For ISO 27001 consultants and virtual CISOs

Run every client's management system from one account

You know how the engagement goes. The system you build is sound on the day you hand it over, and eleven months later the client rings because the surveillance audit is in three weeks and nobody has touched the risk register since you left. StandardOS is the part of the job that keeps running after you do: one account, every client, each one's records kept apart, and the recurring work scheduled so the year does not go quiet.

A product, and now a partner programme

Referral partners earn 20% of every payment for twelve months per client they bring and, once the client accepts, are named inside that client's product as the officer to call. Resellers bill the client themselves at a 30% margin. No white label: the brand is the trust. The terms are on the partners page; bringing one client is still the way to start.

Partner programme

What changes about the engagement

Day one is a day, not a month

Seven questions about the client produce a draft scope, risk criteria, a starter risk register, a Statement of Applicability across all 93 Annex A controls with a justification on each, and the policy set. You spend the first meeting correcting drafts with the client rather than typing them, which is where your judgement is worth the fee.

Every client, one account, nothing mixed

You belong to each client's organization and switch between them from the sidebar. Every register, document and evidence entry is filtered to the organization on screen, enforced in the database rather than in the interface, so a screen never shows one client another client's risks. Your client's own people work in the same organization you do, with the roles you give them.

The year between your visits does not go quiet

Every control, risk, supplier, document and certificate carries a review date. Overdue items surface in one inbox and in a digest, to the client and to you. Evidence expires and says so. When the surveillance audit is three weeks out, the question is not what happened this year but which of the dated records to show first.

Evidence that collected itself

12 read-only integrations read the client's systems on a schedule: GitHub, Microsoft Entra ID, Okta, Google Workspace, Personio, Amazon Web Services, Microsoft Azure, Google Cloud, Snyk, Kandji, Jamf Pro, and Microsoft Intune. A passing check keeps an evidence entry fresh; a failing one lets it expire, so a regression shows up in the inbox rather than in the audit. No agent on anyone's laptop, ever, which is a conversation you no longer have to have with the client's engineers or works council. What each one reads.

Security questionnaires answered from the record

When a client's customer sends the forty-question spreadsheet, paste the questions in. Each answer is drafted from that client's own Statement of Applicability, approved policies, evidence and integration checks, and cites them by name and date, so the customer's security team can check it. Nothing is invented: a control still in progress is drafted as in progress, and a question the ISMS has nothing on says so. The client confirms each answer, and confirmed answers are reused on the next questionnaire. The question-to-control map, published.

An export the auditor can check without trusting anyone

Every record sits on an append-only, hash-chained audit log. The export is organised by Annex A reference, and the chain can be verified with a published script by the certification body, by the client, or by you. Your work is shown by records with dates on them, which is what an auditor samples and what a client remembers you for.

Price, plainly

€249/mo excl. VAT, flat per organization, every feature, unlimited people. Each client organization is its own subscription, paid by the client or by you, whichever your engagement prefers. Your own seat costs nothing extra in any of them: there are no seats. The 14-day trial needs no card, so a client can be set up and shown the system before anyone pays anything.

The certification audit is paid to the certification body, as it always was. The consulting is paid to you, as it always was. What the product replaces is the spreadsheet, the shared drive and the eleven-month silence, not either of those.

What it will not do for you

  • It will not decide scope, treat risks or sit in the audit

    Those are the judgement you are paid for. The product drafts and records; you decide.

  • It is not white-labelled

    Your client sees StandardOS, and sees you inside it as the person running their system. We think that is the honest arrangement and it is the only one on offer.

  • It covers ISO 27001, ISO 42001 and ISO 9001

    Not SOC 2, not TISAX, not the 75-framework catalogue. Clauses 4 to 10 are shared across the three, so a client running two of them keeps one set of records. The clause-by-clause coverage is published, gaps included.

Bring one client

Write to support@getstandardos.com with the client's size and where they are in the cycle, and we will set them up with you on a call. If you would rather look first, the trial is open and needs no card.