How we dogfooded our solution to streamline ISO 27001 certification

We turned time-consuming compliance into a seamless process by leveraging real-time Aftra data instead of manual documentation. And you can too.

Sep 8, 2026

#case studies
#Compliance
Back to Resources
Photograph of a dog next to food with a purple gradient filter


In short

For small to medium-sized businesses (SMBs), achieving ISO 27001 certification often feels like a slow, expensive exercise in bureaucratic box-checking. That’s why when the Aftra team set out to earn our own ISO 27001 certification, we took a different approach.

Instead of building redundant processes or buying tools just for compliance, we used our own Aftra cybersecurity software to power the Information Security Management System (ISMS). As a security-first organization, the security part was already there. We just needed to prove it.

Since Aftra brings asset management, vulnerability scanning, and risk assessment data into one platform, it allowed us to eliminate duplicate work, ground compliance in operational reality, and pass the audit with flying colors.

The challenge: Compliance without the chaos

ISO 27001 doesn't magically make a company secure, but it does require companies to prove that security already exists. It’s about making implicit, everyday security practices explicit, structured, and auditable.

For a lean team, spending months manually gathering evidence and maintaining disconnected spreadsheets was not an option. We needed a way to document and prove what we were already doing without adding unnecessary overhead.

Our goal wasn’t security, because we were already secure. Our goal was to build an auditable ISMS without creating a massive administrative burden or forcing the team to duplicate data across isolated tools.

"ISO certification doesn't make you secure, but it does force you to write things down, make implicit practices explicit, and clean up processes you already believe in.”

— Björn Orri Guðmundsson, CEO Aftra

The strategy: Practical dogfooding

Instead of treating ISO 27001 as a separate, manual paper trail, Aftra integrated its platform directly into the compliance workflow (using a lean setup of Aftra + Vanta + Confluence).

Rather than filling out risk assessments based on subjective gut feelings, Aftra provided live, technical telemetry about the environment to guide decisions.

ISO-case-diagram-1

How Aftra powered our ISO 27001 journey

1. Automated asset management & vulnerability discovery

Instead of building static inventories, Aftra automatically discovered and enumerated all of our company assets and ran regular vulnerability scans across the entire environment.

2. Grounding risk assessments in reality

Risk assessments are frequently based on static, hypothetical documentation. By surfacing real-time exposure data including assets, services, third-party software, and known vulnerabilities, Aftra gave us an accurate, data-backed view of our actual risk posture.

3. Single-pane remediation management

Bringing third-party pentest findings and vulnerability scanning data into a single view stopped security details from scattering across isolated dashboards. Our engineers prioritized high-risk vulnerabilities directly within the Aftra software, tracking remediation efforts without jumping between disconnected tools.

4. Frictionless evidence generation via integrations

By sending Aftra’s automated vulnerability results directly into Vanta, the team fed live operational data straight into their compliance framework, drastically cutting down manual evidence collection.

"Having all our vulnerability data scattered across multiple places is somewhere I’ve been before, and I never want to go back. Having one clear view of our environment inside Aftra made risk prioritization and evidence collection effortless."

-Sindri Guðmundsson, CTO Aftra

The business impact

  • Massively reduced manual work: By leveraging existing operational security data inside Aftra, the team avoided recreating records purely to satisfy an auditor.
  • Sped up sales: Achieving ISO 27001 eliminated repetitive security questionnaires, giving prospects an industry-standard way to verify Aftra’s security posture.
  • Delivered continuous security, not point-in-time audits: Because the evidence is fed by live platform data, maintaining compliance is now a continuous background process rather than an annual scramble.

Our advice to SMBs who want to become compliant

If you are preparing for your ISO 27001 journey, keep your compliance engine as lean as possible. Don't build separate workflows just to satisfy a framework. Aftra can centralize your asset visibility, vulnerability data, and risk insights, and let your everyday security practices generate the compliance evidence for you.

And remember:

“Real security is more than compliance. It comes from how your systems are designed, how your code is written, how your infrastructure is operated, and how your people think day to day.”

-Björn Orri Guðmundsson, CEO Aftra

Talk to one of our experts

Book a demo to learn how Aftra can help streamline compliance & take control over your cybersecurity.