The security questionnaire that is holding up your biggest deal

ISO 27001, SOC 2, and the client security reviews that arrive with a deadline attached. Wizard turns the answers into a system you maintain once instead of assembling every time.

Compliance arrives as an interruption

It starts with a questionnaire from a client who is bigger than you. Forty tabs, three hundred questions, and a deal waiting behind it. Someone spends a week on it, the deal closes, and the file goes into a folder.

Six months later another client asks, with different questions and a different format, and most of the answers have changed because the product has changed. So it happens again.

Somewhere in that cycle a client asks for certification rather than answers, and the work that has been happening in bursts has to become continuous. That is usually the point at which the spreadsheet stops being enough, and it arrives without warning because it is driven by your customers rather than by you.

Automation covers the infrastructure, not the organisation

Evidence collection is the easy part. Platforms that pull evidence from cloud infrastructure do that well. Policies that reflect how you actually work, risk decisions with owners, supplier reviews, access reviews for things that are not cloud infrastructure, and training records still need people.

Certification is treated as the finish line. Tools built to get you certified quickly are optimised for the audit date. Keeping it true for three years afterwards, through team changes and product changes, is a different problem.

One standard at a time. ISO 27001 today, SOC 2 because a US client asks, GDPR because you process personal data, the AI Act if there is a model in the product. Adding each one as a separate project means maintaining overlapping evidence in separate places.

Answer it once, maintain it continuously

Controls mapped across frameworks. Evidence collected for one standard serves the others rather than being duplicated. ISO 27001 and SOC 2 overlap heavily, and the overlap should be structural rather than manual. PLACEHOLDER: product screenshot, control mapping across frameworks.

Policies with owners and review dates. Approval workflows built in, so what is documented is what is current rather than what was written before the last two hires. PLACEHOLDER: product screenshot, policy library with owners and review cycles.

Risk and supplier registers that connect. Risks and third parties linked to the controls they affect, so a change in one surfaces in the other. PLACEHOLDER: product screenshot, risk and supplier registers.

One source for questionnaire responses. Maintained rather than reassembled, so the next questionnaire is a review rather than a week of work. PLACEHOLDER: product screenshot, questionnaire response library.

Where Wizard fits, and where it does not

Against automated compliance platforms. If ISO 27001 or SOC 2 is your entire scope, you are cloud-native, and speed to certification is the priority, those tools are very good at exactly that and you should use one. Wizard becomes the better choice when the scope is broader than security, when a meaningful part of your compliance is not automatable, or when the question is maintaining certification rather than obtaining it.

Against a consultant and spreadsheets. This works, and many companies certify this way. It stops working when the person holding it leaves, or when the second standard arrives.

Against building it into your existing tooling. Some engineering teams manage this in the same systems they use for everything else. That holds while compliance is owned by engineering. It breaks when someone outside engineering becomes accountable for it.

What Wizard is not. It will not generate evidence you do not have, and it is not a substitute for someone owning security in your organisation. It also does not audit you. You will still need a certification body.

Built by people who have been audited, and who have audited others

Wizard was designed by people who spent years building these systems inside regulated organisations before they built software for them. What follows is their professional background. These were consultancy and audit engagements, not Wizard implementations, and we mention them because the design decisions in this product came directly from that work.

Eoghan Kenny, Co-Founder and CEO. Over twenty years implementing governance, risk and compliance systems in regulated organisations. He has built and implemented ISO 27001 management systems for organisations including OneTouch Health, Trojan, Thrive Accounts and ICDL Foundation, and has worked as an external Data Protection Officer for organisations processing personal data at scale.

Derek Mizak, Co-Founder and CTO. Over thirty years across cybersecurity, audit and systems architecture. He has audited information security management systems as a certification body auditor for Certification Europe (now Amtivo), which means he has seen which controls hold under examination and which ones only look like they do.

Dominic O'Toole, Co-Founder and CPO. Over twenty years building enterprise software, including at IBM and Fidelity.

None of this makes Wizard the right fit for every organisation. It does mean the people who designed it have implemented, maintained and audited the systems it manages.

Common questions

How long does ISO 27001 take from a standing start?

[PLACEHOLDER: to confirm. A real range, and what it depends on.]

Does Wizard handle SOC 2 as well as ISO 27001?

Both, through linked controls. A single control carries every framework it serves, so evidence gathered once counts everywhere it applies. The mapping is configured to your scope and your control set rather than shipped as a generic crosswalk, which means it reflects the system you actually run.

We already use an automated compliance platform. Why would we change?

Often you would not, at least not immediately. Those platforms are strong at automated evidence collection for security frameworks. The question is what happens to everything they do not cover, and whether that is currently living in spreadsheets alongside them.

What happens when the product changes?

That is the point of the design. Controls, risks and policies reference each other, so a change surfaces where it matters rather than sitting unnoticed until the next audit.

Where is our data held?

Microsoft Azure, with enterprise-grade access controls. Our sub-processor list and data processing agreement are published on the site.

Are you certified to ISO 27001 yourselves?

Wizard is built to ISO 27001 requirements and hosted on Microsoft Azure in Ireland, with our security architecture, Data Processing Agreement and sub-processor list published on our Legal, Privacy and Security page.

What does it cost?

Standard plans start at 600 euro per month billed annually for up to 30 active users. Consultant accounts are free and do not count toward the limit.

See what your next questionnaire could look like

Request a demo and we will walk through how this works for your stack and your standards. If you would rather see where you stand first, the Health Check takes five minutes. Request a demo.