Pre-Series A · 5–50 employees

Your first ISMS, investor-ready in weeks instead of months.

Series A is coming and the VC is asking about SOC 2 or ISO 27001. A strategic US customer blocks the deal without a cert. GDPR hits the whole team. Kopexa gets you audit-ready, self-serve or with a Partner CISO. Free trial, no credit card.

  • Gap analysis, policy templates, evidence collection out of the box
  • Cross-mapping ISO 27001 ⇄ SOC 2 ⇄ GDPR via OSCAL
  • Self-serve or add a Partner DPO / Partner CISO
14 days
Free trial · no credit card
from 249 €
Lite plan / month
8–12 wks
typical to audit-ready
ISO 27001SOC 2
85%Audit-Readiness
Gap Analysis
Policies
Evidence
Audit-Ready
Beispiel-Verlauf · individuelle Fortschritte variieren

Startups running on Kopexa

What actually happens at startups

Three scenarios where we meet you.

Compliance rarely arrives when there is time. Here are the typical triggers, and the pragmatic path behind each.

Investor hygiene4–6 mo

VC asks for SOC 2 or ISO 27001 before Series A

Term sheet is close, the lead sends a compliance section in DD. You have 8 employees and no ISMS setup. Without an answer, the round slips.

Mit Kopexa

Lite plan live in 14 days, automated gap analysis, policy templates ready. You walk into DD with a documented status.

See pricing
Sales pipeline3 mo

US or EU enterprise wants a cert before close

The first six-figure deal is in procurement and asks for SOC 2 Type II or ISO 27001. Sales can't move until the evidence is in.

Mit Kopexa

ISO 27001 roadmap with all 93 Annex A controls, SOC 2 via OSCAL on top. Auditor workspace included.

ISO 27001 roadmap
GDPR hitsfrom 20 employees

DPO designation becomes mandatory

20 people regularly process personal data automatically, which makes you DPO-mandatory (§ 38 BDSG) without noticing. Investors see it in DD anyway.

Mit Kopexa

Check the obligation in 60 sec, optionally match a Partner DPO from the network. ROPA templates ready.

External DPO

See where you stand instantly

Click a category and see which controls are missing. Prioritized tasks instead of 200-page PDFs.

ISO 27001:2022
A.8Access Control
Open
Multi-factor authentication missing
High2 days
Access logging incomplete
High1 day
12of 93 controls open
View all 93 controls

Your programme in Kopexa

This is what an ISO 27001 programme looks like in Kopexa. Activate framework, work through controls, track progress.

ISO 27001 Certification
72%
ControlStatusEvidence
Information security policies
A.5
Fulfilled
4/4
Organization of information security
A.6
Fulfilled
6/6
People security
A.7
Fulfilled
3/3
Asset management
A.8
Partial
7/12
Incident management
A.5.24
Partial
2/5
Cryptography
A.8.24
Open
0/4

Timeline

4 phases to certification

Phase 1

Start gap analysis

Activate framework, define scope and start automatic gap analysis. In 30 minutes you see which controls are missing and where your startup stands.

Phase 2

Implement policies & controls

Customize 50+ policy templates, implement controls and assign owners. Prioritized task lists instead of unstructured to-dos.

Phase 3Now

Collect evidence

Store screenshots, configurations and evidence centrally in Kopexa. Automatic mapping to controls. Track progress in real time.

Phase 4

Audit-ready in 8 weeks

Structured export to the auditor. Complete documentation, seamless evidence trail. Ready for certification.

Kopexa guides your team step by step through the entire certification process. Self-service or with partner support.

Kopexa vs. startup alternatives

Vanta and Drata host in the US. Excel doesn't scale. Kopexa is EU-hosted, self-service capable and available from 249 EUR/month. Optionally with partner support.

Excel / NotionConsultingVanta / DrataKopexa
Multi-Framework
Policy Templates
Gap Analysis
Evidence Collection
German Platform (EU Hosting)
Self-service option
KSPEC Open Standard
From 249 EUR/month

FAQ

Frequently asked questions for startups

In 30 minutes we show you the path to certification

Let's figure out together which framework fits your startup and how quickly you can become audit-ready.