How Scigeniq Passed Its First SOC 2 Type 2 and ISO 27001 Audits in Three Months

Certification

SOC 2 Type 2 | ISO 27001

Industry

Life Sciences Software | Quality and Regulatory Management

Engagement Length

3 Months

Location

United Arab Emirates

Product

SOC 2 Type 2, ISO 27001

Industry

Life sciences software, quality and regulatory management

Engagement Length

3 months

Location

United Arab Emirates

Outcome

SOC 2 Type 2 report issued covering Security, Availability and Confidentiality, plus ISO 27001 certification

At a Glance

  • Challenge: Scigeniq needed to satisfy two frameworks at once, starting with no audit evidence, with a team of fewer than 50 people.
  • Solution: Axipro scoped both frameworks together, ran the ISO 27001 internal audit, and took Scigeniq through SOC 2 Type 2 preparation and testing, with Vamu handling evidence collection and control monitoring.
  • Results: Both frameworks completed inside a three month engagement, with the SOC 2 report covering Security, Availability, and Confidentiality.

The Company

Scigeniq builds software for small and mid-sized pharmaceutical companies. The suite covers quality management, document control, regulatory management, electronic batch records, training, and asset management. The company is based in the UAE and sells to pharma manufacturers across the MENA region. Cooper Pharma, Global Pharma, and Belpharma are among the customers named on its site.

That’s why security assurance matters so much here. A manufacturer running its QMS and batch records on Scigeniq is handing a vendor the records it will have to produce when a regulator asks how a medicine was made.

Pharma companies audit their software vendors for exactly that reason. For a vendor selling into regulated manufacturers, an independent security report is part of the sales conversation.

01- THE CHALLENGE

Two Frameworks, No Audit History, Three Months

Scigeniq had no audit history to build on. There was no prior report, no evidence trail, and no feel yet for what an auditor asks once the questions get specific.

Two frameworks, two shapes of evidence

Two frameworks made that harder. ISO 27001 needs a working information security management system, documented and internally audited before certification is even on the table. SOC 2 asks for something else: a defined system boundary, a chosen set of Trust Services Criteria, and controls that can be shown to work over a period of time rather than on a single day.

The two overlap heavily but don’t ask for evidence in the same shape, so running them as separate projects would have meant doing most of the work twice.

A team under 50

Team size added to it. With 11 to 50 people, nobody at Scigeniq could work on compliance full time, and every hour spent gathering evidence came out of product work.

A three-month window

The timeline was tight as well. The engagement ran from May 1 to July 30, 2026, and a Type 2 needs an observation window in which controls are tested in action. Three months left no room for a slow start.

02- THE ENGAGEMENT

Two Frameworks, One Body of Work

 Two decisions that set the shape of the project

The first was Type 1 or Type 2. A Type 1 looks at control design at a single point in time, and it’s the easier first step, which is why a lot of first-time organizations take it. Scigeniq went for the Type 2 instead. It tests whether controls ran over a period; it’s the report enterprise customers ask for, and choosing it up front avoided a year of doing the work twice.

The second was scope. Scigeniq picked three Trust Services Criteria: Security, Availability, and Confidentiality. Security is mandatory in every SOC 2. Availability and Confidentiality match what a pharma customer worries about when its quality system lives in someone else’s cloud: whether the system will be there when an inspector asks for a record, and whether anyone outside can see what’s in it.

Processing Integrity and Privacy stayed out. Three criteria on a first audit meant the team could prove three things properly instead of half-proving five.

For ISO 27001, the equivalent question was where the management system’s boundary sat. Settling both boundaries in the same conversation let the control work underneath serve both frameworks.

  Building the management system

Scigeniq documented its controls, policies, and procedures against the criteria it had chosen. Vamu did the heavy lifting on the operational side. It held the control set, collected evidence, and kept watch on whether controls stayed in place after they were written.

For a small team, that’s the part that matters. Writing a policy is a one-off. Showing it ran across a full observation window is ongoing work, and it’s what sinks small teams that try to do a Type 2 by hand.

  The internal audit

Before an ISO 27001 management system can go for certification, the organization has to audit itself. Axipro ran that internal audit, checking implementation against the framework, testing whether controls and procedures worked in practice as well as on paper, and flagging nonconformities and areas for improvement.

Scigeniq came out of it with a detailed report of findings and recommendations. That’s the point of an internal audit. Gaps found in June cost far less than gaps found during certification.

  Testing, retesting, and the report

Control testing ran through the summer, with separate passes for Security, Availability, and Confidentiality. Evidence came from interviews, observation, and reviews of documentation and system configurations.

The team fixed and retested findings rather than logging them and moving on. Availability controls A1.1 through A1.3 and the Confidentiality series went through a second round, and a further batch of open items was cleared before the report was finalized.

The report is dated August 31, 2026, a month after the engagement closed. It covers both the design of Scigeniq’s controls and how they operated across the observation period.

03- THE RESULTS

Both Frameworks Inside Three Months

Scigeniq completed both frameworks within a three-month engagement.

SOC 2 Type 2: report issued, covering Security, Availability, and Confidentiality.

ISO 27001: internal audit completed, findings closed, certification achieved.

Timeline: May 1 to July 30, 2026, with the report dated August 31, 2026.

For a company this size, the second audit may turn out to be the more useful outcome. The control set now lives in Vamu with evidence collection running against it, so the next observation window starts from a working system rather than a blank page. The first report is the cheap part of a Type 2. Showing every year after that nothing has slipped is the expensive part.

Case Studies

Explore More Case Studies