Home / How We Work
─ From Zero to Certified
From zero to certified. Then we keep it that way.
Compliance isn't a one-off project. FeAce breaks it into four clear stages: see where you stand, build the system, get through the audit, then keep it healthy on a subscription. You pay for the stage you're in — nothing more.
─ The Journey
Four stages from zero to certified
Not every company needs all four. We'll tell you honestly where you should start.
─ Stay Certified
After certification, we're still here
Choose how involved you want us to be. On a subscription, you never have to find a new consultant each year or start a new certificate from scratch.
Plan 01
Steady
Keep the certificate you have
"I just want to keep the certificate — not start from scratch every year."
Best for: certified companies with basic security staff in place, who mainly need each surveillance audit to go smoothly.
- Surveillance-audit preparation and on-site support
- Annual document updates
- Regulation and standard-revision alerts
- Compliance consulting (fixed annual hours)
$$/Year
Most popular
Plan 02
Grow
Keep expanding your compliance footprint
"We'll be adding more standards over time."
Best for: certified, growing companies that expect to add standards as customers and markets demand.
- roprietary tool)
- Everything in Steady
- Exclusive discount on additional standards (e.g. extending 27001 to 27701, 42001, SOC 2)
- Quarterly compliance health-check report
- Annual staff security training
- Double the consulting hours
- Automated ISMS compliance monitoring (FeAce platform)
$$$/ Year
Plan 03
Co-Pilot
Leave day-to-day security to us and run your business
"We don't have a CISO and can't afford a full-time one. Be our co-pilot."
Best for: SMBs without a dedicated security hire that still need professional security governance; or fast-growing startups whose security needs have outgrown the team.
- Everything in Grow
- Regular attendance at security-governance meetings, with professional recommendations
- Fixed monthly consulting hours
- Draft responses to customer security questionnaires
- Incident consulting and process guidance
- Board / investor security reports
$$$$/ Year
Co-Pilot doesn't mean handing over the controls — you're still the captain. We sit beside you: flagging risks early, advising, sharing the workload. Where you fly is your call. FeAce acts as security advisor and provides professional consulting and recommendations; decision-making and execution authority remain with your company. The full scope of responsibilities is defined in the service agreement.
─ FAQ
Questions people ask before starting
Q1 Roughly how much does ISO 27001 cost, and how long does it take?
For most SMBs, consulting fees for an ISO 27001 implementation fall between NT$400,000 and NT$700,000 (roughly US$13,000–23,000, before tax). The exact figure depends on company size, scope complexity, number of sites, and your choice of certification body.
That fee covers building the management system, tailoring the documentation, risk assessment, internal audit, and being at your side on audit day. What you get is a system designed around how your company actually operates — not a boilerplate template with your logo on it. (Consulting fees and the certification body's audit fees are quoted separately; we'll walk you through both.)
On timing: small teams typically take 3–4 months, a typical SMB about 6 months, and public companies or multi-site organizations 6–9 months. The biggest variable is whether you have a dedicated point of contact in-house. We start with a health check to confirm the actual scope, then give you a transparent, fixed quote — no surprise add-ons.
Q2 What if we don't pass the audit?
This is what worries most companies — you've invested the money and the time, and the last thing you want is to get stuck on audit day.
Our approach: before the formal audit, we run a mock audit from the certification body's point of view, surface the likely nonconformities, and fix them ahead of time. On audit day, we're in the room with you the whole way.
Several of our team come from certification bodies themselves. They know exactly what auditors look at — which is why we can bring your risk down to a minimum.
Q3 How much of our own people's time will this take?
You'll need to assign one internal point of contact to provide information, coordinate across departments, and sign off on documents. Ideally that person can commit consistent time — the project moves faster and the timeline stays predictable.
That said, we know SMBs run lean. Even if your point of contact is part-time, we proactively track progress and carry the consultant's share of the work, so your team can stay focused on the business.
Q4 How are you different from other consultants?
Three things.
First, every consultant you deal with is a senior practitioner — you won't get a polished sales pitch and then a junior showing up to do the work.
Second, we come from technical backgrounds. We don't just deliver documents; we help you get the controls configured in Microsoft 365, Entra ID, and the other systems you use every day.
Third, we handle the newer standards — ISO 42001, TISAX, SOC 2 — and not many consultancies in the market can.
That said, we're not the right fit for every company. If what you need isn't what we do best, we'll tell you straight and point you toward the kind of consultant who is.
Q5 Once we're certified, is that it?
No. An ISO certificate has to be maintained — a surveillance audit every year and recertification every three.
If nobody's watching the system, companies tend to discover right before the audit that the documents and records have fallen behind.
Most clients stay on with us after certification and have us handle ongoing operations — after all, the people who built your system know it best. How far that relationship goes is up to you.





