Zero trust sounds enterprise, but for SaaS-heavy SMEs it means identity, device posture and least privilege per app — not a big-bang network project.
Realistic roadmap
- Identity: MFA everywhere, no shared admin accounts, HR ↔ IAM lifecycle.
- Devices: laptop baseline (patch, encryption, MDM where needed).
- Apps: per SaaS: who has which role, quarterly access review.
- Logging: central source for login and admin actions.
ISO 27001 link
Map zero-trust measures to Annex A. Document in SoA how you enforce least privilege in cloud. More: ISO 27001 for SaaS and ISMS.
For SMEs in 2026 conditional access and MFA on all cloud apps deliver highest return: blocks most account takeover without new hardware. Record policy and show quarterly access reviews in sample period.
Device posture can start with encryption and patch compliance on laptops — full MDM is not always needed on day one. Document in risk assessment which devices access which data classes.
Least privilege per SaaS: export role matrix from IdP and top five apps, remove orphaned accounts after offboarding. Auditors sample one departed employee and one admin account.
Identity-first without big bang
For many SMEs the identity provider is the real network: Microsoft Entra ID, Google Workspace or Okta decide who reaches which SaaS. Invest there first in conditional access, MFA and HR lifecycle before expanding office network segmentation.
Per critical SaaS, maintain a role overview: default role, admin role, external access and review frequency. Quarterly access reviews need not be hour-long projects — an export plus line-manager sampling is enough if you document the process.
Admin action logs in cloud apps belong in the same retention as VPN and firewall logs. Auditors cross-check: if someone gets admin rights in Salesforce, that must appear in IdP and application logs.
Document in the SoA which zero-trust measures you choose as risk treatment and which you deliberately defer — with rationale and planned date. That beats putting zero trust on paper without execution.
Start with your top three SaaS apps by data sensitivity — not the entire landscape at once. Success there convinces leadership faster than a thirty-page zero-trust roadmap. Measure before and after: admin account count, orphaned users, MFA coverage.
Identity-first measurement
Start with your top three SaaS apps by data sensitivity — not the entire landscape at once. Measure before and after: admin accounts, orphaned users, MFA coverage. Success there convinces leadership faster than a thirty-page roadmap.
Conditional access and MFA on all cloud apps deliver the highest return for SMEs in 2026. Document policy and show quarterly access reviews in sample period.
Admin action logs in cloud apps belong in the same retention as VPN logs. Auditors cross-check IdP and application logs in samples.
Next steps in your ISMS
Turn this article into one concrete action in your risk register or improvement plan: owner, deadline, expected evidence. Discuss progress in the next management review — auditors and chain partners want decisions, not policy intent alone. Link where possible to existing ISO 27001, NIS2 or GDPR documentation so you do not maintain parallel folders.
Questions on scope, certification or chain requirements? Use our readiness overview and knowledge base for deeper guidance. This article does not replace legal or audit advice for your situation.
Share relevant findings briefly with line management and procurement — compliance becomes workable when the whole organisation recognises the same priorities. Repeat the chosen action quarterly in team meetings and update evidence locations in your SoA or control plan so surveillance samples are easy to answer.
