/

  / ISO 27001 to NHS DSPT Mapping: What Vendors Can Reuse

ISO 27001 to NHS DSPT Mapping: What Vendors Can Reuse

If your ISO 27001 certificate covers all of your health and care data processing, the NHS Data Security and Protection Toolkit does two useful things with it. It marks the applicable evidence items as complete on its own, and it shrinks the scope of any independent audit to whatever your certification doesn’t already cover.

A certified vendor who does the mapping properly walks into a DSPT submission with most of the technical and organizational evidence already written, already audited, and already versioned.

What ISO 27001 won’t do is get you out of the DSPT. It says nothing about the NHS-specific information governance items, clinical safety, the national data opt-out, or Caldicott principles.

Vendors who assume “certified means done” usually discover this in the last two weeks of June.

This piece is for the founder, CTO, or ops lead at a UK health-tech company who owns compliance without being a compliance person. It covers what each framework asks for, which Annex A controls line up with which DSPT requirements, which evidence you can reuse as-is, which needs reframing around patient data, and a five-step workflow for turning an existing ISMS into a DSPT submission. One more thing on timing: NHS England published DSPT version 9 for the 2026/27 cycle on 4 September 2026, and the submission deadline is 30 June 2027. So this exercise belongs in your calendar now, not next spring.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Understanding the Two Frameworks at a Glance​

What ISO 27001:2022 Covers

ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). It comes in two halves. Clauses 4 to 10 define the management system itself: context, leadership, risk assessment and treatment, resourcing, operation, performance evaluation, and continual improvement. Annex A lists 93 reference controls across four themes (organizational, people, physical, technological).

Your Statement of Applicability (SoA) records which of those controls you apply, which you exclude, and why.

An accredited certification body issues the certificate after a two-stage audit, then you keep it through annual surveillance audits and a three-year recertification cycle. The certificate covers a defined scope, and that scope statement is the first thing a DSPT assessor reads.

What the NHS DSPT Requires in 2026/27

The Data Security and Protection Toolkit (DSPT) is NHS England’s annual online self-assessment for every organization that touches NHS patient data or systems. It’s a contractual requirement under the NHS Standard Contract. Your published status (“Standards Met”, “Standards Exceeded”, “Approaching Standards”, “Standards Not Met”) is publicly searchable, so procurement teams and prospective NHS customers do look it up.

The Toolkit isn’t one assessment. NHS England tailors it by organization category, and your category decides which assertions you answer and whether you need an independent audit. Version 9 came out on 4 September 2026. The Category 1 view is aligned to CAF version 4.0, and the whole thing closes on 30 June 2027.

Insider Note: Most health-tech SaaS vendors are Category 3, not Category 2. To be an IT Supplier you need all three things at once: digital goods or services to the NHS, 50 or more staff, and £10 million or more in turnover. Picking “IT Supplier” because you sell NHS-facing software, without hitting the size thresholds, lands you in a heavier evidence set and a mandatory audit you may not need. Check the category before you check anything else.

Key Structural Differences Between ISO 27001 and DSPT

Four differences matter when you’re trying to reuse evidence.

  • What they’re about.
    ISO 27001 is an information security standard. The DSPT is an information governance standard that includes security. A good chunk of it deals with lawful basis, transparency, data subject rights, records management, and the SIRO and Caldicott Guardian roles. None of that is in Annex A.

  • How you’re assured.
    ISO 27001 gets certified once and surveilled once a year by an accredited body. The DSPT starts from a blank submission every year, and Category 1 and 2 organizations get independently assessed every year too.

  • How granular they are.
    Annex A controls read as objectives (“access rights shall be provisioned, reviewed, modified and removed”). DSPT evidence items read as things to upload (“a list of all systems that hold personal data, with the date of last review”). So the mapping runs many-to-one in both directions.

  • Where they’re heading.
    Since 2024/25 NHS England has been moving the Toolkit onto the NCSC Cyber Assessment Framework (CAF). CAF is outcome-based: assessors score you Achieved, Partially Achieved, or Not Achieved against an NHS England profile, rather than accepting a policy upload as proof. Category 1 organizations are already there. Category 2 and 3 are still on assertions and evidence, but NHS England has said CAF alignment will reach more organization types over time.

The Business Case for Reusing ISO 27001 Evidence in DSPT

How Much of DSPT Can Realistically Be Satisfied by ISO 27001 Controls

For a Category 2 or 3 vendor with a full-scope ISO 27001 certificate, expect 60 to 75 percent of the mandatory evidence items to come from ISMS artifacts, either automatically (where the Toolkit auto-completes them) or with some light reframing. The rest is NHS-specific governance and information governance content that ISO 27001 doesn’t touch.

