forumNew topic

They told us to get an "information security audit" — what is it, and is it really necessary?

AAli Ö***Member
Job title
Accounting clerk
Sector
Plastic
Organization type
20-person company
Joined
Nov 2023
Message
42

Doki · Mobile app · 2023

#1

We are a 10-person tech company based in Moscow providing warehouse management software to corporate clients. For about two months we've been negotiating an annual contract worth 14 million RUB with a major retail group. Just when we thought we had an agreement on everything, their compliance department made an independent "information security audit" report a mandatory condition of the contract.

Our team is small; we've always practiced basic security internally, but we've never gone through a formal audit. Looking into consulting firms, I found prices ranging anywhere from 350,000 RUB to 2,000,000 RUB, with timelines spanning from two weeks to three months.

What does an information security audit actually evaluate in practice and how is this handled for a small business? How do we establish a reasonable audit scope that satisfies the client, and is it truly impossible to close enterprise deals without this report?

TTolga A***MemberCommunity member
Joined
Nov 2023
Message
346
Most Helpful#2

Short answer: An information security audit is a third-party evaluation and documentation of your systems, software architecture, and corporate processes to test resilience against cyberattacks and data leaks. Large enterprises are required to mandate this from subcontractors to protect their own data security, making it practically impossible to close the deal without one.

The audit fundamentally covers two areas: technical and process. On the technical side, penetration tests (pentests) are conducted on your servers, databases, and application to identify vulnerabilities, privilege escalation risks, and open ports. On the process side, auditors review employee password policies, source code access permissions, server backup plans, and disaster recovery procedures.

The wide price disparity comes down to scope. Quotes around 2 million RUB typically include full certification for compliance with international standards. However, as a B2B vendor, your client usually doesn't require full certification; they simply want an independent third party to verify that there are no critical vulnerabilities in your system.

Your first step should be asking the client's security team for their standard audit scope specifications in writing. Then, engage a local cybersecurity firm for a penetration test covering your application's API layer and public-facing servers, alongside a basic process review. A technical audit report in the 350,000 - 500,000 RUB range should comfortably fulfill the contract requirement.

EElif Y***Member
Job title
Site Manager
Sector
Media and publishing
Organization type
20-person company
Joined
Mar 2024
Message
5
#3

The auditing firm will request repository access, server logs, and network topology diagrams. In your code, they'll check how sensitive data is encrypted; on servers, they'll inspect where SSH keys and database credentials are stored. Having these organized in advance will speed up the process significantly.

HHande A***MemberCommunity member
Joined
May 2023
Message
377
#4

Don't sign with an expensive auditing firm right away. Ask the client's IT director directly: "Would a standard penetration test report and a remediation roadmap suffice?" In most cases, they aren't looking for a massive organizational audit, just proof that your platform can't be easily breached.

YYiğit V***Member
Job title
Graphic Designer
Sector
Cosmetics
Organization type
two-branch business
Joined
Aug 2024
Message
180
#5

We paid 400,000 RUB to get one done last year. The auditor found 9 vulnerabilities, 2 of which were critical. It took us 10 days to patch them, and then we got a clean report. The client signed a 3-year contract the very next day because of that report—it paid for itself many times over.

OOya K***MemberCommunity member
Joined
Aug 2024
Message
337
#6

There are firms charging 150k rubles that just run an automated vulnerability scanner and export a PDF. Don't fall for that; the enterprise's security team will spot a superficial report instantly, and your company's credibility will be shot.

SSelin K***Member
Job title
QA Tester
Sector
Education
Organization type
120-person company
Joined
Jan 2026
Message
254
#7

Enterprise companies face severe legal and financial penalties for data breaches originating from their supply chain. Demanding an audit report is standard procurement policy under their third-party risk management framework.

GGökhan C***Member
Job title
Studio Founder
Sector
Education
Organization type
chain store
Joined
Jan 2023
Message
64
#8

There are 3 main things the visiting audit team will ask for: 1) Penetration testing findings for the servers, 2) Employee access logs to internal company data and mandatory two-factor authentication, 3) A recovery plan showing how often and where the data is backed up.

IIrmak Ç***Veteran
Job title
System administrator
Sector
Advertising and promotion
Organization type
regional distributor
Joined
Nov 2025
Message
144
#9

A 400 thousand audit cost is definitely worth it for a 14 million deal; this isn't an obstacle, it's your ticket to the enterprise league.

AAdemMember
Job title
Agricultural Consultant
Joined
Jul 2024
Message
82
#10

I've been dealing with this for a long time. If you get three different answers on a topic, the question was asked wrong.

If you post the result here, it will help others too.

SSerkan B***MemberCommunity member
Joined
Mar 2025
Message
53
#11

The answer above hits the nail on the head. When we decide without measuring, we always end up in the same place.

Just leaving this note, it might be useful.

EEmre E***VeteranCommunity member
Joined
May 2025
Message
283
#12

I have a question, don't want to go off-topic though. If you scold false alarms, nobody will report again.

If you post the result here, it will help others too.

SSena M***MemberCommunity member
Joined
Dec 2024
Message
142
#13

Good call starting this thread. If it's your first time start small; scaling comes later.

The answer varies greatly by industry; there is no one-size-fits-all rule. If you post the result here, it will help others too.

UUfuk B***Member
Job title
Field sales representative
Sector
Paper
Organization type
chain store
Joined
Nov 2024
Message
2
#14

I agree. If permission and scope aren't in writing, don't start that test.

That's all, sorry if I went on too long.

KKoray T***MemberCommunity member
Joined
Jan 2023
Message
39
#15

I feel the same way. An automated scan report is not the same as a penetration test.

If you post the result here it will help others too.

MMustafa M***Member
Job title
Quality control inspector
Sector
Food wholesale
Organization type
regional distributor
Joined
Feb 2024
Message
106
#16

I feel the same way. If it's your first time, start small; scaling comes later.

If you post the result here, it will help others too.

HHakan Y***Member
Job title
Production planning
Sector
Seafood
Organization type
20-person company
Joined
Sep 2022
Message
42
#17

I feel the same way. If 2FA is on, a stolen password alone is useless.

An automated scan report is not the same as a penetration test. That's all, sorry if I went on too long.

ÖÖmer D***Member
Job title
Field sales representative
Sector
Automotive aftermarket
Organization type
medium-sized business
Joined
Aug 2024
Message
341
#18

The opposite happened to me, that's why I'm writing... tbh most incidents start with a leaked password, not a vulnerability.

I'm also curious if anyone does it differently.

VVeli Y***Member
Job title
Field sales representative
Sector
Sports and fitness
Organization type
chain store
Joined
Jun 2024
Message
45
#19

Exactly like that. btw when you try to change everything at once, nothing settles.

Good luck with that.

İİsmail E***Member
Job title
Logistics planning
Sector
Energy
Organization type
medium-sized business
Joined
Jun 2025
Message
144

Doki · E-commerce infrastructure · 2023

#20

i feel the same way and solutions that work at a small scale collapse when you grow; I learned this late.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic