Insights / Client Results
Crelate: ISO 27001 in six months, no new headcount.
Crelate wanted a security program credible enough to show enterprise buyers, without hiring for it and without stalling the business. Other consultants had quoted one to two years. With Semper Sec, Crelate certified to ISO 27001 in six months, while a data center migration was underway.
At a glance.
Company
Crelate, Inc.
Talent management SaaS: applicant tracking and recruitment CRM used by staffing and recruiting teams to attract, engage, and hire top talent.
Industry
Software: Talent Management
Recruiting technology serving enterprise buyers with heightened security and vendor-assurance expectations.
Size
Small: ~50 employees
Lean team with no dedicated security headcount to run a certification program.
Condition, action, outcome.
The engagement moved from a gap assessment to a built program to certification, without a hiring cycle and without disrupting the parallel data center migration Crelate had in flight.
Condition: a small SaaS with no dedicated security headcount needed ISO 27001 to compete for enterprise deals, with minimal documentation overhead and no disruption to daily operations, while a data center migration was already underway. Action: Semper Sec proposed a six month timeline covering a gap assessment and ISO 27001 program build, then guided the team through implementation, controls, internal audits, and policy development, with ongoing support post execution and an optional SOC 2 follow on. Outcome: Crelate certified to ISO 27001 in six months, avoided the one to two year timeline other consultants had quoted, added no headcount, reduced inbound security questionnaires and attestations by roughly 25 percent, and differentiated the business commercially.
- ConditionSmall SaaS, no dedicated security headcount, enterprise buyers requiring assurance, and a data center migration already underway.
- ActionSix-month gap assessment and ISO 27001 program build with controls, internal audits, and policy development, plus ongoing support.
- OutcomeCertified in six months, no new headcount, roughly 25% fewer inbound security questionnaires, commercial differentiation.
Condition.
Crelate’s enterprise buyers were asking harder questions about how customer data is protected. As a small SaaS company without dedicated security headcount, Crelate needed to enhance the program and show it to potential large clients. It had to keep documentation lean and daily operations undisturbed. To make it harder, a data center migration was already in flight, and other consultants Crelate had spoken to were quoting one to two years to reach ISO 27001 certification.
Action.
Semper Sec proposed a six-month timeline built around a Gap Assessment and an ISO 27001 program build, with an optional SOC 2 track for later. Once the partnership was in place, we guided the team through implementation: designing the control set, running internal audits, and writing policies that could actually be used. Our senior practitioners continued to support Crelate after execution, so the program did not depend on any single individual staying involved.
Outcome.
Crelate certified to ISO 27001 in six months (not the one to two years they had been told to expect), and did it without hiring dedicated resources or adding team members to maintain the program. A risk-based program was built in parallel with the data center migration, inbound customer and supply-chain security questionnaires and attestations dropped by roughly 25 percent, and the certification became a commercial differentiator in enterprise conversations.
What changed for the business.
Certified in six months, no new headcount
ISO 27001 achieved without hiring dedicated resources or adding team members to maintain the program.
~25% fewer inbound security questionnaires
Client and supply-chain security questionnaires and attestations dropped by roughly a quarter.
Built alongside a data center migration
An efficient risk-based program was stood up while a major infrastructure change was in flight.
Commercial differentiation
ISO 27001 certification differentiated Crelate in enterprise buyer conversations.
Semper Sec improved our overall security posture by augmenting and tailoring our processes and procedures to our business, allowing us to focus on executing the technical security tasks, and concentrate on serving our customers.
Jamey Dulin, VP of IT & Security, Crelate, Inc.
Related.
Service line
Assess and Plan
Gap and readiness assessments that produce a prioritized roadmap you can defend to leadership.
Service line
Build and Implement
Design the operating model, then stand up the controls, workflows, and adoption behind it.
Client Result
ISN: an ISO 27001 program aligned to the business, certified in eight months
How a supply chain risk management leader integrated ISO 27001 with an existing ISO 9001 program.
Start with the program, not the framework.
Talk with a senior advisor about the decisions, ownership, and operating capability your organization needs next.
A conversation with a senior practitioner, not a sales gatekeeper.