Certifications

Certified. Verified. Trusted.

We partner with GRSee's accredited ISO auditors to ensure your certification actually reduces risk — not just earns a badge. ISO 27001, ISO 42001, and SOC 2, guided from gap assessment to audit-ready.

Book a Free Assessment

Why certification matters

Win bigger deals, faster

Enterprise customers and partners increasingly require proof of certification before they'll sign. Certification removes that blocker from your sales cycle.

Prove protection, not promises

Independent audit confirms your controls actually work — turning "we take security seriously" into something you can show, not just say.

Reduce real risk

The process itself surfaces gaps most organizations don't know they have — before an attacker or an auditor finds them for you.

One framework, less duplicate work

ISO 27001, ISO 42001, and SOC 2 share significant control overlap — and that groundwork reuses directly for NIS2 and DORA compliance too.

Information Security

ISO 27001

Information security management, certified.

ISO/IEC 27001 is the internationally recognized standard for information security management systems (ISMS). It gives your organization a structured framework to identify risks, implement the right controls, and continuously improve how sensitive data is protected — not just on paper, but in practice.

Delivered in partnership with GRSee, accredited ISO auditors, Magic Stone guides you through the full path: gap assessment, control implementation, documentation, and audit-readiness — so certification becomes a natural extension of the security work you're already doing.

AI Governance

ISO 42001

Governance for organisations building with AI.

As AI adoption accelerates, so does the risk of ungoverned, "shadow" AI use inside organizations. ISO 42001 is the first international standard for AI management systems (AIMS) — giving you a framework to govern how AI is developed, deployed, and monitored responsibly.

We help you align AI usage with ISO 42001 alongside NIS2, GDPR, and the EU AI Act — delivered in partnership with GRSee, so innovation doesn't come at the cost of control or compliance.

Trust & Assurance

SOC 2

Independently audited controls you can prove.

SOC 2 demonstrates that your organization's controls around security, availability, and confidentiality hold up to independent scrutiny — increasingly a requirement from enterprise customers before they'll finalize a contract.

Delivered in partnership with GRSee, Magic Stone guides you through control mapping, readiness, and audit preparation, so SOC 2 becomes a competitive advantage instead of a bottleneck. Most enterprise buyers expect a Type II report — demonstrating your controls work over time, not just on paper at a single point.

What sets our certification support apart

Hands-on, not templated

Accredited auditors paired with working cybersecurity experts — so controls actually reduce risk, not just check a box.

One roadmap, all your frameworks

Overlap between ISO 27001, ISO 42001, SOC 2, NIS2, and DORA is mapped from day one — including how it connects to Supply Chain Risk Management, so you're never doing the same work twice.

Clear, staged process

Gap assessment, remediation, implementation, audit-readiness, certification — no ambiguity about what happens next.

Built for SMEs and enterprises alike

Whether this is your first certification or your fifth framework, the process scales to your size and maturity.

Support doesn't end at certification

We help you maintain compliance year-round — not just pass the audit once and disappear.

Proven with real organizations

Trusted by clients across the Benelux and Nordics for practical, no-nonsense compliance work.

Our process

01

Gap Assessment

We map your current security posture against the certification's requirements and identify exactly what's missing.

02

Remediation Planning

A clear, prioritized plan — technical and operational — to close the gaps we found.

03

Implementation

We work alongside your team to put the right controls, policies, and documentation in place.

04

Audit Readiness

Internal review and evidence collection, so there are no surprises when the real audit happens.

05

Certification & Beyond

We connect you with the right accredited auditor, then support you in maintaining compliance long after certification.

Your certification questions, answered

How long does certification take?

It depends on your organization's size and current maturity, but most certifications take anywhere from a few weeks to several months. We give you a realistic, tailored roadmap after the initial gap assessment.

Do I need an in-house compliance team?

No. Whether you're pursuing your first certification or managing multiple frameworks, our experts handle the heavy lifting — from gap analysis to audit prep — without requiring in-house expertise.

How much does ISO 27001 certification actually cost?

Costs vary by company size, scope, and current security maturity — there's no single flat number. The real cost drivers are the gap assessment and remediation work, internal staff time, and the external audit fee paid to an accredited certification body. The better question is usually cost versus benefit: certification work overlaps directly with NIS2 and DORA compliance you may already need, so the investment often covers more ground than the certificate alone. We start every engagement with a free assessment so you get a realistic, scoped estimate rather than a generic number.

What is ISO 42001 and do I actually need it?

ISO 42001 is the first international standard for AI management systems (AIMS) — a framework for governing how AI is developed, deployed, and monitored responsibly. Whether you need it depends on how your organisation builds or relies on AI: if you process personal or sensitive data through AI systems, or operate in a way that falls under EU AI Act obligations, ISO 42001 demonstrates due diligence to regulators, customers, and partners before it's demanded of you.

How is ISO 42001 different from ISO 27001?

ISO 27001 governs information security broadly — protecting the confidentiality, integrity, and availability of data across your organisation. ISO 42001 is narrower and specific to AI: it governs how AI systems are designed, trained, deployed, and monitored, covering risks unique to AI such as bias, transparency, and human oversight that ISO 27001 doesn't address. The two frameworks share a similar governance structure, which is why many organisations pursue both together rather than starting each from scratch.

How long is ISO 27001 certification valid for?

Three years, on a structured cycle: Year 1 is your initial certification audit, Years 2 and 3 are surveillance audits confirming your ISMS still meets requirements, and Year 4 brings a full recertification audit. This keeps compliance living and current rather than a one-time checkbox — we support you through every stage of the cycle, not just the first audit.

Do I really need SOC 2 compliance for my business?

It depends on your customer base. If you sell to US-based enterprise or SaaS/cloud customers, SOC 2 is often a contractual requirement before they'll sign. For organisations focused on European markets, ISO 27001 tends to carry more recognised weight, since it's the established standard here — though companies serving customers on both sides of the Atlantic often end up needing both. We help you assess what your specific customer and market mix actually requires, rather than pursuing SOC 2 by default.

Does certification help with NIS2 or DORA compliance?

Yes. There's meaningful control overlap between these certifications and NIS2/DORA requirements, so work done for one often directly supports the other.

Ready to turn security into something you can prove?

Book a free assessment and find out exactly where you stand — and what it takes to get certified.

Book a Free Assessment

Looking for Sales Assistance or have a General Inquiry?

Got a sales question or a general inquiry? Send us a message and we’ll respond as soon as possible.

Please enable JavaScript in your browser to complete this form.
Checkboxes

By submitting this form you agree to our Privacy Policy and consent to Magic Stone Cyber Security storing and processing your information to respond to your enquiry.

Follow us

This will close in 0 seconds

Scroll to Top