Skip to content
The //Zyber// Security
All services

08 · Assess · Build · Certify

ISO/IEC 27001 Readiness

A cert-ready ISMS. Not paper compliance.

End-to-end ISO/IEC 27001:2022 readiness — from gap analysis through Statement of Applicability, risk treatment, control implementation, and internal audit. Built with your teams so the ISMS actually runs, and evidenced so your certification body accepts it on the first attempt.

Outcomes

  • +A complete Statement of Applicability, justified per Annex A control
  • +A Risk Treatment Plan aligned to ISO 27005 methodology
  • +Internal Audit + Management Review — Clause 9 evidence
  • +A certification-body-ready evidence package

01Scope

What we cover

In scope

  • +Full 2022 Annex A control set (93 controls, 4 themes)
  • +Clauses 4–10: Context, Leadership, Planning, Support, Operation, Performance, Improvement
  • +Statement of Applicability + Risk Treatment Plan
  • +Internal Audit Programme (Clause 9.2) execution
  • +Management Review evidence pack (Clause 9.3)
  • +Documentation set — every policy, procedure, standard, record

Out of scope

  • Third-party certification-body engagement (they audit independently)

02Approach

How the engagement runs

01

Gap analysis

Where you are vs where ISO 27001:2022 expects you. Every clause, every Annex A control.

02

ISMS scoping

Physical, logical, and organizational scope of the ISMS. Wrong scope kills more ISO 27001 projects than any control gap.

03

Risk treatment

ISO 27005-methodology risk assessment, treatment plan, and SoA. Evidenced to a defensible standard.

04

Control implementation

Design + implement missing controls with your teams. We build with you, not for you.

05

Internal audit + review

Clause 9.2 internal audit executed, non-conformities logged, Management Review packet delivered.

03Deliverables

What you receive

Every artifact is defensible under external audit and actionable for engineering.

  • 01ISO/IEC 27001:2022 Gap Analysis
  • 02ISMS Scope Statement
  • 03Statement of Applicability
  • 04Risk Treatment Plan
  • 05Full documentation set (policies, procedures, records)
  • 06Internal Audit Report + Management Review packet

04Frameworks

Regulator-defensible mapping

ISO/IEC
27001:202227002:2022 (Guidance)27005:2022 (Risk)27701:2019 (Privacy)
NIST
CSF 2.0 crosswalkSP 800-53 mapping

05Timeline

Typical engagement pace

Phase 01

Gap analysis

3–4 weeks

Phase 02

ISMS design + risk treatment

6–8 weeks

Phase 03

Control implementation support

3–6 months

Phase 04

Internal audit + Management Review

3 weeks

06FAQ

Common questions

Different question? Raise it on a scoping call — we'd rather flag surprises early.

How long until we can be certified?+

Typically 6–9 months from kickoff to Stage 1 audit-ready. Faster paths exist for smaller orgs; slower ones for complex, distributed estates.

Do you help us pick a certification body?+

Yes — we advise on accredited CBs (UKAS, ANAB, etc.) and manage introductions. We take no referral commissions.

How is this different from a Security Risk Assessment?+

An SRA is one-shot risk quantification. ISO 27001 is a management system with continuous governance. If certification is your goal, this is the engagement.

Ship an ISO-defensible ISMS.

Scoping call, program plan within 2 weeks, first internal audit inside 6 months for well-scoped orgs.

Book a scoping call