We are an 18-person software startup based in Barcelona. We sell cloud-based order tracking software to enterprise clients across Europe. A major retail client we recently signed made ISO 27001 certification a contractual requirement. We've started working with a consultant, but we've hit a major roadblock when it comes to the vulnerability management clause.
Our consultant told us an annual penetration test won't cut it for the audit; we need to prove we run recurring vulnerability scans on internal and external systems and track remediations by risk level. Right now our total annual budget for security and infrastructure is around 4,000 EUR, and consulting fees have already eaten up a big chunk of that.
Are we stuck having to pay for expensive enterprise security suites to meet this requirement, or can we set up this process using open-source tools or budget-friendly cloud scanners? In practice, what scanning frequency, prioritization logic, and remediation workflows will an auditor actually accept?