CloudBridge Technologies Inc. | SaaS Sector
Comprehensive gap assessment against ISO 27001:2022 for a high-growth supply chain SaaS platform. Full Annex A control evaluation, Statement of Applicability, risk assessment, and 12-month remediation roadmap.
A comprehensive ISO 27001:2022 gap assessment for a high-growth SaaS supply chain visibility platform preparing for EU market expansion.
The Client: CloudBridge Technologies Inc. is a supply chain visibility platform that provides real-time tracking, predictive analytics, and vendor collaboration tools for enterprise logistics operations. Founded in 2019 and headquartered in Atlanta, GA, the company has grown to 250 employees with $35M ARR and over 500 customers across North America.
The Challenge: CloudBridge was preparing to expand into the European Union market, where enterprise customers increasingly require ISO 27001 certification as a prerequisite for vendor engagement. The organization had no formal Information Security Management System (ISMS) in place, no documented Statement of Applicability (SoA), and limited visibility into their compliance posture against the ISO 27001:2022 standard. With a lean security team of 3 people and rapid product development cycles, the organization needed a clear, prioritized path to certification.
My Role: Lead GRC Consultant — responsible for the full gap assessment lifecycle: engagement scoping, stakeholder interviews, Annex A control evaluation, SoA development, risk assessment, findings documentation, and remediation roadmap. I produced the complete assessment package over a 6-week engagement.
The Approach: A structured 4-phase methodology combining document review, personnel interviews, technical verification, and process observation. All 93 Annex A controls were assessed against a 4-level maturity scale with evidence-backed ratings. Findings were risk-rated and mapped to business impact to drive executive decision-making.
ISO 27001:2022
6 Weeks (Q3 2026)
250 Employees • 6 Departments
EU Market Expansion
SaaS Supply Chain Visibility
$35M ARR • 500+ Customers
22 Stakeholder Sessions
45+ Artifacts
A structured 6-week engagement combining document analysis, personnel interviews, technical verification, and process observation across all 93 Annex A controls.
Engagement charter, ISMS scope definition, stakeholder mapping, document request list, communication plan, project timeline
Document collection (45+ artifacts), 22 stakeholder interviews, process walkthroughs, asset and data flow mapping
93 Annex A control ratings, maturity scoring (1-4), SoA development, risk assessment, evidence verification
48 findings, gap analysis, Statement of Applicability, risk treatment plan, 12-month remediation roadmap, executive report
Every control was assessed using multiple independent evidence sources to ensure findings were corroborated and defensible.
Policies, procedures, security architecture docs, contracts, and training records evaluated against ISO 27001:2022 requirements
22 structured sessions across Executive, Engineering, DevOps, Product, HR, Legal, and IT roles using role-specific question banks
Configuration review, access control testing, log analysis, encryption verification, network segmentation checks, and cloud security review
Change management, incident response, access provisioning, vendor onboarding, and development lifecycle walkthroughs
All 93 Annex A controls assessed across 4 themes with maturity ratings and implementation status.
| Theme | 2022 Ref. | Controls | Implemented | Partially | Not Impl. | N/A | Maturity |
|---|---|---|---|---|---|---|---|
| Organizational | 5.1–5.37 | 37 | 14 | 13 | 8 | 2 | 1.4 |
| People | 6.1–6.8 | 8 | 3 | 4 | 1 | 0 | 2.0 |
| Physical | 7.1–7.14 | 14 | 6 | 6 | 2 | 0 | 2.5 |
| Technological | 8.1–8.34 | 34 | 12 | 9 | 10 | 3 | 1.9 |
Maturity scored on a 1-4 scale (1=Initial, 2=Defined, 3=Managed, 4=Optimized). Target maturity for certification: 3.0 across all themes.
48 findings identified across 4 Annex A themes. Each finding includes risk rating, evidence references, business impact, and specific actionable recommendations.
The organization operates without a documented ISMS framework. No Statement of Applicability exists, no information security policy framework is formally established, and there is no defined scope for the certification boundary. This is a foundational requirement for ISO 27001 certification and must be addressed before any formal certification audit.
Risk management is performed informally within engineering teams using ad hoc methods. There is no documented risk assessment methodology, no risk register, no risk owner assignments, and no formal risk treatment plan. ISO 27001 requires a systematic risk assessment process as a core certification requirement.
The organization relies on 15+ third-party vendors and sub-processors for critical infrastructure (cloud hosting, CDN, monitoring, payment processing) but has no formal supplier security assessment process. No vendor risk classification, no security requirements in contracts, and no ongoing monitoring of supplier security posture.
The organization has no documented business continuity plan, no disaster recovery plan, and no BIA (Business Impact Analysis). While the platform has some technical redundancy (multi-AZ deployment), there are no documented procedures, no RTO/RPO definitions, and no testing or exercising of recovery capabilities.
Incident detection relies on engineering alerts with no formal incident response plan, no defined incident categories, no escalation matrix, and no post-incident review process. The organization has no documented incident response procedures and no tabletop exercises have been conducted.
Information assets are not inventoried, classified, or assigned owners. There is no asset classification scheme, no handling procedures for different classification levels, and no asset lifecycle management process. This impacts multiple dependent controls including access control, media handling, and disposal.
User access provisioning and de-provisioning is handled informally. No periodic access reviews are conducted. Former employee accounts remain active in several systems. No segregation of duties analysis has been performed for sensitive roles.
While TLS is used for data in transit and some encryption is applied at rest, there is no documented cryptography policy, no key management procedure, and no inventory of cryptographic controls. Certificate management is ad hoc with no centralized oversight.
All 48 findings are documented in the full Findings Register with evidence references, risk ratings, and remediation recommendations.
A phased remediation plan organized into 4 phases over 12 months, prioritized by certification impact and implementation effort.
Quantitative analysis of control implementation status, findings distribution, and maturity across all Annex A clauses.
93 Annex A controls: 35 Implemented (38%), 32 Partially (34%), 21 Not Implemented (23%), 5 N/A (5%)
48 total findings: 5 Critical, 14 High, 18 Medium, 11 Low
Findings distribution across ISO 27001:2022 Annex A themes
Current maturity (amber) vs. target maturity of 3.5 (blue) for certification readiness
Complete assessment package available on GitHub. All deliverables follow consulting-quality standards with version control and professional formatting.
All 18+ deliverables are available in the project directory, organized by phase with consistent naming conventions.
Full deliverables available in the project repository.