Specialist Compliance Consultancy

Compliance,
made faster.

ISONEX delivers ISO 27001 with Stage 2 audit complete in 75 days — where the industry standard is six to nine months. Same standard. Same rigour. A quarter of the calendar.

ISO 27001 & SOC 2 specialists 20+ frameworks covered Practitioner-led delivery
Alliance member Drata Launch Alliance 2026 — Registered Member
Frameworks we deliver
ISO 27001SOC 2ISO 42001NIST CSFGDPRHIPAAPCI DSSDORAISO 9001ISO 27017 ISO 27001SOC 2ISO 42001NIST CSFGDPRHIPAAPCI DSSDORAISO 9001ISO 27017
75
Days to Stage 2 audit, where the industry takes 180–270.
2
Core specialisms — ISO 27001 and SOC 2 — run in-house.
20+
Frameworks delivered through our specialist consultant network.
15+
Years of cybersecurity experience behind the practice.
Our services

Six practices.
Built for speed.

Every engagement begins with a diagnostic and ends with evidence — not slides. Each practice is structured to compress the calendar without compromising depth.

Gap Diagnostic

A structured baseline against your chosen framework — so you know exactly what's missing before you commit to certification.

  • Ranked, costed remediation plan — not a colour-coded heatmap
  • Senior-led assessment against the real control set
  • Clear effort estimates so you can plan the timeline
Learn more

Compliance as a Service

Your full compliance team, without hiring one. We build the policies, operate the evidence, manage the platform, and own the audit.

  • Named Business Lead and specialist consultants from day one
  • End-to-end implementation and team enablement
  • Ongoing monitoring, updates, and audit readiness
Learn more

Internal Audit

Strengthen your controls, surface hidden risks, and turn compliance into a competitive advantage — catching every gap before the certification auditor does.

  • ISO 19011-aligned reviews tailored to your industry
  • Risk identification with actionable recommendations
  • Beyond compliance — operational excellence
Learn more

Penetration Testing

Vulnerability assessment and real-world penetration testing to expose exploitable risk, satisfy certification requirements, and strengthen your defenses.

  • Real-world testing that maps to the standards that matter
  • Vulnerability assessment plus active exploitation
  • Actionable reporting with prioritized remediation
Learn more

Custom Frameworks

When your regulator, customer, or product demands a control set no platform supports — we build it, map it, and make it auditable.

  • Bespoke control sets mapped to your obligations
  • GCC regulatory regimes — NCA ECC, SAMA, PDPL
  • Designed to satisfy the framework your GRC tool can't
Learn more

Certification Support

End-to-end programme management from scoping through audit day. One partner, one accountable Business Lead, all the way to your certificate.

  • Seamless ISO 27001 and SOC 2 certification
  • We sit with you through Stage 1 and Stage 2 audits
  • One accountable point of contact, end to end
Learn more
Why it matters

The ISONEX difference.

We've spent enough time inside enterprise consultancies and compliance platforms to know what we don't want to build. Here is the contrast.

The traditional approach

  • Six-to-nine month timelines that drift
  • Sold by partners, delivered by junior analysts
  • Generic template libraries dressed as advice
  • Rolling SOWs that grow 40% over a year
  • Policies written for the binder, not the build

The ISONEX model

  • Stage 2 in 75 days, on a fixed calendar
  • A named Business Lead accountable end to end
  • Specialist consultants matched to your framework
  • Fixed scope, fixed fee — re-quoted in writing
  • Evidence-first — built around what auditors test
Engagement flow

From kickoff to Stage 2,
in five stages.

Five clearly bounded stages on a tight calendar. The industry standard for the same work is 180 to 270 days.

01

Scoping

We map your environment, define the certification boundary, and agree the risk model.

02

Diagnostic

Senior-led gap assessment. Output is a remediation plan with effort estimates.

03

Build

Policies, procedures, controls, platform setup. Weekly cadence with engineering.

04

Operate

Evidence runs. Internal audit. Management review. The audit dress rehearsal.

05

Audit

We sit with you through Stage 1 and Stage 2 and answer the auditor's questions.

Mossab K. Yousef, Co-founder of ISONEX Co-founder · ISONEX
Leadership

Mossab K. Yousef

ISONEX is co-founded by a named compliance practitioner who sets the firm's technical direction. With over fifteen years in cybersecurity, Mossab brings hands-on experience leading information security programmes — including in government-sector environments.

ISONEX operates a remote-first, outcome-driven model with registered offices in Manama, Dubai, and Riyadh. Every engagement is overseen by a named Business Lead, working alongside the specialist consultant matched to your framework — so the people doing the work have done it before, many times.

Certifications
ISO 27001 Lead Implementer · CREST CRT
Experience
15+ years in cybersecurity
Education
BSc IT — Cybersecurity
Sectors
Government & commercial
Connect with Mossab on LinkedIn
What we deliver against

Core in two.
Twenty more on tap.

ISO 27001 and SOC 2 are our core practice. Additional frameworks are delivered through our curated network of senior specialist consultants.

Questions

Frequently asked.

The 75 days runs from engagement kickoff to your ISO 27001 Stage 2 audit. It assumes an engaged team and a defined scope. Final audit dates depend on your certification body's availability, which we plan around at scoping. SOC 2 Type II includes a mandatory observation window and follows a different timeline, which we'll always set out honestly up front.

A named Business Lead owns your engagement end to end, working alongside a senior specialist consultant matched to your specific framework. No rotating account managers, no junior analysts you've never met.

Not necessarily. We're platform-agnostic — we'll work with the GRC platform you already use, recommend one if it fits your stage, or deliver without one. The right tool depends on your size and goals, not on a referral fee.

ISO 27001 and SOC 2 are our core in-house practice. Beyond those, we deliver 20+ frameworks — including ISO 42001, GDPR, HIPAA, PCI DSS, DORA, NIST CSF, ISO 9001, and GCC regimes such as NCA ECC, SAMA, and PDPL — through our curated network of senior specialist consultants.

Fixed scope, fixed fee. You know the cost and timeline before you commit. If something changes materially, we re-quote in writing — no rolling SOWs, no surprise invoices mid-programme.

ISONEX is a remote-first firm with registered offices in Manama, Dubai, and Riyadh. We work with engineering-led companies across the GCC and beyond, delivering remotely while staying close to the region's regulators and certification bodies.

Technology Alliance

Certification delivery,
backed by automation.

ISONEX is a registered member of the Drata Launch Alliance. We pair our hands-on certification delivery with Drata's continuous compliance automation platform — so evidence collection and control monitoring run continuously in the background while we drive your engagement through to audit.

Drata Launch Alliance 2026 — Registered Member
Start the conversation

Ready to move
faster?

Tell us what you're certifying against. We'll come back within one business day with a scoping note — not a sales sequence.

info@isonex.co