The NHS’s own guidance treats reuse as a scope question. The DSPT help pages say an ISO 27001 certification must cover all health and care data processing to receive the full exemption, and that a certificate scoped only to an IT department is good evidence for many of the IT questions but not all of them. If your certificate says “the SaaS platform hosted in AWS eu-west-2” and NHS data also passes through your support desk tooling, your analytics sandbox, and a contractor’s laptop, the auto-completion won’t apply. Your assessor will want to know how those flows are controlled.

Time and Cost Savings for Health-Tech Vendors

There’s no fee to submit the DSPT. The cost is internal time, plus, if you’re Category 2, the independent audit and the annual penetration test the mandatory assertions expect.

Building a first DSPT submission from nothing usually takes a small vendor three to five months of part-time effort: writing policies, standing up an asset register, documenting suppliers, running training, and producing evidence for each one. The same submission built on top of a live ISMS is normally a four to eight week job, and most of that goes on the NHS-specific gaps rather than on security basics. For Category 2 vendors the independent audit runs two to three days, and assessors will agree at scoping that anything your ISO 27001 audit already covered can come out of theirs.

The saving founders tend to underestimate isn’t year one. It’s years two through five, when a well-run ISMS produces the DSPT evidence pack as a by-product of the surveillance audit cycle instead of as a separate annual scramble.

Reducing Duplicate Audit Effort Across Frameworks

ISO 27001, Cyber Essentials Plus, the DSPT, and the Digital Technology Assessment Criteria (DTAC) all draw on overlapping evidence, and NHS procurement often asks for two or three of them together. The DTAC in particular uses your DSPT status and Cyber Essentials as inputs. Running one control set, one risk register, and one evidence library tagged against all four is what separates a compliance function that scales from one that grows with every new NHS contract.

ISO 27001 to NHS DSPT Control Mapping

Mapping Annex A Controls to DSPT Assertions

The National Data Guardian’s 10 Data Security Standards still sit underneath the Category 2, 3, and 4 Toolkit views, and they group naturally against Annex A themes. NHS England publishes the official cross-reference as a spreadsheet alongside the Toolkit, and that should be your source of truth when you fill in the submission.

Information Security Policies (A.5) → DSPT Data Security Standards

Your top-level information security policy (A.5.1) and the topic-specific policies under it map straight onto the DSPT’s requirement for approved, communicated, and reviewed policies. What the DSPT adds is proof that the board or senior leadership signed them off within the assessment year, plus a review date. A policy last approved 14 months ago is a finding under either framework. The DSPT assessor will just spot it first.

Access Control (A.5.15–A.5.18) → DSPT Access Control Requirements

This is the cleanest overlap. Your access control policy, joiner-mover-leaver procedure, privileged access records, and quarterly access reviews cover the DSPT’s requirements for role-based access, removing leavers, and periodic review. The one addition is multi-factor authentication. NHS England’s MFA policy expects MFA for all remote access and all privileged access to externally hosted systems, and since v8, Cyber Essentials Plus on its own no longer counts as evidence. Write up your MFA coverage explicitly, exceptions included.

Human Resource Security (A.6) → DSPT Staff Training and Responsibilities

Screening, contract terms, awareness training, and the disciplinary process (A.6.1 to A.6.4) map onto NDG standards 2 and 3. Since 2023/24, the DSPT no longer demands 95 percent completion of a specific e-learning module. It asks that all staff have an appropriate understanding of information governance and cyber security. Your A.6.3 training records will show that, as long as the content covers patient confidentiality and not just phishing.

Asset Management (A.5.9–A.5.14) → DSPT Asset and Device Management

Your information asset inventory (A.5.9), classification scheme (A.5.12), and acceptable use rules (A.5.10) cover the DSPT’s asset and device items. The DSPT is more prescriptive, though. It wants a register of systems holding personal data, with owners, and for some categories, a digital asset register of hardware and software. If your ISMS inventory is organized by information asset rather than by system, plan on adding a system-level view.

Cryptography and Data Protection (A.8.24) → DSPT Confidentiality Requirements

Your cryptography policy and proof of encryption at rest and in transit cover the DSPT’s confidentiality items for data in transit, on mobile devices, and in backups. The DSPT also asks about secure email (NHSmail or a DCB1596-compliant equivalent) for sending patient data. That’s an NHS-specific expectation your ISMS won’t have addressed unless you already serve the NHS.

Incident Management (A.5.24–A.5.28) → DSPT Incident Reporting

Your incident management plan, incident log, and lessons-learned records carry over well. What changes is the reporting route. The DSPT has its own incident reporting tool, and reportable personal data breaches involving NHS data have to go through it (it forwards to the ICO) rather than only through your own ICO process. Your A.5.26 response procedure needs a step that says so.

