Independent External Audit

ISO 27001 Compliance & Certification

Prepare your organization to achieve ISO 27001 certification — the international standard for Information Security Management Systems

We guide your organization through every step of the ISO 27001 journey from gap analysis to certification, including building a complete ISMS, training teams, and preparing all required documentation.

What's included

  • Gap analysis against ISO/IEC 27001:2022 and definition of the ISMS scope, assets and processes
  • Authoring the full documentation hierarchy: the information security policy, standards, operating procedures, and forms and records
  • Building the risk assessment and treatment methodology and preparing the Statement of Applicability for the 93 Annex A controls
  • Implementing the organizational, people, physical and technological controls across the standard's four themes
  • Running the internal audit and management review and closing non-conformities before the certification body audit
  • Team training and awareness and readiness of evidence for the Stage 1 and Stage 2 audits

Methodology & standards

01

Initiation and scoping: define the ISMS boundaries, context and interested parties and their requirements

02

Risk assessment and treatment: apply a risk methodology and produce the treatment plan and the Statement of Applicability

03

Documentation and implementation: author the policies and procedures, implement controls and collect operational evidence

04

Internal audit and review: run an internal audit and a management review and close findings

05

External audit support: accompany you through the Stage 1 and Stage 2 audits up to certification

Deliverables

  • A complete ISMS documentation set (policies, standards, procedures and forms)
  • A documented Statement of Applicability covering each Annex A control with inclusion or exclusion justification
  • The risk register and the risk treatment plan
  • The internal audit report and the management review minutes
  • A non-conformity remediation plan ahead of the certification body
  • An auditor-ready evidence pack and a certification readiness report

Regulatory controls it satisfies

ISO/IEC 27001:2022
Build an ISMS conformant with clauses 4 to 10, with the Statement of Applicability, internal audit and management review
ISO/IEC 27002:2022
Implementation guidance for the 93 Annex A controls across the organizational, people, physical and technological themes
ISO/IEC 27005
The information security risk assessment and treatment methodology underpinning the Statement of Applicability
NCA ECC-2:2024 and SAMA CSF
Align the ISMS documentation with the Saudi frameworks so a single policy set serves more than one regulator

Typical timeline

The project typically spans three to six months to audit readiness, followed by the certification body's two-stage audit on its own schedule.

Common questions

Do you issue the ISO 27001 certificate directly?

No. The certificate is issued solely by an accredited, independent certification body. Our role is to prepare you fully to pass its audit with confidence, and we accompany you through both audit stages.

We already meet NCA controls, do we start from scratch for ISO?

No. We reuse your existing controls through an ISO 27001 to NCA ECC mapping, so what is already implemented is counted once and documented within the Statement of Applicability.