Home / How We Work

─ From Zero to Certified

From zero to certified. Then we keep it that way.

Compliance isn't a one-off project. FeAce breaks it into four clear stages: see where you stand, build the system, get through the audit, then keep it healthy on a subscription. You pay for the stage you're in — nothing more.

─ The Journey

Four stages from zero to certified

Not every company needs all four. We'll tell you honestly where you should start.

01

EXPLORE

Security Health Check — find out where you stand

— Who it's for

You don't know which certificate you need yet. A customer suddenly asked for ISO. You won an RFP and found a security requirement buried in it. Or you just have a feeling your security "needs sorting out" and don't know where to begin.

— The problem it solves

Companies often open with "how much is ISO 27001?" before they know what they're actually missing. Explore answers three questions before you spend real money: where you are, what's missing, and where to start.

— What you get

A gap analysis against ISO 27001 / 42001 / SOC 2 or similar frameworks, an inventory of your security risk gaps, a plain-language "do this now, this can wait" recommendation report, and a 30–60 minute readout. No 200-page binder — just what's worth doing next, given your size and resources.

— What happens next

The report shows your gaps clearly. If you decide to go ahead, we move into Build. If you're not ready, we'll tell you — some companies genuinely don't need ISO yet.

01

EXPLORE

Cybersecurity Health Check

First, let's see where you are now.

— Who is suitable?

You're still unsure which certificate you need. It could be that a client suddenly requests ISO certification, you only discover a cybersecurity threshold after taking on a project, or you simply feel that "the company's cybersecurity needs to be improved," but don't know where to start.

— This stage solves the problem

Many companies immediately ask, "How much does ISO 27001 cost?", but they don't even know what they're lacking. The Explore stage helps you understand three things before spending a lot of money on implementation: where you are now, what you lack, and what you should do first.

— Content

The presentation will include: a current status quo analysis (compare with target standards such as ISO 27001 / 42001 / SOC 2), a cybersecurity risk gap assessment, a plain-language report outlining "what to do and what not to rush," and a 30-60 minute results presentation meeting. We won't give you a technical report you can't understand; instead, we'll tell you what the most worthwhile next step is, given your scale and needs.

— Next step

Your health check report will clearly indicate your shortcomings. If you decide to take the necessary steps, we'll guide you through the Build process. If you're not ready yet, we'll be honest with you—for some companies, ISO isn't actually their top priority.

02

BUILD

Implementation — build a system that actually works

— Who it's for

You know which certificate you need — a customer asked, an RFP requires it, or you're expanding overseas — but nobody in-house has done this before. You need a consultant to build the whole thing from scratch, and it has to work in practice, not just on paper.

— The problem it solves

Most companies are stuck at "there is no system." Build doesn't just produce documents. We stand up the system, train your people, and wire it into the tools you already use.

— What you get

Full implementation (ISO 27001 / 27701 / 27017 / 27018 / 42001 / SOC 2 / TISAX and more), risk assessment and treatment planning, the Statement of Applicability (SoA), policies and procedures, internal audit, staff training, two consultants throughout (lead and deputy, with clean hand-over if the lead is away), and integration with existing platforms like Microsoft 365 and Entra ID. The access controls and logging ISO asks for won't just sit in a Word file — they'll be live in your systems.

— What happens next

System built, documents in place, staff trained. You're ready for Certify — the certification body's formal audit.

02

BUILD

Import from scratch

Guide you to establish a complete system

— Who is suitable?

You've decided to obtain a certain certificate (due to client requirements, project needs, or group compliance pressures), but your company lacks internal experience in implementing it and needs a consultant to guide you in building the entire system from scratch. This is the core service that most of Feiais's clients choose.

— This stage solves the problem

ISO isn't just about buying a template and copying it. You need someone to help you with risk assessments, write policies and procedures that fit your company's actual operations, establish record-keeping mechanisms, train employees, and accompany you during internal audits to identify problems. The "Build" stage is about turning "a stack of international standard clauses" into "systems that your company can actually run."

— Content

Comprehensive system establishment (ISO 27001 / 27701 / 27017 / 27018 / 42001 / SOC 2 / TISAX scope selection), risk assessment and risk management plan, Statement of Applicability (SoA), policy and procedure document drafting, internal audit support, and employee training. A dual-consultant setup (primary consultant   associate consultant) is provided throughout the process, with the associate consultant seamlessly taking over when the primary consultant is away. If your company uses Microsoft 365, we will work with your IT team to map the access controls required by ISO to the actual Entra ID settings—ensuring that the system is not just written in Word, but truly operational within the system.

— Next step

Once the system is in place, the documents are complete, and the employees have received training, you are ready to enter Certify—to face a formal audit by a verification agency.

