The audit is one day. The maintenance is 365. Here’s what startups get wrong after their ISO 27001 certification, and how to fix it.

When we founded Yonder, a B2B SaaS company, we focused on winning enterprise contracts from early on. We succeeded for the first time in 2020, winning a few deals with some larger airlines in Europe.

Our customers requested proof of ISO 27001 certification within six months. We had no QMS. No ISMS. No process documentation to speak of. What we had was a product, a team of twelve, and a very full roadmap.

What options did we have? We can either spend 10–20k EUR on certification consultants, or we can handle the certification ourselves without external help.

That’s what we did. We got our company ISO 9001 certified in 2020, ISO 27001 certified in 2021, and migrated to ISO 27001:2022 during our 2024 recertification audit — without the help of any consultants.

I have written about the certification journey before. But the aspect almost nobody writes about is what happens after the auditor leaves. Let’s look at some challenges every startup and SME faces when they need to maintain their ISO 9001/27001 certification.

Challenge 1: Audit is one day per year, maintenance is all year round

Your auditor visits once a year for a maintenance audit. The auditor doesn’t just check whether your QMS and ISMS documentation exists, but whether it is alive: Has it changed since the last visit? Do your employees know what is in it? Can you prove that the processes documented match the processes actually followed?

Three years after the certification audit, the recertification audit comes due. If you have spent three years keeping your documentation just barely alive, your auditor will notice. But what does “keeping the QMS and ISMS alive” mean in practice? It means four things:

Update your documentation whenever things change. No matter if your team switches expense tools, your cloud provider changes their logging tool, or your remote working policy needs an update for a new customer in a new country, all of those changes need to be reflected in your QMS and ISMS — reviewed by the process owner, approved, and communicated to the relevant people.

Track and close non-conformities. Every audit produces findings. They need to be tracked, assigned to someone, and closed before the next audit. An open finding from two years ago makes you look like a beginner in a recertification audit.

Run internal audits. ISO 27001 requires you to run internal audits. You don’t run them to please your auditor in a recertification audit, but to see for yourself what works well within your team, and where you need to sharpen the processes and their communication.

Keep your risk and asset inventories up to date. Your risk landscape changes. You add new software components. Contracts expire. New employees join, and old ones leave. If you haven’t reviewed your risk and asset inventories for 18 months, they are worthless.

Challenge 2: Avoiding “Ghost Policies”

You have a beautifully written access control policy. It explains who can grant access to which systems, under what conditions, and how access is reviewed and revoked. You wrote it before the certification audit. The auditor approved it.

In the first maintenance audit, the auditor walks up to a developer on your team and asks: “Where can I find your access control policy, and what does it say?”

The developer has never read it. He might not even know it exists.

This is what I call a ghost policy: A document that satisfies the auditor on paper but has no connection to how people actually work. Ghost policies are not a sign of bad intentions. They are the natural result of building documentation for the audit rather than for the team.

The fix is less complicated than it sounds. The documentation has to reach the people it applies to, at the time it is updated, with proper change notifications.

Challenge 3: Startup teams have other priorities

In a twelve-person startup, the developer who needs to read your access control policy update is also fixing a production bug, preparing a demo for a prospect, and reviewing a merge request for another team member. The email about a changed internal policy gets buried under the daily grind activities.

The companies that maintain their ISO certifications well have two things in common. First, they made someone responsible: a Quality Manager, a CISO, or a founder who dedicates a few hours each month to keeping the documentation current and the open findings list short. Second, they use tools that surface compliance tasks in a way that the team can act on them quickly, and the Quality Manager or the CISO knows immediately who still has open compliance tasks.

Neither of those things requires a large compliance team or an expensive GRC platform. They require a deliberate decision about ownership and tooling, made once, before the certification audit.

Conclusion

I think it’s fair to say that no consultant and no auditor will honestly tell you about those post-certification challenges. You can avoid them by following a pragmatic, step-by-step process:

Get ISO 9001 certified before ISO 27001. This sounds counterintuitive if your customer is asking for ISO 27001. But the discipline of building a well-structured QMS — clear processes, controlled documentation, a working change request workflow — makes the ISMS significantly easier to build and maintain. The tooling, the habits, and the ownership model carry over.

Build the risk and asset inventories in JIRA from day one. Static spreadsheets become outdated the moment you close the file. Dynamic JIRA-based inventories let you assign ownership, set due dates, and track status without any additional tools. The auditor can see live progress rather than a snapshot.

Documentation should serve the team, not the auditor. If your team reads the process documentation only when the auditor visits, it is not serving its purpose. Good documentation is short, linked, searchable, and updated when things change. The auditor is a useful deadline, not the primary audience.

Interested in following my ISO 9001/27001 certification approach in your organization? I have written up the full approach and my 5+ years of experience in maintaining an ISO 9001/27001 certification in an eBook available on Gumroad — now in its 3rd edition!