Supplier Relationships (A.5.19–A.5.23) → DSPT Third-Party Assurance

Supplier policy, due diligence records, and contractual security clauses transfer directly. The DSPT adds an explicit ask for an up-to-date list of suppliers processing health and care data, and the NHS Standard Contract expects you to confirm that your own processors have completed a DSPT or an equivalent. That second point catches cloud-hosted vendors who’ve never asked their sub-processors for anything beyond a SOC 2 report.

Business Continuity (A.5.29–A.5.30) → DSPT Continuity Planning

ICT readiness for business continuity, backup procedures, and tested recovery plans satisfy NDG standard 7. The DSPT wants proof that you tested the plan within the year and that the test dealt with losing access to patient data specifically. A generic tabletop on “office fire” won’t land as well as one on “ransomware locks the EHR integration for 72 hours.”

Where ISO 27001 Falls Short of DSPT Requirements

NHS-Specific Governance and SIRO/Caldicott Guardian Roles

The DSPT expects named accountability that ISO 27001 doesn’t ask for: a Senior Information Risk Owner (SIRO) at board level, a Caldicott Guardian if you handle confidential patient information, and a Data Protection Officer where UK GDPR requires one. Your ISMS “top management” clause won’t be accepted as a substitute. Appoint the roles, write them down, and show that the Caldicott Guardian has done the appropriate training.

National Data Opt-Out Compliance

The National Data Opt-Out lets patients block the use of their confidential patient information for anything beyond their own care, such as research and planning. Any vendor using NHS data for secondary purposes has to apply the opt-out and show how. ISO 27001 has no concept of it. If your product only supports direct care, document why the opt-out doesn’t apply. If it touches analytics, research datasets, or population health, you need a working process, and the NHS England national data opt-out guidance explains what compliance looks like.

Clinical Risk Management (DCB0129/DCB0160)

Software used in delivering care falls under DCB0129 (the manufacturer’s clinical risk management standard) and, on the NHS side, DCB0160 for the organization deploying it. Vendors have to appoint a Clinical Safety Officer, keep a hazard log, and produce a clinical safety case report. This usually surfaces through the DTAC rather than the DSPT itself, but assessors and procurement teams treat them as a package. The DCB0129 standard is a different discipline from information security, and it’s the most common blind spot for vendors coming from a pure ISO 27001 background. If your software also counts as a medical device, MHRA registration and UKCA or CE marking sit on top of all that.

Records Management Code of Practice

The NHS Records Management Code of Practice sets minimum retention periods for health records that are far longer and more specific than anything in a typical SaaS retention policy. The DSPT asks for a retention schedule aligned to the Code. Your A.5.33 records protection control gets you a policy. It doesn’t get you the right numbers.

Cyber Assessment Framework (CAF) Alignment in 2026/27

For Category 1 organizations the CAF-aligned Toolkit is fully in force and v9 maps to CAF v4.0. One point here matters a lot for vendors: CAF-aligned organizations no longer get any exemptions for holding Cyber Essentials Plus or ISO 27001. Both are still strong supporting evidence, especially for supply chain assurance, but they don’t auto-complete anything anymore. Category 2 and 3 vendors keep the exemption behavior for now. If NHS England pushes CAF alignment down the categories, the auto-completion benefit in this article goes with it, and the value of ISO 27001 shifts from “fewer questions” to “better answers.”

Worth Knowing: NCSC's Cyber Assessment Framework

The NCSC's Cyber Assessment Framework has four objectives (managing risk, protecting against attack, detecting events, minimizing impact). The NHS version adds a fifth, Objective E: using and sharing information appropriately, which holds the data protection and information governance outcomes. Objective E is where ISO 27001-certified organizations score worst on their first assessment, because it's the part with no ISMS equivalent. The NCSC CAF collection is the primary source for objectives A to D.

Evidence You Can Reuse Directly

Risk Assessments and Statement of Applicability

Your risk assessment methodology, risk register, risk treatment plan, and SoA are the backbone of the submission. The SoA is what an assessor uses to understand which controls you claim, and cross-referencing it to DSPT assertions is Step 2 of the workflow below. Make sure the version you present is the one your certification body signed off on, not a working copy.

Information Security Policies and Procedures

Every approved ISMS policy is reusable. Upload the approved PDF with the approval date visible, not the editable source. Assessors have learned to check version-control metadata.

Training Records and Awareness Programmes

Your LMS exports, attendance logs, and phishing simulation results satisfy the training assertion, provided the content covers confidentiality of patient data. If it doesn’t, add a short NHS-specific module rather than rebuilding the whole programme.

