We recently got certified for ISO 9001 and ISO 27001. Honestly, the question we keep coming back to is: what now?
Most companies post the badge, write “thrilled to announce,” and move on to the next post. We’d rather talk about what actually happened, because we think the story is more useful than the announcement.
It’s not quick, and it’s not clean
Getting certified means opening up everything you do. How projects get managed? How client data gets handled? How decisions get made when nobody outside the team is watching? And then letting someone come in and look at the real version of all of it, not the version you’d show a client.
We found things we were doing well. We also found things we weren’t. Some of that was uncomfortable to sit with, honestly. But if an audit doesn’t surface anything uncomfortable, it probably wasn’t a real audit.
The part people underestimate
Some of our processes only lived in one person’s head. Not written down anywhere. Not backed up by anything except that person remembering to do it, week after week. Which sounds fine, right up until that person is on vacation, or sick, or leaves the company, and suddenly nobody quite knows how the thing gets done, or why it was done that way in the first place.
That’s the part we think people underestimate about this whole process. It’s not really about the certificate. It’s about the fact that our company can no longer just run in someone’s head.
If someone leaves tomorrow, the work doesn’t leave with them. Someone else can pick it up, because it’s written down, it’s clear, and it doesn’t depend on one person’s memory or goodwill to keep functioning. That’s not a small thing. That’s the difference between a company and a group of people who happen to be good at their jobs right now.
Nothing to be ashamed of
We went through this because we want to keep getting better, not because we wanted something to put in an email signature. The certificate is proof that we were willing to be looked at closely. It’s not proof that we’ve arrived anywhere.
What’s actually changed: not much, yet
Here’s what we want to be honest about: nothing has changed yet. Our people are doing the same work they were doing last month. The workflow is a little more structured now, a little more written down, a little less dependent on one person remembering the right steps at the right time. That’s it, for now.
There are no results to point to yet. No faster delivery, no fewer mistakes, nothing we can hold up and say “here, this is what the certificate got us.” That will take time to show up, if it shows up at all. The certificate doesn’t guarantee anything on its own. It just gives us a better foundation to actually build on.

We’ve grown into an organization with clearly defined processes, high standards, and a responsible approach to security. This is just the beginning of a new phase in which we’ll continue raising the bar and building technology that delivers lasting value to our clients.
The start of a conversation, not the end
So consider this the start of that conversation, not the end of it. We’ll come back and talk about whether this actually changed how we work. Once we have something real to report. Not before.


