Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Compliance & governance

Preparing for ISO 27001 certification

ISO 27001 certification is not a set of documents: it calls for a living information security management system, and evidence that it works. Here is how we take you there, without jargon or needless overhead.

The challenge

An ISMS that holds up, not just on paper

ISO 27001 requires an Information Security Management System (ISMS): governance, a risk assessment, security controls (Annex A) and above all evidence that the whole thing is applied and improved. Many organisations underestimate the gap between "having policies" and "demonstrating they are effective".

Effective preparation starts from what exists, prioritises the gaps by risk, and ties the organisational side (GRC) to concrete technical evidence — which is why it pays to pair the gap analysis with penetration testing and team awareness.

Our role: structure the process, produce the deliverables the auditor expects and take you calmly through to the certification audit.

What is at stake
  • A gap between documented policies and actual practice
  • Risk assessment absent or unusable
  • Annex A controls not covered or not evidenced
  • Major non-conformities discovered far too late
  • Teams not trained, evidence of effectiveness missing
Diagram

Roadmap to certification

Roadmap to ISO 27001 certification AssessBuildProveCertify1Gapanalysis2Riskassessment3ISMS &policies4Penetrationtesting5Awarenesstraining6MockauditCertifi-cation
From gap analysis to certification, within a continuous improvement loop (PDCA).
Our approach

How we proceed

A clear path, marked out with usable deliverables, matched to the maturity you start from.

01

Gap analysis

Assessment of your maturity against ISO 27001: coverage of the requirements and of the Annex A controls, identification of the gaps and prioritisation by risk and effort.

02

Risk assessment & ISMS

Running the risk assessment, defining the scope, the policy and the statement of applicability (SoA), and building the ISMS with its processes.

03

Technical evidence

Penetration testing to establish the real security level objectively and to feed risk treatment with concrete findings.

04

Awareness & ownership

Awareness for users and training for key populations: security becomes shared practice and you hold the evidence of effectiveness that is expected.

05

Mock audit & support

A mock audit to clear the non-conformities before the certification audit, then support during the audit and over time (continuous improvement).

Services involved

Several disciplines, a single point of contact

The organisational and the technical sides advance together — the condition for a credible ISMS and for certification first time round.

Deliverables
  • Prioritised gap analysis report
  • Risk assessment and statement of applicability (SoA)
  • ISMS policies, procedures and documentation
  • Penetration test and awareness reports
  • Mock audit report and compliance plan
Frequently asked questions

Frequently asked questions

It depends on the maturity you start from and on the scope. After the gap analysis we set out a realistic roadmap; expect anything from a few months to a little over a year to build the ISMS, gather the evidence and pass the audit.

Because ISO 27001 asks for evidence of effectiveness, not only documents. Penetration testing establishes the real security level objectively, feeds the risk assessment and demonstrates that the controls work.

No, and that is deliberate: certification is issued by an independent accredited body. Our role is to prepare you and support you up to the audit; keeping preparation and certification separate guarantees objectivity.

It is a good starting point, but rarely enough. The gap analysis checks that your policies cover the requirements, are genuinely applied and can be evidenced. We start from what exists so as not to rebuild what already works.

Aiming for ISO 27001 with confidence?

Let's start with a gap analysis: you will know exactly where you stand and what remains to be done.