Internal Audit Reports and Management Reviews

Clause 9.2 internal audit reports and Clause 9.3 management review minutes are strong evidence for the DSPT’s process review and leadership assertions. They show controls being checked rather than just documented, which is what the outcome-based direction of the Toolkit rewards.

Supplier Due Diligence Documentation

Supplier assessments, security questionnaires you’ve sent out, and signed data processing agreements transfer directly once you’ve tagged which suppliers touch health and care data.

Penetration Test Results and Vulnerability Scans

A penetration test of your NHS-facing applications and infrastructure from the last 12 months, with a remediation tracker, satisfies the relevant technical assertions. For Category 2 vendors the mandatory audit expects an annual test from an independent provider. Vulnerability scan reports showing critical and high findings patched inside your defined SLA back up the patching assertion.

Pro Tip: Build your Evidence Library

Build your evidence library with a tag per framework, not a folder per framework. One access review record tagged "ISO A.5.18", "DSPT 4.2.4", "SOC 2 CC6.3", and "DTAC C2" gets uploaded once and reused four times. A folder structure copied per framework drifts within a quarter, and it's the usual reason a vendor ends up submitting last year's policy to this year's Toolkit.

Evidence That Needs Adaptation for DSPT

Reframing Data Flows Around Patient Data

Your ISMS data flow diagrams are almost certainly organized around systems. The DSPT wants them organized around personal confidential data: where it comes in, who can see it, where it goes, and on what lawful basis. Redraw the flows with patient data as the subject, add the lawful basis for each one, and you’ve got most of an Information Asset and Flows Register. NHS England publishes a template for that.

Adjusting Retention Schedules to NHS Standards

Take your existing retention schedule and add a column mapping each record type to the Records Management Code of Practice. Where your period is shorter than the Code’s, the Code wins for NHS records. Where it’s longer, write down why.

Documenting NHS-Specific Data Sharing Agreements

The DSPT expects a register of Data Sharing Agreements (DSAs) and data processing agreements with each NHS customer, plus evidence they’ve been reviewed. Most vendors have the contracts. Few have the register. Build it before the assessor asks.

Aligning Incident Response with NHS Reporting Channels

Add the DSPT incident reporting tool, the relevant ICB or trust contacts, and the 72-hour UK GDPR notification window to your incident runbook. Then run one tabletop where the scenario is an NHS data breach, so the log shows the route has been exercised.

A Practical Workflow for ISO 27001-Certified Vendors

Common Pitfalls When Reusing ISO 27001 Evidence

Assuming Certification Equals DSPT “Standards Met”

It doesn’t, and the NHS guidance says plainly that certified organizations get no exemption from completing the Toolkit. The certificate cuts the work down. It doesn’t take it away.

Overlooking Sub-Processor and Cloud Hosting Requirements

Your cloud provider’s certifications are evidence of their controls, not yours. The DSPT wants your configuration, your access model, and your assurance over the sub-processors who see NHS data. A vendor that can’t list which sub-processors touch patient data won’t reach Standards Met, however good the hyperscaler’s SOC 2 report is.

Missing the CAF-Aligned Profile Changes

If you are, or expect to become, a Category 1 organization (a designated Operator of Essential Services, say), the ISO 27001 exemption no longer applies, and your assessment is outcome-scored. Plan for evidence that shows controls working over time, not just existing.

Underestimating Clinical Safety Documentation

Assessors and procurement teams increasingly ask for the DCB0129 safety case alongside DSPT status. Vendors who turn up with an immaculate ISMS and no hazard log lose weeks at the point of contract.

Important: The most common failure we see in ISO 27001-certified vendors approaching the DSPT is scope mismatch, not missing controls. The ISO certificate covers the production platform. NHS data also sits in the customer support ticketing tool, the sales team’s demo environment, and a data scientist’s notebook. None of those are in the certified scope, so the Toolkit’s auto-completion doesn’t apply, and the assessor’s first question is “how are those controlled?” Extend the ISMS scope before you submit, or be ready to evidence those environments on their own.

Tooling and Automation to Streamline the Mapping

A GRC platform with multi-framework control mapping makes the tagging approach above practical: one control, one piece of evidence, mapped to ISO 27001, DSPT, DTAC, Cyber Essentials Plus, and SOC 2 at the same time, with evidence pulled automatically from your cloud, identity provider, and endpoint tooling for the technical assertions. It won’t write your Caldicott Guardian appointment letter or your clinical safety case. The platform handles collection and monitoring. The NHS-specific governance still needs a human who knows what an assessor is looking for.

