# How we use AI to get SMBs certification-ready in four to six weeks

> AI drafts the documentation, our consultants adapt it with you, and the evidence gathers itself in a GRC tool. That is how the timeline holds up.

Source: https://fmcybersecurity.com/en/insights/compliance/how-we-use-ai-to-get-smbs-certification-ready/
Locale: English
Other locale: https://fmcybersecurity.com/insights/compliance/slik-bruker-vi-ai-til-sertifiseringsklar-pa-fire-til-seks-uker/

## Metadata

- Date: 2026-08-11
- Author: fredrik-standahl
- Topic: compliance
- Format: article

Certification-ready in four to six weeks is the claim on our [Secured by FM CyberSecurity](/en/secured/) page, and I understand the doubt. An ISO 27001 project has traditionally been measured in months. This article shows where the weeks go, and what AI changed.

I sit in the buying conversations for the package, and the timeline is the first thing skeptical buyers question. The second is whether documentation drafted with AI can survive an audit. Both deserve a straight answer.

## AI drafts, people decide

Most of a classic ISO 27001 project is writing: policies, procedures, risk assessments, and the statement that explains which controls you apply and why. That writing used to fill the calendar. Now AI drafts it, mapped against the ISO 27001 standard so each document covers what the standard asks of it.

The drafts are the start, not the deliverable. Our consultants review and adapt every document with you, so the finished policy describes how your company works rather than how a template imagines it. Nothing reaches the auditor before a consultant and your own people have read and approved it.

We hold ourselves to the same split when we write, this article included. The disclosure line at the end is the same rule applied to our own text.

## The audit file builds itself

The second big time cost in a traditional run is evidence. Screenshots, access lists, and sign-offs get collected in a stressed rush the month before the audit. We removed that rush by moving the collection into the work itself.

Controls and evidence are gathered continuously in a GRC tool, software that keeps governance, risk, and compliance records in one place. When a control runs, the proof lands in the file. By audit day, no one has to sit down and write the audit file. It has grown as a byproduct of the work.

## Monitoring runs from day one

ISO 27001 expects you to detect and handle incidents, not just describe how you would. So we switch monitoring on in the first week, well before the certificate. FM CyberSecurity's own SOC, driven by agentic AI and built on CrowdStrike, monitors around the clock.

Our analysts follow up directly during working hours, and an on-call arrangement covers the rest of the day. A critical attack escalates to the SOC immediately. When the auditor asks how incident handling works, you point at a function that is already running, with real alerts and real follow-ups behind it.

## What decides the pace

So why four to six weeks, and not less? Because AI cannot compress your side of the work. The drafts need your answers: how you hire, who approves access, where your data lives, which suppliers matter. The pace of a run depends mostly on how quickly you answer our questions.

That is why four to six weeks is the typical run, and why we never promise less. Answer fast and you land early in that window. If the answers take longer, the run takes longer, and we would rather say so up front.

## One contract, with a guarantee

The whole run is packaged as Secured by FM CyberSecurity: one vendor, one contract, one price. Why buyers demand the certificate in the first place is covered in [what ISO 27001 is, and why you lose tenders without it](/en/insights/compliance/what-iso-27001-is-and-why-tenders-require-it/).

The package carries a guarantee. If the audit does not go through within the agreed window, we cover the next attempt. Gross negligence on the customer side voids it. We can stand behind that because we run every step above ourselves: the drafting, the evidence, the monitoring, and the review before the auditor arrives.

## Next step

See what the package contains at [Secured by FM CyberSecurity](/en/secured/), or read how the subscription is put together in [ISO 27001 as a subscription, with a guarantee](/en/insights/strategy/iso-27001-as-a-subscription/). If the timeline still sounds too good, bring the skepticism to a short conversation. We will walk you through a run, week by week.

Drafted with AI assistance, reviewed and edited by Fredrik Standahl and the FM CyberSecurity editorial team.

## FAQ

### Is the documentation just AI-generated templates?

No. AI produces the first draft, mapped against the ISO 27001 standard. Our consultants then review and adapt every document with you, so the result describes how your company works. Nothing goes to the auditor without human review and your approval.

### Does an auditor accept documentation drafted with AI?

The audit assesses whether your management system matches how you work in practice, and the standard does not regulate who typed the first draft. What the auditor sees is documentation your team has reviewed and approved, with evidence in the GRC tool showing that the system runs.

### Can we be certification-ready faster than four to six weeks?

Four to six weeks is the typical run, and we do not promise less. The pace depends mostly on how quickly you answer our questions. The audit itself is performed by an accredited certification body once you are ready.

### Who monitors our systems while we work toward the certificate?

FM CyberSecurity's own SOC monitors around the clock from day one, driven by agentic AI and built on CrowdStrike. Our analysts follow up directly during working hours, an on-call arrangement covers the rest, and a critical attack escalates to the SOC immediately.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
