TL;DR: ISO 27001 certifies your security process, not your code. For a lean SaaS team, plan three to six months from gap review to certificate. AI-built apps fail the prep on one thing above all: the evidence trail. The code works, but nobody wrote down who set each control and why. We get you ready for that audit. We do not certify — only an accredited body can. Start with a free scan of your live URL.
Big buyers ask for it because it answers one question: is your security a process, or a pile of lucky defaults? If you built your app with Lovable, Bolt, Cursor, or v0, the honest answer today is probably the second one. That is fixable. Prep is the fix. This guide shows what the standard covers, where AI-built code trips the audit, and what prep really takes.
What ISO 27001 covers
ISO 27001 is the global standard for an ISMS, short for information security management system. Plain words: it is proof that you run security on purpose, not by luck.
It does not certify a product, a codebase, or a feature. It certifies a process. How you find risks. How you pick controls. How you prove they run, month after month.
That shift matters for founders. You think in terms of the app. The standard thinks in terms of the company: who can reach what data, how that access gets reviewed, and what happens when someone leaves. If you prompted your way to a product, this may be the first time anyone asked you to write down a process instead of ship a feature. It is a different muscle.
The four Annex A themes
The 2022 update sorted the controls into 93 Annex A controls under four themes. The names are long. The ideas are not. Here is what each theme means for a small SaaS team:
| Theme | What it covers | Typical startup gap |
|---|---|---|
| Organizational | Policies, roles, vendors, incident response | No written incident plan; no named security owner |
| People | Vetting, training, remote work rules | No offboarding step that revokes access |
| Physical | Devices, clear desks, safe disposal | Low risk for remote teams, but still needs a written policy |
| Technological | Access control, encryption, logging, secure builds | Default database rules, no rate limits, no audit logs |
That last theme is where vibe-coded apps fall apart before the audit. AI builder defaults were never built with an auditor in mind.
Where AI-built code breaks the audit
An auditor does not just want a policy document. They want proof the control runs in the live app. For a hand-built app, that trail is usually clean. A developer set the access rules, tested them, and can say why. For a vibe-coded app, the trail is often missing.
The AI wrote a working login flow. It did not write a decision log. Nobody can say why Row Level Security is set the way it is, or whether a policy is owner-scoped or left open with USING (true). That missing paper trail is exactly what an assessor flags. Test your own tables now with the free RLS checker.
The scale of the problem is measured. Symbiotic Security scanned 1,072 AI-built apps. 98% had at least one flaw. 16% had critical issues. A CMU study found 61% of AI-written code had at least one flaw. Across 100 apps we scanned ourselves, the average Launch Readiness Score was 42/100. The code works. The proof does not.
What it costs and how long it takes
Be wary of flat quotes. The real cost depends on your team size, your auditor, and — more than anything — how much of the technical layer your AI builder skipped on day one.
The spend splits into three parts. The gap review and policy work. The fixes to your app. The audit body's fees. For a lean team with clean prep, the path from gap review to certificate runs about three to six months. If access control and logging need a rebuild first, add the rebuild time up front.
That is the case for doing the cheap technical pass first. Finding an open table yourself costs a scan. Having an assessor find it costs a failed audit round.
We prep. We do not certify.
This line matters, because many vendors blur it. Only an accredited body can issue an ISO 27001 certificate. We are not one. Anyone who offers to "certify" you in a week for a flat fee is not selling the real thing.
What we do is the prep. Our Compliance Wing runs 60 checks against your live URL — GDPR, the EU AI Act, SOC 2, and ISO 27001 — with no code access, in minutes:
- Free check — $0. A baseline score on your live URL.
- Compliance Score — $799 one time. The full 60-check pass, an AI policy review, template docs, and a report. The $799 is credited toward the DFY setup.
- DFY Compliance Setup — $2,999 one time. A CTO makes the fixes and gets your proof in order.
- Compliance Monitoring — $399 a month. Re-scans and drift alerts as your app changes.
The goal: walk into the real audit with your proof already in order, instead of digging for it while an assessor waits.
Security audit vs. ISO 27001: which comes first?
A security audit is a snapshot: what is broken right now. ISO 27001 is the wrapper around it: the policies, the risk list, and the review cycle that proves fixes stay fixed. You need the first before the second.
| Question | Answer |
|---|---|
| Does a security audit replace ISO 27001? | No. It is a snapshot of risk, not a proven process. |
| Do I need both? | If you sell to big buyers, yes. The audit fixes gaps; the standard proves you keep fixing them. |
| Which comes first? | The audit. Fixing code issues is far cheaper before an assessor finds them. |
Our Launch Readiness Audit is that first step: $499 one time, a branded report with every finding, a ranked fix plan, and how you stack up against 200+ audited apps. See a sample report first, or read how we score. Quick self-checks help too: run the security headers checker and the API rate limit checker on your app today.
Where GDPR and the EU AI Act overlap
Most founders ask about one framework and leave needing three. That is normal. GDPR, the EU AI Act, and ISO 27001 all rest on the same base: know what data you hold, know who can reach it, and prove it.
GDPR covers lawful basis, user rights, and retention — our GDPR guide for vibe-coded apps walks through it. The EU AI Act adds Article 50: from August 2, 2026, apps must tell users when an AI is talking to them, with fines up to €15 million or 3% of global turnover if you break it. Our EU AI Act guide covers who it hits. ISO 27001 sits under both. It is the system that makes the other two provable.
Your users' location, not your office, triggers most of these duties. A US founder with EU users still has GDPR and EU AI Act exposure.
FAQ
Is ISO 27001 worth it for a small startup?
Yes, if big buyers ask for it or deals stall on security forms. If you are pre-revenue and sell to consumers, not yet. Fix the basics first and get the certificate when a real deal depends on it.
How long does ISO 27001 take for a startup?
Plan for three to six months from gap review to certificate for a lean team. It takes longer if your AI-built code needs rework on access control and logging first. That rework is the biggest driver of both time and cost.
Can AI-built code pass an ISO 27001 audit?
It can, but rarely on the first try. The code may work, but the evidence trail is missing: no decision log, no access reviews, default database rules. Auditors ask who set each control and why. An AI never wrote that down.
Does Launch Ready Code certify ISO 27001?
No. Only an accredited body can issue an ISO 27001 certificate. We do the prep: we scan your live app, find the gaps, hand you the fix list and the template docs, and get your proof ready for the real audit.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is a global standard with a formal certificate from an accredited body. SOC 2 is a US-style report from a CPA firm. The controls overlap a lot, so many startups prep for both at once and reuse the same evidence.
Does GDPR compliance count toward ISO 27001?
Partly. GDPR and ISO 27001 share controls on data access, retention, and risk review. But GDPR is law and ISO 27001 is a choice with its own audit. Work on them together and you cover both faster.
ISO 27001 is not a badge for your homepage. It is proof your security runs on purpose. AI-built apps were never set up to show that proof — which is why prep, not the audit itself, is where the work lives. By the time the real auditor opens your app, you should already know where every gap was. Because you found them first.
See your gaps before an auditor does
Free scan of your live URL. No code access. No install. A Launch Readiness Score out of 100 and the list of gaps to fix.
Run the free scan — $0