03

CERTIFY

Certification — get the certificate in hand

— Who it's for

Two kinds of company. Those who've done Build with us and are heading into the audit. And those who built half the system themselves, have the audit coming up, and aren't sure they'll pass — they need someone to check and shore it up in the final stretch.

— The problem it solves

Plenty of companies get the system mostly right, then stumble at the audit because they don't know how certification bodies work — the documents exist, but they don't line up. Certify makes sure you don't just look ready. You are ready.

— What you get

Document review and remediation, a mock audit run from the certification body's point of view, nonconformities fixed before the auditor finds them, and a consultant beside you on audit day. We know what auditors look at and what they'll ask. That's the most direct payoff of years spent doing this.

— What happens next

The certificate isn't the finish line. It's where Scale begins.

03

EXPLORE

Cybersecurity Health Check

First, let's see where you are now.

— Who is suitable?

You're still unsure which certificate you need. It could be that a client suddenly requests ISO certification, you only discover a cybersecurity threshold after taking on a project, or you simply feel that "the company's cybersecurity needs to be improved," but don't know where to start.

— This stage solves the problem

Many companies immediately ask, "How much does ISO 27001 cost?", but they don't even know what they're lacking. The Explore stage helps you understand three things before spending a lot of money on implementation: where you are now, what you lack, and what you should do first.

— Content

The presentation will include: a current status quo analysis (compare with target standards such as ISO 27001 / 42001 / SOC 2), a cybersecurity risk gap assessment, a plain-language report outlining "what to do and what not to rush," and a 30-60 minute results presentation meeting. We won't give you a technical report you can't understand; instead, we'll tell you what the most worthwhile next step is, given your scale and needs.

— Next step

Your health check report will clearly indicate your shortcomings. If you decide to take the necessary steps, we'll guide you through the Build process. If you're not ready yet, we'll be honest with you—for some companies, ISO isn't actually their top priority.

04

SCALE

Ongoing — stay certified and expand

— Who it's for

Companies that already hold a certificate. ISO isn't one-and-done: surveillance audits every year, recertification every three, and the system has to be kept alive in between. Regulations move. And once you have one certificate, customers tend to ask for the next. Scale means no annual hunt for a consultant and no starting from zero each time.

— The problem it solves

The classic story: a company invests in ISO 27001, and a year later — surveillance audit weeks away — discovers the documents weren't updated, the records weren't kept, and the person who owned it has left. Scale turns the once-a-year scramble into business as usual.

— What you get

Surveillance-audit preparation, document upkeep, continuous compliance monitoring with FeAce's own tooling, regulatory-change alerts, roll-out of additional standards, and at the top tier, vCISO (part-time CISO) services.

04

EXPLORE

Cybersecurity Health Check

First, let's see where you are now.

— Who is suitable?

You're still unsure which certificate you need. It could be that a client suddenly requests ISO certification, you only discover a cybersecurity threshold after taking on a project, or you simply feel that "the company's cybersecurity needs to be improved," but don't know where to start.

— This stage solves the problem

Many companies immediately ask, "How much does ISO 27001 cost?", but they don't even know what they're lacking. The Explore stage helps you understand three things before spending a lot of money on implementation: where you are now, what you lack, and what you should do first.

— Content

The presentation will include: a current status quo analysis (compare with target standards such as ISO 27001 / 42001 / SOC 2), a cybersecurity risk gap assessment, a plain-language report outlining "what to do and what not to rush," and a 30-60 minute results presentation meeting. We won't give you a technical report you can't understand; instead, we'll tell you what the most worthwhile next step is, given your scale and needs.

─ Stay Certified

After certification, we're still here

Choose how involved you want us to be. On a subscription, you never have to find a new consultant each year or start a new certificate from scratch.

Plan 01

Steady

Keep the certificate you have


"I just want to keep the certificate — not start from scratch every year."


Best for: certified companies with basic security staff in place, who mainly need each surveillance audit to go smoothly.

  • Surveillance-audit preparation and on-site support
  • Annual document updates
  • Regulation and standard-revision alerts
  • Compliance consulting (fixed annual hours)

 $$/Year

Inquire

Most popular

Plan 02

Grow

Keep expanding your compliance footprint


"We'll be adding more standards over time."


Best for: certified, growing companies that expect to add standards as customers and markets demand.

  • roprietary tool)
  • Everything in Steady
  • Exclusive discount on additional standards (e.g. extending 27001 to 27701, 42001, SOC 2)
  • Quarterly compliance health-check report
  • Annual staff security training
  • Double the consulting hours
  • Automated ISMS compliance monitoring (FeAce platform)

 $$$/ Year

Inquire

Plan 03

Co-Pilot

Leave day-to-day security to us and run your business


"We don't have a CISO and can't afford a full-time one. Be our co-pilot."


