FAQ

Implementation & process

How long does it take to get certified?

It depends on the standard, organization size and scope — typically 3–6 months; smaller organizations can be faster. We provide a clear timeline after the gap analysis.

Is the process the same for every standard?

No. ISO 27001, CMMC, TISAX and AS9100 differ in requirements and assessment; we tailor the plan to each standard and your current status.

Do we need prior background?

No. We start from gap analysis and training, guiding your team to build the system step by step.

Must we hold ISO 27001 first to adopt ISO 27701?

No. ISO 27701:2025 is now a standalone standard and can be implemented and certified independently.

Cost & packages

How is the fee calculated?

Based on the standard, scope, number of sites and headcount. Contact us for a customized quote.

Do you have a package for SMEs?

Yes — our "ISMS Easy-Adoption Toolkit for Small Business" helps SMEs adopt a compliant system efficiently.

Certification & maintenance

Do you help liaise with the certification body?

Yes. Our consultants have hands-on experience at certification bodies and help you prepare for the external audit to improve first-time pass rates.

What happens after certification?

Typically an annual surveillance audit and re-certification every three years. We provide ongoing internal audit, management review and continual-improvement support.

Other

Where and whom do you serve?

Primarily enterprises and agencies in Taiwan, and clients with international supply-chain needs (e.g. CMMC, TISAX).

How do we start?

Contact us via the footer with your needs and we will arrange an initial consultation and assessment.

Have a question? Contact us and a specialist will assist you.