Axipro’s ISO 27001 certification and NHS services are built around that combination: platform-native evidence collection with a delivery team that has mapped ISMS controls across ISO 27701, ISO 27017, and the other frameworks NHS procurement tends to ask for. If you’re coming to ISO 27001 for the first time with the DSPT already on the horizon, the scope decision above is the conversation to have with an ISO 27001 consultant before the ISMS gets designed, not after the certificate is issued.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

Conclusion: Turning ISO 27001 Into a DSPT Accelerator

A full-scope ISO 27001 certificate auto-completes the applicable DSPT evidence items for Category 2 and 3 vendors, narrows the independent audit, and supplies most of the security evidence the Toolkit wants. It doesn’t cover the SIRO and Caldicott roles, the national data opt-out, clinical risk management, NHS retention periods, or NHS incident reporting routes, and for CAF-aligned Category 1 organizations the exemptions are already gone. Confirm your category, extend your ISMS scope to every environment that touches patient data, tag your evidence once against every framework, and clear the NHS-specific gaps in a planned four to six week block. Do it that way and the DSPT stops being an annual scramble and turns into a by-product of the ISMS you’re already paying to maintain.

Frequently Asked Questions

Does ISO 27001 certification automatically satisfy the NHS DSPT?

No. Certified organizations still have to complete the DSPT. For Category 2 and 3 vendors, a certificate whose scope covers all health and care data processing marks the applicable evidence items complete and reduces independent audit scope, but the NHS-specific governance and information governance items still need answering. Category 1 organizations on the CAF-aligned Toolkit get no exemptions at all.

With a full-scope certificate, roughly 60 to 75 percent of mandatory evidence items for a Category 2 or 3 vendor can come from existing ISMS artifacts. The rest concern SIRO and Caldicott Guardian roles, the national data opt-out, records retention, data sharing agreements, and NHS incident reporting. A certificate scoped only to an IT department or a single platform covers a lot less.

Yes, if you’re a separate legal entity with your own ICO registration. NHS England’s guidance is that each such entity completes its own Toolkit. You can use a parent company’s ISO 27001 certificate as evidence only if its scope explicitly includes your entity’s health and care data processing.

DSPT v9, published on 4 September 2026, aligns the Category 1 view to CAF v4.0 and closes on 30 June 2027. For Category 1 organizations, ISO 27001 and Cyber Essentials Plus no longer auto-complete anything and assessment is outcome-scored. Category 2 and 3 vendors stay on the assertion-and-evidence model with the exemption behavior intact this cycle, but should treat CAF alignment as where things are heading and start building outcome-style evidence now.

Yes. ISO 27701 extends the ISMS into a Privacy Information Management System and adds controls for lawful basis, data subject rights, transparency, and processor obligations. Those map onto the DSPT’s information governance items and the CAF-aligned Objective E far better than ISO 27001 alone. It still doesn’t cover the Caldicott Guardian role, the national data opt-out, or NHS retention periods, so the NHS-specific gap list gets shorter but doesn’t disappear.

At least once a year, in September, when NHS England publishes the new Toolkit version and its change log. Re-run the mapping whenever your ISMS scope changes, whenever you onboard an NHS customer with a different data flow, and after each ISO 27001 surveillance audit so any new nonconformities show up in the DSPT evidence before you submit.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

