Focus on growth. We’ll handle security.

Security that helps you close deals. We help you understand your risks and secure your systems and processes. Our security experts, backed by our own AI agents, take you through certification and keep it all running efficiently as you grow.

We cover
  • ISO 27001
  • SOC 2
  • ISO 42001
  • NIS2
  • DORA
  • CyFun
  • GDPR
  • EU AI Act
+9 more frameworks
Our team's certifications
  • CISSP
  • CCSP
  • CISA
  • CISM
  • CGEIT
  • CDPSE
  • ISO 27001 Auditor
  • ISO 42001 AuditorAI governance

Sound familiar?

We've been on both sides: building security inside growing companies and reviewing suppliers for regulated ones. We know the questionnaire with a deadline, the deal on hold, the regulation nobody fully understands. Which one is yours?

Your case is different? Let's talk

One path, three stages. Start where you are.

Take the stages in order, or join at the one that fits. Select a service to see what's included.

1Know where you stand

2Get certified

3Stay certified

Security Health Check

For when you want to know where you really stand: how exposed you are to today's risks, which gaps matter most, and whether your security needs strengthening. You finish with a clear picture, a prioritized plan and a budget, whether or not you continue with us.

Typical duration
3–4 days
Price
€3,000

Fee credited in full if you continue with a certification program.

Discuss this on a free call (opens in a new tab)

What we do

  • Assessment of where you stand against ISO 27001, CyFun or the framework you need
  • Scan of your internet-facing systems for known vulnerabilities
  • Prioritized improvement roadmap with effort and owners
  • Indicative budget for the improvement program
  • Management presentation in business language

What stays with you

  • Access to the people who run each area
  • Existing documents and evidence, where they exist

All prices exclude VAT.

ISO 42001 Lead Auditors on the team

AI your customers can trust

Customers, investors and regulators now ask how you govern AI. We build AI governance into the same security program as your ISO 27001, so you answer once and prove it with a certificate.

  • You use AI in your company

    Your team uses AI tools every day. Do you know what data leaves the company?

    We map where AI is used, set clear rules for staff, assess the risks of each tool and vendor, and check what the EU AI Act expects from you as a user of AI.

  • You build AI into your product

    Your customers ask why they should trust your models. Give them proof.

    We classify your system under the EU AI Act, run AI impact assessments and take you to ISO 42001 certification, an answer procurement teams recognize.

More ways to keep your company secure

Additional services, on their own or alongside your program.

  • Add another framework

    Already certified? Map your existing controls to the next framework and plan only the real gap.

  • Audit remediation

    Came out of an audit with nonconformities? We find the root cause and close them within the deadline.

  • Compliance automation platforms

    Help choosing the right platform for your company, on its own or as part of a certification program. Once it's running, we operate it as your Virtual CISO, or your team does.

  • Penetration testing

    Infrastructure, web, mobile, API and cloud testing, with a free retest after you fix the findings.

  • GDPR and DPO as a service

    DPAs, DPIAs, records of processing, or a formally appointed Data Protection Officer.

  • Incident response

    Hands-on investigation, containment and recovery, on retainer or on demand.

  • Managed detection and response

    24/7 monitoring through a specialist partner, integrated with your security program.

  • Cyber insurance support

    Accurate insurer questionnaires, closed control gaps and cover that matches your real risk.

Build security controls once. Reuse them for what comes next.

Already have one framework in place? You don't start the next one from zero. We reuse the policies, controls and evidence you've built and add only what the new standard or regulation requires.

Control areaISO
27001
SOC 2ISO
42001
NIS2DORA
Risk managementCoveredCoveredCoveredCoveredCovered
Access controlCoveredCoveredNot coveredCoveredCovered
Supplier managementCoveredCoveredCoveredCoveredCovered
Incident responseCoveredCoveredNot coveredCoveredCovered
Business continuityCoveredCoveredNot coveredCoveredCovered
AI impact assessmentNot coveredNot coveredCoveredNot coveredNot covered

Swipe sideways to see all frameworks.

All frameworks we work with

Information security
  • ISO 27001
  • SOC 2 Type I
  • SOC 2 Type II
  • CyFun
  • Cyber Essentials
  • Cyber Essentials Plus
EU regulation
  • NIS2
  • DORA
  • GDPR
  • CRA
AI governance
  • ISO 42001
  • EU AI Act
Privacy
  • ISO 27701
Payments
  • PCI DSS
  • PCI PIN
United States
  • HIPAA
  • CCPA
  • CMMC Level 1

Why companies choose ScaleUP Security

  1. We know what your customers will check

    We've worked in some of the most heavily regulated industries, so we know how demanding customers assess their suppliers: the questions they ask, the evidence they accept and the gaps that make them hesitate. We prepare you for exactly that, so the security review helps your deal instead of stalling it.

  2. One team. Every specialist you need.

    No need to hire a GRC analyst, security engineer, internal auditor, penetration tester and CISO. We bring in the right specialist at each stage, from GRC analysts and DevSecOps engineers to senior CISO-level consultants. One senior lead stays with you throughout, so nothing gets lost between specialists.

  3. Only what your business needs

    We don't add controls, tools or policies because they can be sold. Every recommendation answers a real customer, audit or regulatory requirement, or reduces a real risk. If an existing control can be reused or the scope simplified, we tell you.

  4. Clear scope. Clear price. Clear timeline.

    Before work starts, you know what we deliver, when, what we need from your team and what it will cost. Our own AI agents handle routine drafting and reviews, so every expert hour goes where it adds value and you get results sooner. No surprise hours, and early warning if any date is at risk.

About us

ScaleUP Security was founded by two security leaders who have both led programs across ISO 27001, SOC 2 and PCI DSS. Behind them is a team of certified specialists.

  • Portrait of Slava Sklyarenko, co-founder of ScaleUP Security

    Slava Sklyarenko

    Co-founder, security strategy and AI governance

    20+ years in IT, cybersecurity, risk and compliance. Slava has seen what makes security programs succeed or fail, and brings that senior CISO judgment to every engagement while still working hands-on. He brings deep expertise in AI governance and ISO 42001.

  • Portrait of Dmytro (Dima) Cherkas, co-founder of ScaleUP Security

    Dmytro (Dima) Cherkas

    Co-founder, security programs and EU regulation

    8+ years leading security in heavily regulated industries, from Head of Information Security to CISO. A former developer, Dima builds security that fits a fast-moving team: only what you need, run by your own people. He knows NIS2, DORA and GDPR from the inside.

    LinkedIn profile (opens in a new tab)

Our specialist team

Beyond the founders, certified consultants, auditors and engineers from our own team and trusted partners join your project when their expertise is needed.

  • GRC consultants
  • Internal auditors (ISO 27001, ISO 42001)
  • DevSecOps engineers
  • Penetration testers
  • Data protection specialists and DPOs
  • Incident responders

Client stories

Real projects, real outcomes.

Not sure where to start? One call, a clear next step.

30 minutes with a co-founder. Bring your questions, leave with a plan.

You'll speak with Slava or Dima

To make the most of 30 minutes

  • What triggered it: the questionnaire, contract clause, audit or regulation in front of you
  • Your deadline, if there is one
  • A quick picture of your company: team size, product, and where your data and systems live
  • What's already in place, even if it's nothing yet

No preparation required. It just helps us understand your company and your needs, so we can suggest the most pragmatic plan.