ISO/IEC 27001 Readiness for a Multi-Tenant Logistics SaaS Platform

Client scenario
Business archetype
Multi-Tenant Logistics SaaS Platform
The scale
Mid-market WMS/TMS SaaS vendor serving dozens of 3PL and fulfillment clients on shared infrastructure.
The objective
Pass an enterprise customer's ISO/IEC 27001 vendor security review within one quarter, without freezing the product roadmap.
The Challenge
Current State
A large prospective customer made ISO/IEC 27001 evidence a hard requirement before signing. The platform had grown for four years without a formal ISMS - access decisions were made ad hoc, by whoever set up a given client's account.
- No documented access control policy - roles were granted by habit, not by design
- Former employees and contractors still had standing access to production systems
- No centralized logging of who accessed which tenant's data, or when
- Security ownership was informally split across two engineers with no other job description for it
“Pain” Point
The immediate pressure was commercial, not technical:
The instinct was to write policy documents to match what the auditor wanted to see. That would have passed a paper review and failed the first real incident.
Hidden Risks
- Multi-tenant data isolation had never been formally tested, only assumed
- Shared admin credentials existed for at least one legacy integration
- No incident response plan existed beyond "call the CTO"
A vendor security review is often the first time these gaps get looked at directly.
Constraints & Risks
Technical Constraints
- One-quarter deadline tied to a live commercial negotiation
- Zero downtime tolerance - the platform could not go offline to fix access control
- Legacy integrations that predated any access control policy
- A small engineering team already at capacity on product work
Operational Risks
- Losing the deal if evidence was not credible, not just present
- Overcorrecting into process that engineers would quietly route around
- Treating this as a one-time audit response instead of a standing capability
Decision & Trade-offs
01. The Core Decision
Run a scoped ISO/IEC 27001 gap assessment against Annex A controls first, before writing a single policy document. The gap assessment became the priority list.
- Access control audit across every production system and integration
- Revocation of standing access for anyone without a current, documented need
- Centralized audit logging for cross-tenant data access
- A named, accountable owner for security - not a shared responsibility
02. The Trade-offs
We prioritized:
- Fixing real access control gaps over drafting comprehensive policy first
- A narrow, verifiable ISMS scope over a company-wide rewrite
- Evidence an auditor could independently verify over self-reported checklists
Feature work continued in parallel. The security work ran as its own sprint track, not a company-wide freeze.
03. Why Not Just Write the Policy Documents?
Because policy documents that describe controls nobody actually runs are worse than no documents - they create liability without reducing risk.
Every policy we wrote described a control that was already implemented and tested, not an aspiration for the next quarter.
Impact
What changed after the engagement.
Operational Outcome
- Access control audit completed and standing access revoked platform-wide
- Centralized, queryable logs for all cross-tenant data access
- A named security owner with defined authority, not a shared afterthought
- An incident response plan tested against a tabletop scenario before go-live
Business Value
- The enterprise deal closed on schedule
- The gap assessment became a reusable ISMS foundation, not a one-time exercise
- Security evidence became a sales asset for later enterprise deals
- Zero disruption to the product roadmap during the engagement
Key Notes
Lessons Learned
What we learned from this engagement.
A gap assessment against a real framework beats writing policy from a template.
Access control debt accumulates silently in fast-growing SaaS teams.
Security ownership needs a name attached to it, not a shared understanding.
Compliance work run as its own sprint track does not have to freeze the roadmap.
“Compliance is a byproduct of good architecture, not a separate project.”
Find out what a vendor security review would find in your systems today.