Vanta can tell you a control is failing within the hour. It cannot rewrite your access review process, decide which systems belong in audit scope, or explain to a CPA why a test that shows red is actually fine. That work falls to people, and choosing the right ones is the difference between a 6-week path to audit readiness and a 6-month slog that ends with your Vanta subscription renewing before you have a report. This guide ranks the 7 best Vanta deployment services for 2026, explains what each one is good at, and covers what most comparison pages skip: how long this really takes, what it costs, and how to spot a partner who’ll hand you a half-configured platform and disappear. What Is a Vanta Deployment Service? A Vanta deployment service is a hands-on engagement where a specialist firm sets up, configures, and operationalizes Vanta so your company reaches audit readiness for one or more compliance frameworks. Vanta itself is a compliance automation and trust management platform: it connects to your cloud, identity provider, code repositories, HR system, and endpoints, then runs automated tests and maps the evidence to frameworks such as SOC 2, ISO 27001, HIPAA, and GDPR. The platform automates evidence collection and continuous monitoring. It doesn’t put controls in place for you. A deployment partner handles the judgment work around the tool: scoping, gap analysis, control mapping, policy writing, risk assessment, remediation of failing tests, and coordination with the audit firm. The best partners also stay on after the audit, because a Vanta instance nobody owns degrades fast. Worth Knowing: Vanta is a software vendor, not an auditor. Vanta is a software vendor, not an auditor. Your SOC 2 report still comes from a licensed CPA firm under AICPA attestation standards, and your ISO 27001 certificate comes from an accredited certification body. A deployment partner sits between the platform and the auditor. 1. Axipro Best for: SaaS and technology companies that want Vanta deployed, controls implemented, and the audit delivered by one accountable team, fast. Axipro is an authorized Vanta partner and a Drata Elite Partner, so its team works inside both leading compliance automation platforms every day. Founded in 2023, it has served 200+ clients from offices in the US, UK, and Bahrain, with a 100% audit success rate across 200+ certified clients. What puts Axipro first is scope. Most Vanta partners configure the platform and leave control implementation to you. Axipro’s Achievement Plan covers the whole path: kick-off and Vanta setup, gap analysis, a full policy and procedure suite, risk assessment and treatment, control implementation, vulnerability scanning, an internal audit, and external audit facilitation with an independent auditor. Clients get a dedicated infosec team over Slack, and the Achievement Plan comes with guaranteed certification. The other reason is speed. Axipro typically reaches SOC 2 readiness in around four weeks and ISO 27001 certification readiness in as little as six. It supports 20+ frameworks, including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, ISO 42001, and the EU AI Act, plus Gulf frameworks such as NCA ECC and SAMA CSF that most US-only partners cannot cover. Teams that want to test the relationship first can start with the free 30-day Compliance Accelerator Plan, which includes Vanta setup, gap analysis, and policy documentation, and continue into ongoing vCISO and continuous monitoring through the Trust Assurance Plan after certification. Watch for: Axipro is built for companies that want the work done for them. Teams that want a light-touch coaching engagement and plan to run the program in-house will use only part of what it offers. 2. Control and Function Best for: US SaaS companies of roughly 10 to 60 people that want SOC 2 and ISO 27001 run as one fixed-price project. Control and Function is a Denver-based consultancy built around fixed-scope, fixed-price readiness for small SaaS teams that have no compliance department. Its sweet spot is the dual-framework engagement: building SOC 2 and ISO 27001 from one shared control set rather than running two projects back to back. It also covers HIPAA for healthtech and maps ed-tech requirements such as FERPA and HECVAT. The firm is platform-neutral, so it works inside Vanta rather than reselling it, and it is explicit about handing off cleanly to an independent auditor. It’s also one of the few firms here that publishes prices, with readiness coaching starting around $8,000 and full readiness around $15,000. Watch for: The framework range is narrower than larger partners. Companies that need PCI DSS, CMMC, or international frameworks will need a second provider. 3. Neutral Partners Best for: Growing companies that need managed GRC across SOC 2, ISO 27001, CMMC, and FedRAMP without hiring an internal compliance team. Neutral Partners, based in Miami, runs a managed GRC model. It builds and documents the compliance program, tests it through internal audits, and then hands off to the relevant independent assessor: a CPA firm for SOC 2, a certification body for ISO 27001, or a C3PAO for CMMC. It never issues the certificate itself, which keeps the independence question simple. Its framework coverage leans toward regulated and government-adjacent work, including CMMC, FedRAMP, PCI DSS, HIPAA, and HITRUST. That makes it worth a look for defense suppliers and companies selling to the public sector. Watch for: Vanta isn’t its main focus. Ask for recent Vanta deployment examples in your framework before signing. 4. Kobalt.io Best for: Small and mid-sized businesses that want Vanta plus managed security operations. Canada-based Kobalt.io markets itself as one of Vanta’s leading global service partners. Its Vanta practice covers policy and control development inside the platform, custom control mapping where standard controls do not fit, and an applicability review of Vanta’s tests. The broader appeal is its managed security services, which suit companies that want compliance and security operations from the same provider. 5. AuditPeak Best for: Startups that want a readiness and audit-preparation partner focused narrowly on SOC 2. AuditPeak focuses on SOC 2 audit readiness for early-stage companies working in

