- Job title
- Quality control inspector
- Sector
- IT services
- Organization type
- 8-person team
- Joined
- Jan 2022
- Message
- 139
We are a Riyadh-based B2B software and integration company with 14 employees. We've reached the annual contract stage worth 420,000 SAR with a major semi-governmental client in Saudi Arabia. However, their procurement department added an ISO 27001 certification requirement to the specs and gave us 6 months to get certified.
We don't have a full-time cybersecurity or compliance specialist on staff; our system infrastructure is managed by our senior DevOps engineer. We got quotes from two different consulting firms: one wants 45,000 SAR for the preparation process while the other is asking 75,000 SAR including the audit.
Even though our team is technically strong we have zero experience when it comes to documentation, risk analysis, and drafting policies. Can we complete this process entirely with internal resources in 6 months or is hiring a consultant an absolute must at these budgets?