ISO 27001 & HDS consulting · Led by a certification auditor

Get ISO 27001 or HDS certified, prepared from the auditor's side of the table.

We help startups, scale-ups and digital health companies worldwide go from gap analysis to certification audit. Led by a certification auditor, we know exactly what your auditor will check.

ISO 27001 Lead AuditorISO 27001 & HDS certification auditor
Your path to certification
01
Gap analysisWhere you stand, what's missing, how long it takes.
02
ISMS implementationRisks, SoA, policies, evidence. Sized for your company.
03
Internal audit and management reviewGaps found before the auditor arrives, not during.
04
Certification auditStage 1 and stage 2, with us by your side.
40+ISO 27001 internal audits delivered
Across
FinTechHealthTechAIHR servicesMarketplaces
Partners who trust us with their clients' audits
The trigger

When a customer requires ISO 27001 or HDS, time becomes your biggest risk.

An enterprise deal is on hold

The tender or contract requires a certification you don't have yet. You need a credible, dated plan.

Security questionnaires keep piling up

Every prospect sends 200 questions. An ISO 27001 certificate answers most of them in one line.

You host health data in France

If you store personal health data for French healthcare providers or health software vendors, HDS certification is a legal requirement, not a nice-to-have.

Both sides of the table
As your consultant

Gap analysis, risk assessment, Statement of Applicability, policies, evidence and internal audit, built with your team.

As a certification auditor

Stage 1 and stage 2 ISO 27001 and HDS audits for an accredited certification body, always on other organisations' management systems.

Same standard, same questions. Your team hears them first.
The auditor's advantage

Your consultant is also a certification auditor.

Cyberbits Consulting is led by an ISO 27001 certification auditor who audits for an accredited certification body. Every month we see what makes an audit fail, and what makes it pass without surprises. That experience goes straight into your project.

No paperwork for its own sake. Only what the standard requires and what the auditor will actually read.
Nonconformities caught before the audit. Not on the day, in front of the auditor.
An ISMS sized for a startup. Not a corporate system nobody will keep alive.
Method

A dated plan from the very first call

1

Scoping call

30 minutes, free. Your context, your deadline, a realistic scope.

2

Gap analysis

A clause-by-clause, control-by-control assessment with a costed plan.

3

Build

Weekly check-ins, ready-to-use deliverables, and your team stays in ownership.

4

Certification

Internal audit, management review, then support during the certification body's audit.

Clients

Companies we've helped

ISKernel
HealthTech · 10 to 15 people

ISO 27001 and HDS certification

Built their information security management system and the HDS requirements from scratch, then supported them through to the certification audit.

Result: certified ISO 27001 and HDS.

Randstad France
HR services · 150+ people in ISMS scope

ISO 27001 certification

ISO 27001 consulting from implementation through to the certification audit.

Result: certified ISO 27001.

Back Market
Marketplace · 90+ people in ISMS scope

ISO 27001 audit readiness

ISO 27001 consulting and preparation of the management system and teams for the certification audit.

Focus: certification audit readiness.

“He supported us throughout our ISO 27001 implementation, from prioritizing clauses and controls to shaping our documentation approach and preparing for the external audit. What stood out beyond his technical expertise was his style: responsive, genuinely supportive, and always available when we needed guidance.”
Kevin KonrathCo-Founder, Basqo
FAQ

What people ask on the first call

How long does certification take?

It depends on your starting point, your scope and how much time your team can give. The gap analysis gives you a realistic, dated plan in the first week.

How much does it cost?

Pricing is on request. We quote a fixed fee once we understand your scope, usually after the free call or the gap analysis, so there are no surprises.

Can you also run our certification audit?

No, and that protects you: impartiality rules forbid certifying a system you helped build. We prepare you, an independent body certifies you.

ISO 27001 and HDS: do we need two projects?

No. HDS certification builds on ISO 27001, so we build one management system and add the health-data hosting requirements on top.

Do you work remotely?

Yes. The whole engagement can run remotely, in English or French, wherever you are.

Let's talk about your certification deadline.

30 minutes, free, no commitment. You leave with a timeline and scope estimate.

  • Your context, your deadline, a realistic scope
  • ISO 27001, HDS or both: what applies to you
  • In English or French, by video call
Prefer email? info@cyberbitsconsulting.com Calendar not loading? Open the booking page
Cyberbits Consulting
ISO 27001 and HDS certification, internal audit