Compliance software collects the evidence. A consultant builds the system that evidence is meant to prove. That’s the real difference in the ISO 27001 consultant vs software decision, and most teams only figure it out after they’ve bought one and realized they still need the other. Below, we compare what each route covers, where it breaks down, and what it costs you in time, money, and your team’s hours. Short version: software on its own works for a small group of companies. For most SaaS and tech scale-ups trying to get an enterprise deal over the line, consultant-led implementation on a compliance platform is the faster and safer path to a certificate. Quick Answer: Consultant, Software, or Both? Software-only works if you already have an in-house security lead who’s taken a company through ISO/IEC 27001 before and has the time to own the project. Consultant-only still makes sense if you run mostly on-premise or legacy systems that platforms barely integrate with. For everyone else, which means most cloud-native companies under a few hundred people, a hybrid works best: a platform to handle evidence and monitoring, and a consultant to build the management system and stand behind it in front of an auditor. Here’s why. What an ISO 27001 Consultant Handles ISO/IEC 27001:2022 is a management system standard. Clauses 4 to 10 cover how you run information security, and Annex A lists 93 controls you pick from based on risk. Almost none of it is box-ticking. Most of it comes down to judgment calls about your business, and that’s what you’re paying a consultant for. Scoping, Gap Analysis and Risk Assessment Scope is the first decision you make, and the most expensive one to get wrong. Go too wide and you’ll spend months on controls for systems no customer asks about. Go too narrow and the certificate won’t get through the procurement review it was supposed to pass. A consultant scopes around the deals you’re trying to close, runs a gap analysis, and builds a risk assessment based on your real assets and threats. That’s the document auditors dig into hardest. ISMS Documentation and Policy Writing The standard asks for a specific set of documents: the ISMS scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, risk treatment plan, and evidence of competence, monitoring, internal audit, and management review. A consultant writes these around how your company works day to day, instead of how a template imagines it works. Auditors check whether you follow your own procedures, so a mismatch shows up fast. Internal Audit and Certification Audit Support You need an internal audit before certification, and Clause 9.2 says the auditor has to be objective and impartial. In a small company, the people who built the ISMS can’t credibly audit it, so most teams outsource it through ISO 27001 internal audit services. A good consultant also gets your team ready for the Stage 1 and Stage 2 audits, joins the conversations that matter, and handles corrective actions if the auditor raises nonconformities.  What ISO 27001 Compliance Software Handles Compliance automation platforms, often called GRC platforms, have changed how cloud-native companies get certified. They’re very good at the repetitive, evidence-heavy side of the work. Automated Evidence Collection and Continuous Control Monitoring The platform plugs into your cloud provider, identity provider, code repos, HR system, and device management tools, then pulls evidence on its own. It’ll flag an unencrypted storage bucket, an ex-employee who still has access, or a laptop without disk encryption. For technical controls, that saves weeks of screenshots and spreadsheet tracking. Policy Templates and Annex A Control Mapping Most platforms come with a policy library and map each control to the ISO 27001 clauses and Annex A. You get a starting point and a clear view of which controls have evidence and which don’t. Auditor Access and Ongoing Compliance Tracking Auditors can log in and review evidence themselves, which cuts down fieldwork. After you’re certified, dashboards show when controls slip between surveillance audits, so you aren’t rebuilding evidence from scratch every year. Where Each Approach Falls Short Neither route covers everything by itself. The good news is that the ways each one fails are predictable, so you can plan around them. Limits of Compliance Automation Platforms A platform can tell you a control is failing. It can’t decide your scope, run your risk assessment, write a policy that matches your operations, convince your CTO to change the offboarding process, or explain to an auditor why you excluded a control from your Statement of Applicability. Templates can also make you feel further along than you are. A dashboard at 90% can hide an ISMS that won’t survive Stage 1, because the missing 10% is the management system itself. Insider Note: The Stage 1 problem we see most on software-only projects is a risk assessment copied straight from the platform’s default risk library. The risks are generic, the scores are almost identical, and nothing ties back to the company’s own assets. Auditors notice within minutes, and it weakens the Statement of Applicability that’s built on it. The other problem is ownership. Software assumes someone inside the company will drive the project. At most startups that’s a CTO or ops lead who already has a full-time job, and the subscription renews whether the work gets done or not. Limits of a Consultant-Only Approach A consultant working without automation spends billable days on things a platform does for free, like chasing screenshots, updating evidence trackers, and collecting the same proof again before every surveillance audit. You pay more and wait longer. You also end up with a program that’s only accurate on the day it’s handed over. Once the engagement ends, the evidence goes stale and year-two surveillance turns into a scramble. ISO 27001 Consultant vs Software: Side-by-Side Comparison Factor Consultant only Software only Hybrid (consultant + platform) Time to audit readiness 3 to 6+ months Highly variable; depends on internal expertise As little as 6 weeks for well-scoped

