customers require and the scope of your business. I can help you plan for either framework or coordinate the preparation if you need both.

What does the engagement include?

An independent auditor I work well with: $20,000 for the internal audit (dry run) and $25,000 for ISO certification. My time is $250 per hour, with 50–100 hours anticipated ($12,500–$25,000). Multiple penetration testing engagements cost $5,000.

My time covers the custom readiness planning, ISMS and policies, risk assessment, training, and audit coordination listed above. We agree the scope and responsibilities before starting.

How long does certification take?

The schedule depends on the scope, the maturity of your existing security program, the changes needed, and the certification body’s availability. We assess those factors first, then agree milestones and responsibilities.

Who performs the certification audit?

An independent certification body performs the Stage 1 and Stage 2 audits and makes the certification decision. I prepare and manage your ISMS and coordinate with the auditors.

What happens after certification?

The ISMS needs to stay active as your business changes. Your team continues to maintain policies, manage risks, and prepare for the certification body’s surveillance and recertification audits.

I help your staff learn how to maintain the program. You can then manage it in-house or retain me as your fractional CISO.

What do your customers need to see?

Tell me about the certification requirement, your target date, and your existing security program. We can work out the scope and a realistic plan.

Book an introductory call [email protected]