From Compliance Requirement to Competitive Advantage

The Foundation of Modern Information Security

In 2026, ISO 27001 is no longer a luxury for a select few, but a baseline requirement in almost all tenders and partnerships. It is proof that your organization has carried out a systematic risk assessment and built its defenses according to documented standards. At Stratu, we help you make the certification process manageable. We ensure that your IT infrastructure supports your policies, allowing you to transfer significant parts of the security responsibility to us as your supplier - without your customers having to conduct extensive audits of you every time.

Proof of Risk Assessment

Get concrete proof that you have control over your critical assets. ISO 27001 ensures your IT security is built on facts and risk-based decision-making, not on chance.

NIS2 Platform

Make NIS2 a manageable task. If you already have ISO 27001, you are roughly 80% of the way to NIS2 compliance. We use the standard as a stepping stone for your continued compliance journey.

Transfer of Responsibility

By using an ISO-certified partner like Stratu, you can document your supply chain security through our audit reports. This saves you time and resources.

A World of Requirements

Are you tired of filling out vendor questionnaires?

Each time you start working with a major customer, a complex IT security questionnaire lands in your inbox. Without ISO 27001 certification, these forms become a growing administrative burden that slows down your growth.

Why ISO 27001 is necessary in 2026:

  • Audit fatigue: Companies spend weeks answering the same security questionnaires. A certification removes the need for most manual checks.

  • Supplier Management: NIS2 requires you to monitor your suppliers. Without a common framework such as ISO 27001, this task becomes unmanageable.

  • Undocumented Defense: Many organizations are actually secure, but they lack the proof. Without documentation, you are perceived as insecure in today’s market.

We aim to be our customers’ best decision

We are proud to work with

Control Your Risk

We build the technical foundation behind your certification.

We do not see ISO 27001 as a pure documentation exercise, but as a way of running a sound IT operation. Our advisory approach is about closing the gap between what management has decided and what actually happens in the engine room.

Our Approach to Your ISO Journey:

  1. Risk-Based IT Operations: We help you translate your risk assessment into concrete technical decisions in your infrastructure, for example regarding network security and Microsoft 365 backup.

  2. Harmonized Compliance: We design your ISMS to cover both ISO and NIS2. This way, both frameworks are integrated into the same annual cycle, saving you from duplicate work.

  3. Audit Backing: As your operations provider, we deliver the necessary “audit trails” and assurance reports (e.g. ISAE 3402), enabling your external auditor to quickly approve your setup.

Structuring the Journey

How to Get Audit Ready

Becoming certification-ready requires a methodical effort. We guide you through the critical steps so you do not waste time on irrelevant documentation.

1. Scoping & Context (Week 1–2) We define exactly what the certification should cover. Which systems and which employees are in scope? The more precise the scoping, the more cost-efficient the process becomes.

2. Risk Analysis & Gap Assessment (Week 3–5) We identify the gaps between your current setup and the 93 controls in Annex A. We develop your Statement of Applicability (SoA), which serves as your definitive security evidence.

3. Implementation & Evidence (Ongoing) We implement the missing technical controls and set up the logs and reports that serve as evidence when auditors review your setup.

The Smart Shortcut

Inherit security from Stratu’s platform

The most expensive part of ISO 27001 is documenting and maintaining the technical controls. But if you use Stratu’s platforms, much of that work is already done for you.

When you operate with Stratu, you can reference our certifications in your audit for areas such as:

  • Physical Security (Annex A.7): Access control, power supply, cooling, and fire protection in the data center.

  • Operational Security (Annex A.8): Backup, malware protection, and logging.

  • Supplier Management (Annex A.5): We are an approved, certified supplier.

This significantly reduces the scope of your own audit—and therefore the cost of certification.

Why Choose Stratu?

We are both architects and builders.

When you let us support your ISO preparation, you are working with a partner who applies the same standards every day in its own operations.

    • We Are Certified Ourselves: Stratu is ISO 27001 certified. We know exactly where the pressure points are during an audit, and we have proven templates that work.

    • Audit reports are standard: Our own reports (ISAE 3402 and 3000) are always available to you. This is your shortcut to documenting supplier responsibility.

    • Focus on Technology: We are not just theorists. We understand the code and infrastructure behind the documentation, ensuring that your policies are actually technically feasible to implement.

Want to learn more about

Stratu as Your ISO Partner?

Complete the contact form below and one of our specialists will contact you.

Frequently asked questions:

ISO 27001 (FAQ)

For a small or medium-sized company (SME), it typically takes 6–9 months from start to certification if you work on it consistently. Larger organizations should expect 12+ months.

In addition to advisory services, you must pay an accredited certification body (e.g. DNV or Bureau Veritas) to conduct the actual audit. The price depends on the number of employees and your locations.