Best for: SMBs without a dedicated security hire that still need professional security governance; or fast-growing startups whose security needs have outgrown the team.

  • Everything in Grow
  • Regular attendance at security-governance meetings, with professional recommendations
  • Fixed monthly consulting hours
  • Draft responses to customer security questionnaires
  • Incident consulting and process guidance
  • Board / investor security reports

 $$$$/ Year

Inquire

Co-Pilot doesn't mean handing over the controls — you're still the captain. We sit beside you: flagging risks early, advising, sharing the workload. Where you fly is your call. FeAce acts as security advisor and provides professional consulting and recommendations; decision-making and execution authority remain with your company. The full scope of responsibilities is defined in the service agreement.

─ FAQ

Questions people ask before starting



  • Q1 Roughly how much does ISO 27001 cost, and how long does it take?

    For most SMBs, consulting fees for an ISO 27001 implementation fall between NT$400,000 and NT$700,000 (roughly US$13,000–23,000, before tax). The exact figure depends on company size, scope complexity, number of sites, and your choice of certification body.


    That fee covers building the management system, tailoring the documentation, risk assessment, internal audit, and being at your side on audit day. What you get is a system designed around how your company actually operates — not a boilerplate template with your logo on it. (Consulting fees and the certification body's audit fees are quoted separately; we'll walk you through both.)


    On timing: small teams typically take 3–4 months, a typical SMB about 6 months, and public companies or multi-site organizations 6–9 months. The biggest variable is whether you have a dedicated point of contact in-house. We start with a health check to confirm the actual scope, then give you a transparent, fixed quote — no surprise add-ons.


  • Q2 What if we don't pass the audit?

     This is what worries most companies — you've invested the money and the time, and the last thing you want is to get stuck on audit day.


    Our approach: before the formal audit, we run a mock audit from the certification body's point of view, surface the likely nonconformities, and fix them ahead of time. On audit day, we're in the room with you the whole way.


    Several of our team come from certification bodies themselves. They know exactly what auditors look at — which is why we can bring your risk down to a minimum.


  • Q3 How much of our own people's time will this take?

    You'll need to assign one internal point of contact to provide information, coordinate across departments, and sign off on documents. Ideally that person can commit consistent time — the project moves faster and the timeline stays predictable.


    That said, we know SMBs run lean. Even if your point of contact is part-time, we proactively track progress and carry the consultant's share of the work, so your team can stay focused on the business.


  • Q4 How are you different from other consultants?

    Three things. 


    First, every consultant you deal with is a senior practitioner — you won't get a polished sales pitch and then a junior showing up to do the work.


    Second, we come from technical backgrounds. We don't just deliver documents; we help you get the controls configured in Microsoft 365, Entra ID, and the other systems you use every day. 


    Third, we handle the newer standards — ISO 42001, TISAX, SOC 2 — and not many consultancies in the market can.


    That said, we're not the right fit for every company. If what you need isn't what we do best, we'll tell you straight and point you toward the kind of consultant who is.


  • Q5 Once we're certified, is that it?

    No. An ISO certificate has to be maintained — a surveillance audit every year and recertification every three. 


    If nobody's watching the system, companies tend to discover right before the audit that the documents and records have fallen behind.


    Most clients stay on with us after certification and have us handle ongoing operations — after all, the people who built your system know it best. How far that relationship goes is up to you.

- Contact Us

Leave your information

We will send you our initial assessment.

No need to schedule a time or make a phone call—just fill out this form, and we will reply with preliminary suggestions and a general quote within one business day, depending on your situation.

Email

service@feaceint.com

Office

5th Floor, No. 390, Section 1, Wenhua 2nd Road, Linkou District, New Taipei City



Contact Us

The information you provide will only be used to assess needs, make contacts, and provide preliminary suggestions. The preliminary assessment and quotation direction are for reference only and do not constitute a formal quotation or service commitment. The actual quotation or contract between both parties shall prevail.

We will reply within one business day.

- Contact

Leave your details. We'll come back with a first assessment.

No call, no meeting needed. Fill in the form and within one business day you'll have our initial take and a rough idea of pricing

Email

service@feaceint.com

Office

5F, No. 390, Sec. 1, Wenhua 2nd Rd., Linkou Dist., New Taipei City, Taiwan (R.O.C.)



Contact Us

Your details are used only to assess your needs, contact you and provide initial advice. Initial assessments and pricing directions are indicative only and do not constitute a formal quote or service commitment; a written quotation or contract prevails.

We'll get back to you within one business day.