You'd think this needs a $40K compliance consultant and 9 months — Tycoon Agent runs the prep playbook in chat with Vanta or Drata as the system of record.
The short answer
Tycoon Agent walks you through ISO 27001 prep in 4 months using a structured 6-phase playbook. Phase 1 (week 1-2): scope definition — which products, teams, and data are in scope; she drafts the Statement of Applicability mapping the 93 Annex A controls to your environment. Phase 2 (week 3-6): policies — she generates 14 required policies (information security, access control, incident response, BCP, etc.) tailored to your stack and team size, reviewed against current ISO 27001:2022 standards. Phase 3 (week 7-10): controls implementation — she runs the gap analysis via Vanta or Drata, prioritizes remediation by audit risk, opens Linear tickets for each gap, and tracks completion weekly. Phase 4 (week 11-12): risk assessment + treatment plan. Phase 5 (week 13-14): internal audit dry-run. Phase 6 (week 15-16): external Stage 1 audit. Weekly Lark report shows % controls passing, top 5 gaps, and ETA to audit-ready. Target audit pass rate: 100%.
How Tycoon Agent actually does it
- Define scope + Statement of Applicability
Map 93 Annex A controls to your stack. Identify which apply, which are excluded with justification. Draft the SoA in Notion for legal review.
Notion
- Draft 14 required policies
Information security, access control, change management, incident response, BCP/DR, supplier security, asset management, etc. Tailored to your team size and tech stack.
Notion
- Run gap analysis via Vanta/Drata
Connect Vanta or Drata to AWS/GCP, GitHub, Okta, HRIS, etc. Auto-detect failing controls. Open Linear tickets per gap with auditor-grade descriptions.
VantaDrataLinear
- Prioritize and remediate weekly
Risk-weighted prioritization (high-impact gaps first). Weekly Lark report on % controls passing, top 5 gaps, ETA to audit ready. She nudges owners on stuck tickets.
LinearLark
- Internal audit + Stage 1 prep
Run mock audit covering all 93 controls. Generate evidence package (logs, screenshots, signed policies). Brief team on auditor interview prep. Schedule Stage 1 audit.
VantaDrataNotion
What it looks like in chat
YouWe need ISO 27001 for a big enterprise deal. Where do we start?
Tycoon Agent16-week plan. First 3 decisions: **1. Scope.** Are we certifying just the production product or the whole company? Recommendation: just product (faster, cheaper, satisfies most enterprise buyers). Locks in 60% smaller audit scope. **2. Platform.** Vanta ($16K/yr) or Drata ($14K/yr) for control automation. Both connect to AWS, GitHub, Okta. I recommend Vanta if you have 50+ employees, Drata if smaller. They cut prep time from 9 months to 4. **3. Auditor.** Schedule with Schellman, A-LIGN, or BSI. Stage 1 audit at week 15. They book 8-12 weeks out so we'd start procurement Week 6. **This week I'll:** - Draft the SoA mapping all 93 controls to your stack (you review Friday) - Set up Vanta connectors to GitHub, AWS, Google Workspace - Generate the 14 required policies, tailored to your 22-person team **Next 4 weeks:** policies signed, Vanta gap analysis live, ~30-50 Linear tickets opened. By week 8 we should be at 80% controls passing. Go?
What you get back
Audit-ready stack: SoA, 14 signed policies, 100% controls passing in Vanta/Drata, internal audit complete, Stage 1 audit scheduled. Weekly Lark report on progress.
Cadence: 16-week prep cycle. Weekly progress reports. Quarterly re-audit prep after certification.