Not directly, but ISO 27001 is the internationally recognized standard that NIS2 legislation is closely aligned with. If you are ISO certified, you are very close to being NIS2 compliant.

Column in Ingeniøren

With countless emails and passwords, cyber fatigue is taking hold

In a column in Ingeniøren, our CEO Jeppe Klestrup shares his thoughts on a growing challenge: cyber fatigue.

In the article, he writes:

"Cyber fatigue is a form of mental exhaustion that affects two levels. On one side are employees who face a constant stream of warnings, passwords and security requirements.

 The result is not greater vigilance, but that people tune out and ignore warnings simply to get through the working day.

On the other side are decision-makers, including IT managers tired of constantly having to choose between security, operations and budgets."

– Jeppe Klestrup, CEO, Stratu

Read the full column here.

World-class international technology partners

We partner with

Ligesom vi som faglig organisation skal hjælpe, servicere og sætte os i det enkelte medlems sted, har vi brug for en IT-leverandør, der kan det samme. En leverandør, der værdsætter os som kunde og som kan designe løsninger til netop os

Frequently asked questions:

ISO 27001 Forberedelse FAQ

Hvad er ISO 27001?
ISO 27001 er en international standard for informationssikkerhed, der hjælper virksomheder med systematisk at identificere, vurdere og håndtere sikkerhedsrisici. Et centralt element er etableringen af et Information Security Management System – ISMS – hvor virksomhedens risici, politikker, kontroller og løbende forbedringer struktureres og dokumenteres. Stratu hjælper med at koble dette arbejde til virksomhedens faktiske IT-infrastruktur.
En ISO 27001-certificering kan dokumentere over for kunder, samarbejdspartnere og andre interessenter, at virksomheden arbejder struktureret med informationssikkerhed. Certificeringen kan samtidig reducere behovet for gentagne sikkerhedsspørgeskemaer og omfattende leverandøraudits, fordi virksomheden kan dokumentere sit sikkerhedsarbejde gennem en anerkendt standard.
Tidsforbruget afhænger af virksomhedens størrelse, kompleksitet og nuværende modenhed. Stratu angiver, at en mindre eller mellemstor virksomhed typisk skal regne med omkring 6–9 måneder ved en dedikeret indsats, mens større organisationer ofte skal regne med 12 måneder eller mere.
En gap-analyse sammenligner virksomhedens nuværende sikkerhedssetup med kravene og kontrollerne i ISO 27001. Formålet er at identificere de områder, hvor organisationen allerede lever op til standarden, og hvor der mangler politikker, processer, dokumentation eller tekniske sikkerhedsforanstaltninger. Stratu anvender gap-analysen som en del af forberedelsen frem mod audit.
Statement of Applicability, ofte forkortet SoA, beskriver, hvilke sikkerhedskontroller fra ISO 27001 Annex A virksomheden har vurderet som relevante, hvilke der er implementeret, og hvordan de håndteres. Stratu beskriver SoA som et centralt element i arbejdet med de 93 kontroller i Annex A under forberedelsen til certificering.
Nej. ISO 27001 er en international standard, mens NIS2 er regulering. Der er dog et betydeligt overlap i arbejdet med blandt andet risikostyring, informationssikkerhed, hændelseshåndtering og dokumentation. Stratu arbejder derfor med at harmonisere ISO 27001- og NIS2-arbejdet i samme ISMS og årshjul, så virksomheden undgår unødvendigt dobbeltarbejde.
Ikke nødvendigvis. Kontrollerne i Annex A vurderes ud fra virksomhedens risici, kontekst og behov. Det afgørende er, at virksomheden kan dokumentere, hvilke kontroller der er relevante, hvorfor de er valgt eller fravalgt, og hvordan relevante risici håndteres. Dette dokumenteres blandt andet gennem virksomhedens Statement of Applicability.
Ja. Når dele af infrastrukturen drives hos en certificeret leverandør, kan leverandørens sikkerhedskontroller og dokumentation understøtte virksomhedens egen audit. Stratu er selv ISO 27001-certificeret og stiller blandt andet dokumentation og revisionserklæringer til rådighed for kunder, hvilket kan reducere den dokumentationsbyrde, virksomheden selv skal håndtere.

Tal med en specialist i netværkssikkerhed

Book et møde med Lars om ISO 27001-forberedelse

Få en uforpligtende snak om, hvor jeres virksomhed står i forhold til ISO 27001, og hvad der skal på plads før en certificering. Lars hjælper med at skabe overblik over krav, dokumentation, risici og de næste konkrete skridt.

Our customers say it best.

We wanted a flexible platform that could keep pace with developments and support the organisation without unnecessary administration.
Frederik Krebs Jensen
Head of Technology at e-Boks
Stratu has a strong team with a clear customer focus. They have helped us build a digital foundation that supports both operations and development.
Dennis H. Krogstrup
CIO Group Online