Uzbekistan regulates artificial intelligence through two documents. The first is Law ZRU-1115, signed on 21 January 2026. It amends existing legislation to define AI, stops anyone from basing decisions about people’s rights on AI output alone, and fines companies that process personal data unlawfully with AI. The second is the set of Ethical Rules approved by Order No. 3787, in force since 17 June 2026, which spell out what developers, implementers, and users actually have to do. Uzbekistan hasn’t passed a standalone AI act, and its rules don’t sort systems into risk tiers or require conformity assessments. The framework is short and blunt, and it’s already enforceable. Below we walk through what each document requires, who it applies to, how it stacks up against the EU AI Act, and what a company using AI in Uzbekistan should do next. Uzbekistan AI Regulation at a Glance (TL;DR) Instrument Date What it does Who it binds Law ZRU-1115 Signed 21 January 2026 Defines AI in law, sets general rules for AI-built information resources and systems, bans legally significant decisions based only on AI, adds fines for unlawful AI processing of personal data State bodies, organizations, website owners, anyone processing personal data with AI Order No. 3787 (Ethical Rules) Registered 14 March 2026, in force 17 June 2026 Sets eight mandatory ethical principles and lists rights and obligations for developers, implementers, and users Individuals and companies developing, implementing, or using AI in Uzbekistan Law No. 1125 (Personal Data amendments) Adopted 26 March 2026 Limits data localization to biometric, genetic, and local telecom user data, and allows cross-border transfers under conditions Personal data operators, including AI providers AI Strategy until 2030 (RP-358) 14 October 2024 Sets national targets for AI adoption, infrastructure, and skills Government bodies What Is Law ZRU-1115? The law’s official title is a mouthful: “On making additions and changes to certain legislative acts of the Republic of Uzbekistan in connection with the regulation of relations arising from the use of artificial intelligence.” Put simply, it’s an amending law. Instead of creating a new AI code, it writes AI into laws that were already on the books. When It Was Signed and When It Took Effect The Legislative Chamber of the Oliy Majlis adopted the bill on 12 August 2025, and the Senate approved it on 1 November 2025. President Shavkat Mirziyoyev signed it on 21 January 2026. You can read the official text in Lex.uz, Uzbekistan’s national legislation database. The law set out the principles and the penalties. The day-to-day detail arrived later with the Ethical Rules, which came into force on 17 June 2026. For compliance planning, treat mid-June 2026 as the point when the whole framework started applying. Why Uzbekistan Amended Existing Laws Instead of Passing a Standalone AI Act Uzbekistan wants more AI, not less. Its national strategy sets numeric targets for adoption, investment, and local computing capacity, and a heavy EU-style act would have worked against them. So lawmakers kept it light. They defined AI, drew two hard lines (human control over decisions that affect people’s rights, and protection of personal data), and left the Ministry of Digital Technologies to fill in the rest through secondary rules. Businesses get less legal certainty, and the government gets to move faster. Which Laws ZRU-1115 Changes For businesses, two amendments matter most. The Law “On Informatization” (ZRU-560-II, 2003) now contains a legal definition of AI, a new article on using AI in information resources and systems, duties for website owners, and updated powers for the ministry in charge. The Code on Administrative Liability now includes an offense for processing and spreading personal data unlawfully using AI. The Legal Definition of Artificial Intelligence in Uzbekistan Under the amended Law “On Informatization,” AI is a set of technological solutions that imitate human cognitive functions, including learning on their own and solving problems, and that produce results on specific tasks comparable to what a person could do. That’s deliberately broad. It covers generative AI, machine learning classifiers, recommendation engines, and most agentic systems. The Ethical Rules add a narrower term, the AI system: software built on AI that can find, collect, store, analyze, process, evaluate, and use data, and make decisions on its own based on that data. If your product makes a decision from data, or shapes one, assume it counts. Key Rules Introduced by Law ZRU-1115 General Principles for Using AI in Information Systems and Resources The new article in the Law “On Informatization” starts from harm. Information resources created with AI, and information systems running on AI, must not harm people’s life, health, freedom, honor, or dignity, or violate their other inalienable rights. The standard is short and open-ended. It gives regulators something to enforce against without saying in advance what counts as harm. Principle-based rules like this deserve to be taken seriously precisely because the edges are undefined. Human Oversight: No Decisions on Rights and Freedoms Based Solely on AI Most coverage leads with this provision, and it’s easy to see why. When someone makes a legally significant decision that affects human rights and freedoms, they can’t rely only on conclusions produced by AI systems or AI-built information resources. AI can feed into the decision, but a person has to make it. That applies to loan denials, benefit eligibility, hiring rejections, licensing outcomes, and disciplinary action. In each case, someone needs to look at the AI output and own the final call. Insider Note: In AI governance engagements, teams rarely struggle to show that a review step exists. What they struggle to show is that the reviewer could disagree, and sometimes did. If a human clicks “approve” on every AI recommendation and nobody ever records an override, auditors will see automation with a signature on top. Build the override path and log when people use it, starting on day one. Powers of the Authorized State Body (Ministry of Digital Technologies) ZRU-1115 makes the Ministry of Digital Technologies the authorized state body for AI. Among its new jobs, it’s