Preparing for ISO 27001 certification
ISO 27001 certification is not a set of documents: it calls for a living information security management system, and evidence that it works. Here is how we take you there, without jargon or needless overhead.
An ISMS that holds up, not just on paper
ISO 27001 requires an Information Security Management System (ISMS): governance, a risk assessment, security controls (Annex A) and above all evidence that the whole thing is applied and improved. Many organisations underestimate the gap between "having policies" and "demonstrating they are effective".
Effective preparation starts from what exists, prioritises the gaps by risk, and ties the organisational side (GRC) to concrete technical evidence — which is why it pays to pair the gap analysis with penetration testing and team awareness.
Our role: structure the process, produce the deliverables the auditor expects and take you calmly through to the certification audit.
- A gap between documented policies and actual practice
- Risk assessment absent or unusable
- Annex A controls not covered or not evidenced
- Major non-conformities discovered far too late
- Teams not trained, evidence of effectiveness missing
Roadmap to certification
How we proceed
A clear path, marked out with usable deliverables, matched to the maturity you start from.
Gap analysis
Assessment of your maturity against ISO 27001: coverage of the requirements and of the Annex A controls, identification of the gaps and prioritisation by risk and effort.
Risk assessment & ISMS
Running the risk assessment, defining the scope, the policy and the statement of applicability (SoA), and building the ISMS with its processes.
Technical evidence
Penetration testing to establish the real security level objectively and to feed risk treatment with concrete findings.
Awareness & ownership
Awareness for users and training for key populations: security becomes shared practice and you hold the evidence of effectiveness that is expected.
Mock audit & support
A mock audit to clear the non-conformities before the certification audit, then support during the audit and over time (continuous improvement).
Several disciplines, a single point of contact
The organisational and the technical sides advance together — the condition for a credible ISMS and for certification first time round.
- Prioritised gap analysis report
- Risk assessment and statement of applicability (SoA)
- ISMS policies, procedures and documentation
- Penetration test and awareness reports
- Mock audit report and compliance plan
Frequently asked questions
Aiming for ISO 27001 with confidence?
Let's start with a gap analysis: you will know exactly where you stand and what remains to be done.