Skip to main content

Certification without pausing the product roadmap

ISO 27001 readiness delivered in twelve weeks, with zero major non-conformities at external audit and eleven engineering days per quarter reclaimed from manual evidence gathering.

Industry
Health technology
Location
Dublin, Ireland
Engagement
12 weeks
Team
2 NordsCode engineers, 4 client engineers
0Major non-conformities at external audit
The Stage 2 assessment returned three minor observations, all closed within the four week window. Certification was issued seven months after the engagement began.
11 daysEngineering time reclaimed per quarter
Access reviews, backup verification and vulnerability reporting now generate on a schedule. The previous quarterly evidence collection consumed roughly eleven engineer-days of manual work.
94%Reduction in standing production credentials
From 68 long-lived access keys and 31 broadly privileged accounts to 4 break-glass credentials with alerting on use, replaced by short-lived federated access everywhere else.

What we found when we arrived.

MediSync Health provides appointment and patient communication software to private clinics across Ireland and the United Kingdom. Two hospital group prospects, together worth roughly EUR 400,000 in annual recurring revenue, had made ISO 27001 certification a condition of signature, with a deadline nine months out.

The engineering team of nine had built the product carefully but the environment had grown without an access model. There were 68 long-lived access keys across three cloud accounts, production database credentials in a shared password manager entry used by most of the team, and no record of who had accessed what. Evidence for the audit did not exist in any collectable form. The board's concern was straightforward: certification work would consume the roadmap for a quarter and the hospital deals would slip anyway.

What we did, in the order we did it.

Sequence matters more than tooling on engagements like this one. Each step below existed because the previous one produced something the next one needed.

  1. 01

    Separate what matters from what merely scores badly

    The initial posture review produced 213 findings. Ranked against MediSync's actual threat model and the certification scope, 19 were genuinely urgent. Publishing that distinction early stopped the team from spending its first month on low-severity noise.

  2. 02

    Close the credential problem first

    Single sign-on, role-based access and short-lived federated credentials, rolled out account by account with a break-glass path tested at each step. The 68 standing keys were reduced to 4 audited break-glass credentials over five weeks without locking anyone out of production.

  3. 03

    Make evidence a by-product, not a project

    Access reviews, change approvals, backup restoration tests and vulnerability scans wired to run on a schedule and write their output to an evidence store. What used to be assembled by hand each quarter now accumulates continuously.

  4. 04

    Write policies describing the real environment

    Every policy statement was checked against a control that actually existed. Where the two disagreed we changed the environment rather than softening the wording, which is the reason the Stage 2 assessment found nothing major.

What changed, and how we know.

MediSync passed Stage 2 with zero major non-conformities and three minor observations, all closed inside the four week window. Certification was issued seven months after the engagement started, comfortably ahead of the nine month contractual deadline, and both hospital group contracts were signed.

The ongoing cost is the part the team notices most. Quarterly evidence collection that previously consumed around eleven engineer-days now runs on a schedule and requires review rather than assembly. Product delivery did not stop: the team shipped its two largest planned features during the twelve week engagement, because the security work was engineering rather than committee time.

What it was built on

  • AWS
  • AWS IAM Identity Center
  • HashiCorp Vault
  • Terraform
  • Trivy
  • GitHub Actions

Recognise any of this?

Most engagements start with a call describing a situation that sounds a lot like one of these. Tell us yours and we will say plainly whether we can help.