New: ISO 42001 and NIS2 Supply Chain are available in the Compliance Tool.Explore standards and requirements →Careers
ICT & SaaS

Compliance for ICT and SaaS that fits your product.

A security questionnaire from a new customer, a planned audit or a growing number of cloud suppliers: connect the evidence requested to what your team actually does.

When is a focused approach needed?

At ICT service providers and SaaS companies, commercial questions, product development and information security can all fall to the same team at once. Common triggers include:

  • A customer wants evidence: sales receives a security questionnaire and needs answers about access, hosting, incidents or recovery. The team must establish which answers are accurate for the service offered.
  • Certification is being considered: a client asks for ISO 27001, but it is not yet clear which products, locations, people and outsourced services fall within the scope.
  • The service is changing: new releases, suppliers or access to customer environments mean existing arrangements are incomplete. Someone needs to connect those changes to risks and controls.

Bring the actual customer request, contractual requirement or audit finding. This helps us determine whether the main need is software, temporary implementation support or ongoing operational support.

Which questions does DCA help you address?

The core is a verifiable connection between your service, the arrangements governing it and evidence from implementation. Together, we can address questions such as:

  • What belongs within the scope? Distinguish between your own product, the underlying cloud environment, customer configurations and management activities performed by another party.
  • Who can substantiate an answer? Link customer questions to process owners and current documentation. Record which evidence may be shared and who checks the content.
  • How does the evidence file stay current? Assign an owner and review point to changes in access, suppliers, the product and incident handling.

The Compliance Tool can bring requirements, risks, tasks and evidence together. It does not replace technical implementation or confirmation of the facts by your product, IT and management teams.

What does the approach involve?

  1. Establish the objective and scope. Discuss which service, customer request or standard is central. Take stock of existing documentation, responsibilities and dependencies.
  2. Identify gaps and priorities. Compare the evidence requested with current practice. Distinguish between missing arrangements, missing implementation and missing evidence.
  3. Allocate and carry out the work. For each action, agree what DCA develops and what your team implements. Link evidence to the relevant control and agree who reviews changes.
  4. Check and maintain. Discuss open actions and management decisions. Where needed, prepare an internal audit or assessment and plan ongoing maintenance after the initial assessment.

Illustrative example: when asked about offboarding, HR can confirm the end of employment, IT can record the removal of access and a designated owner can carry out the check. DCA helps structure the arrangements and evidence. This is a working example, not a measured customer outcome.

What remains your team’s responsibility?

We agree the level of support in advance. In a self-managed project, you use the software and carry out the work. In a supported project, DCA can take on analysis, documentation, planning and agreed implementation activities.

  • Leadership: defines the scope, allocates resources and decides on risks, priorities and investment.
  • Product, engineering and IT: provide factual system knowledge, implement technical controls and confirm that documentation reflects production practice.
  • Sales and contract owners: record commitments made to customers and have security responses checked for accuracy.
  • DCA: provides structure, helps develop requirements and risk assessments, and monitors agreed actions. The allocation of responsibilities and any audit support are recorded explicitly.

Software and support do not themselves constitute a certificate. In a certification process, an independent certification body decides the outcome.

What relevant experience is available?

The existing Chief customer story describes how an IT company used workflows, templates and centralised evidence to organise its own ISO 27001 project. The story explains the combination of software, structure and targeted support.

This illustrates one way of working together, not a fixed outcome for every SaaS company. Your scope, existing knowledge and available resources determine the support that fits. In a discussion, we can compare the approach with your own product and customer requirements.

Which standards and information are relevant?

ISO 27001 provides a framework for the information security management system. The official ISO explanation describes the risk-based approach and its application to organisations of different sizes. Also read the ISO 27001 roadmap and the practical checklist for evidence and audit preparation.

Does a client ask about NIS2 Supply Chain? First record which level, scope and assessment they mean. The private scheme and legal obligations must be assessed separately.

If you work for healthcare organisations, include their specific information security and privacy arrangements. The NEN 7510 page helps distinguish the healthcare context from the questions suppliers need to address.

Which next step fits your needs?

Explore the prices and support options for the cost breakdown. Internal work, technical improvements and any external certification require their own budget.