A deal stalled until you could prove ISO 27001. An RFP asked for a certificate you don’t have. A letter arrived mentioning NIS2, and somehow you’re the person who has to deal with it.
If any of that sounds familiar, you’re in the right place. You’re not the first person to arrive here holding a job nobody quite handed you on purpose.
This is a community for people getting compliance done at smaller organisations, usually without a dedicated security team. You ask real questions, you see how other people actually did it, and you get an answer you can trust.
What you’ll find here
- A plain-English answer to “what does this even take?” Before you commit budget or call a consultant. Certification isn’t a mystery, and you can make a go/no-go decision without spending a cent first.
- Real examples, not just the standard. See how someone else implemented the control you’re stuck on, so you’re not reinventing it or over-engineering it from a blank page.
- A place to ask the obvious question without it costing you credibility. Beginner questions are welcome. Asking early is how you avoid stalling later.
What it actually takes (the short version)
Certification is a project, not a purchase. At a high level: work out what’s in scope, put the controls that actually apply to you in place with the evidence to back them, then have an auditor check it in two stages. It takes months, not weeks. But it’s a known path, and most of the work is organising things you already half-do.
If NIS2 is what brought you here, the good news is the two overlap heavily. Much of an ISO 27001 build maps straight onto what NIS2 asks for.
Your first step
Ask one question in the Q&A category. Tag it with your framework (iso27001 or nis2) and, if you’re just starting out, pre-certification. That’s it. You don’t need to have it all figured out first; that’s what the question is for.