How COMMITLY built its ISMS and achieved ISO 27001 certification with Copla

Cash flow management platform

Austria

ISO 27001 certification

“ISO 27001 gives our customers and partners additional confidence that security is embedded in how COMMITLY operates. Copla gave us the expertise and hands-on support needed to complete the certification without building the entire process internally.”

Jürgen Faè, Founder and CEO, COMMITLY

The challenge

Turning customer expectations into a structured security management system

COMMITLY is a cash flow management platform that helps businesses connect financial data, monitor liquidity, build forecasts, and make better financial decisions.

Because its platform brings together sensitive financial information from banks, accounting systems, and other business applications, security and trust are fundamental to COMMITLY’s relationship with its customers.

As COMMITLY grew, customers and investors increasingly expected the company to demonstrate its security standards through an internationally recognised certification. Achieving ISO 27001 therefore became more than an internal security initiative: it was an important commercial milestone that could support customer confidence and future growth.

However, COMMITLY did not have a dedicated internal function to interpret every ISO 27001 requirement, create the necessary documentation, establish the required registers, gather evidence, and coordinate the audit process.

The solution

From manual preparation to a guided certification process

To achieve certification, COMMITLY needed to establish a complete Information Security Management System (ISMS) – a structured system of policies, responsibilities, risk-management processes, registers, controls and evidence showing how information security is managed across the company. Building this internally would have required significant time and specialist knowledge.

After meeting at an event in Frankfurt, COMMITLY selected Copla to guide the company through its ISO 27001 certification.

A dedicated Copla CISO worked directly with COMMITLY’s CTO, taking responsibility for structuring the certification journey and helping the team translate ISO 27001 requirements into practical policies and processes.

Copla supported COMMITLY with:

 

Instead of leaving COMMITLY to interpret the standard and build everything independently, Copla provided hands-on expertise throughout the project. Copla adapted the process to COMMITLY’s capacity, allowing the team to complete the required activities without taking focus away from product development and business growth.

“Copla helped us understand what was required, prepared the core documentation and guided us through the evidence and audit process. That gave us a clear path to certification while keeping the workload manageable for our internal team.”

Jürgen Faè, Founder and CEO, COMMITLY

The result

ISO 27001 certified within a few months

Within approximately four months, COMMITLY had established its ISMS and successfully completed its ISO 27001 certification audit. The result was not only a certificate, but a structured system for managing security risks, responsibilities, controls and evidence across the business.

The company completed the required documentation, registers, evidence collection and internal audit before successfully proceeding through the external certification audit.

For a growing technology team, Copla’s support provided access to experienced security leadership without the need to recruit a full-time CISO or build the entire certification process from scratch.

Most importantly, COMMITLY gained independent validation of its approach to information security – a recognised signal of trust for customers, partners and investors.

Looking ahead

Certification is the beginning of an ongoing process

ISO 27001 certification is valid for three years, but certified companies must complete annual surveillance audits to demonstrate that their information security management system continues to operate effectively.

This means maintaining registers, completing recurring security activities, gathering evidence and ensuring that the processes described in the company’s policies are consistently followed.

Following certification, COMMITLY began putting these recurring activities into practice and preparing for the next surveillance audit. This ongoing stage is essential: the objective is not simply to create documentation for an audit, but to ensure that security controls become part of everyday operations.

“Achieving certification was an important milestone, but ISO 27001 does not end when the certificate is issued. The next step is making sure our ISMS remains active and that we are continuously ready for future surveillance audits.”

Jürgen Faè, Founder and CEO, COMMITLY

Built for trust

ISO 27001 is a recognised security standard that strengthens confidence with customers, partners and investors.

Cash flow management platform · Austria

Ready to build your ISO 27001 ISMS?

See how Copla helps you prepare for certification, manage your ISMS and stay audit-ready after certification.