08 · Assess · Build · Certify
ISO/IEC 27001 Readiness
A cert-ready ISMS. Not paper compliance.
End-to-end ISO/IEC 27001:2022 readiness — from gap analysis through Statement of Applicability, risk treatment, control implementation, and internal audit. Built with your teams so the ISMS actually runs, and evidenced so your certification body accepts it on the first attempt.
Outcomes
- +A complete Statement of Applicability, justified per Annex A control
- +A Risk Treatment Plan aligned to ISO 27005 methodology
- +Internal Audit + Management Review — Clause 9 evidence
- +A certification-body-ready evidence package
01Scope
What we cover
In scope
- +Full 2022 Annex A control set (93 controls, 4 themes)
- +Clauses 4–10: Context, Leadership, Planning, Support, Operation, Performance, Improvement
- +Statement of Applicability + Risk Treatment Plan
- +Internal Audit Programme (Clause 9.2) execution
- +Management Review evidence pack (Clause 9.3)
- +Documentation set — every policy, procedure, standard, record
Out of scope
- −Third-party certification-body engagement (they audit independently)
02Approach
How the engagement runs
Gap analysis
Where you are vs where ISO 27001:2022 expects you. Every clause, every Annex A control.
ISMS scoping
Physical, logical, and organizational scope of the ISMS. Wrong scope kills more ISO 27001 projects than any control gap.
Risk treatment
ISO 27005-methodology risk assessment, treatment plan, and SoA. Evidenced to a defensible standard.
Control implementation
Design + implement missing controls with your teams. We build with you, not for you.
Internal audit + review
Clause 9.2 internal audit executed, non-conformities logged, Management Review packet delivered.
03Deliverables
What you receive
Every artifact is defensible under external audit and actionable for engineering.
- 01ISO/IEC 27001:2022 Gap Analysis
- 02ISMS Scope Statement
- 03Statement of Applicability
- 04Risk Treatment Plan
- 05Full documentation set (policies, procedures, records)
- 06Internal Audit Report + Management Review packet
04Frameworks
Regulator-defensible mapping
05Timeline
Typical engagement pace
Gap analysis
3–4 weeks
ISMS design + risk treatment
6–8 weeks
Control implementation support
3–6 months
Internal audit + Management Review
3 weeks
06FAQ
Common questions
Different question? Raise it on a scoping call — we'd rather flag surprises early.
How long until we can be certified?+
Typically 6–9 months from kickoff to Stage 1 audit-ready. Faster paths exist for smaller orgs; slower ones for complex, distributed estates.
Do you help us pick a certification body?+
Yes — we advise on accredited CBs (UKAS, ANAB, etc.) and manage introductions. We take no referral commissions.
How is this different from a Security Risk Assessment?+
An SRA is one-shot risk quantification. ISO 27001 is a management system with continuous governance. If certification is your goal, this is the engagement.
Ship an ISO-defensible ISMS.
Scoping call, program plan within 2 weeks, first internal audit inside 6 months for well-scoped orgs.
Book a scoping call