We guide your organization through every step of the ISO 27001 journey from gap analysis to certification, including building a complete ISMS, training teams, and preparing all required documentation.
What's included
- Gap analysis against ISO/IEC 27001:2022 and definition of the ISMS scope, assets and processes
- Authoring the full documentation hierarchy: the information security policy, standards, operating procedures, and forms and records
- Building the risk assessment and treatment methodology and preparing the Statement of Applicability for the 93 Annex A controls
- Implementing the organizational, people, physical and technological controls across the standard's four themes
- Running the internal audit and management review and closing non-conformities before the certification body audit
- Team training and awareness and readiness of evidence for the Stage 1 and Stage 2 audits
Methodology & standards
Initiation and scoping: define the ISMS boundaries, context and interested parties and their requirements
Risk assessment and treatment: apply a risk methodology and produce the treatment plan and the Statement of Applicability
Documentation and implementation: author the policies and procedures, implement controls and collect operational evidence
Internal audit and review: run an internal audit and a management review and close findings
External audit support: accompany you through the Stage 1 and Stage 2 audits up to certification
Deliverables
- A complete ISMS documentation set (policies, standards, procedures and forms)
- A documented Statement of Applicability covering each Annex A control with inclusion or exclusion justification
- The risk register and the risk treatment plan
- The internal audit report and the management review minutes
- A non-conformity remediation plan ahead of the certification body
- An auditor-ready evidence pack and a certification readiness report
Regulatory controls it satisfies
Typical timeline
The project typically spans three to six months to audit readiness, followed by the certification body's two-stage audit on its own schedule.
Common questions
Do you issue the ISO 27001 certificate directly?
No. The certificate is issued solely by an accredited, independent certification body. Our role is to prepare you fully to pass its audit with confidence, and we accompany you through both audit stages.
We already meet NCA controls, do we start from scratch for ISO?
No. We reuse your existing controls through an ISO 27001 to NCA ECC mapping, so what is already implemented is counted once and documented within the Statement of Applicability.