Founding Five — five no-fee places. See if you qualify →

The Founding Five

Five startups. No fee. Your story is the price.

This quarter I'm taking five startups through their compliance journey — ISO 27001, SOC 2 or Cyber Essentials — at no cost, over twelve weeks. In return I want permission to write up how it went and use it in our marketing. That is the entire arrangement.

Or apply in writing →
5 of 5 places open

I have existing clients who come first, so I run this at the edges of the day:

Tuesday & Thursday 7:30–9:00am

Wednesday 5:00–6:30pm

0161 327 5077Or book a slot yourself →

The situation this is for

If none of this sounds familiar, you probably don't need it.

The deal is stuck behind a security review

An enterprise customer has sent a 200-line questionnaire, or asked for your ISO 27001 certificate. Procurement won't move until it's answered.

Nobody in the building has done this before

There's no ISMS, no risk register, no Statement of Applicability, and no obvious person to own any of it.

The quotes came back at £20k and six months

Which is real money at your stage, for something you can't yet tell is being done well or badly.

You bought a tool and it didn't help

A dashboard turned green and you still couldn't answer the auditor's third question. The tool was never the hard part.

What the five places include

Twelve weeks, working directly with me, not an account manager.

Gap analysis

Where you actually stand against the standard, in plain English, with the awkward findings included.

A real roadmap

Sequenced to your certification date, not a generic 12-month template.

The ISMS, built

Policies, risk register, Statement of Applicability, evidence — built with you inside the platform, not emailed as templates.

Audit run-up

Readiness review and a rehearsal of the questions the auditor will actually ask.

What it costs

No fee. Not a discount, not a trial that converts, not a rate held back for later. The price is that you let me write up how it went.

  • A short written case study — what the problem was, what we did, what changed
  • Your logo and a quote from you
  • You approve every word before it is published. If you'd rather stay unnamed, we publish it anonymised — I'd still rather work with the right company than the right logo.
  • Certification body audit fees are yours — those are paid direct to your auditor and I can't waive them
  • No obligation to become a paying customer afterwards, and no auto-renewal into one

Who I'm looking for

Five places, and I'd rather turn people away now than three weeks in.

A good fit

  • Pre-Series B, UK or EU
  • A real certification deadline in the next six months — usually a customer's
  • A founder or senior person who can make decisions in the room
  • Able to give a couple of hours a week, early or late
  • Willing to be written about

Not a fit

  • Exploring compliance with no deadline and no driver
  • Needing a certificate in under eight weeks — that isn't a thing I can honestly promise
  • Unable to be named or written about even anonymously
  • Looking for someone to do it entirely for you with no internal owner

How it works

No form, no discovery call with a rep, no sequence of nurture emails.

  1. 1

    You ring me

    0161 327 5077, in one of the windows. Forty-five minutes, and we work out whether this is a fit. If it isn't, I'll tell you on the call and point you somewhere better. Prefer to book a slot? Pick one here.

  2. 2

    Scoping session

    We agree the standard, the deadline and the scope, and I write it down so we both know what we've committed to.

  3. 3

    Twelve weeks of work

    Fortnightly working sessions, early morning or evening, with the platform carrying everything in between.

  4. 4

    The write-up

    We do the case study together at the end, you approve it, and then it goes out.

Who you'd be working with

Simon Green, founder of Sentinel42

I'm Simon Green, founder of Sentinel42. Sixteen years in governance, risk and information security — most of it spent getting organisations through the exact process I'm offering here.

I've taken a UK SaaS provider to ISO 27001 certification and SOC 2 Type 2 attestation as its Head of Information Security, and worked across the NHS, financial services and energy. I sit on the other side of the table too, as a qualified lead auditor — which is the main reason I know which parts of this genuinely matter and which parts are theatre.

  • ISO 27001 Lead Auditor & Implementer
  • ISO 42001 Lead Auditor & Implementer
  • Cyber Essentials Assessor
  • CISM
  • CCSK
  • SC Cleared

Straight answers

Actually free. No fee for my time or for the platform during the twelve weeks, and no obligation afterwards. The only money you'll spend is the certification body's audit fee, which is paid direct to them.

Apply for one of the five

Two minutes. I read every one myself and reply within two working days — including the ones I turn down.

Ring me. You'll get me.

Not a switchboard, not an SDR, not a form that generates an email in four working days.

0161 327 5077

Tuesday & Thursday 7:30–9:00am · Wednesday 5:00–6:30pm — outside those hours, leave a message and I'll ring you back the same day.