Certify Your Security Programme
ISO 27001 Certification and ISMS Consulting
ISO 27001 is the global benchmark for managing information security. We take you from first gap assessment to a certified ISMS, and stay with you through the audit and beyond.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
ISO/IEC 27001 sets out how to run an information security management system, or ISMS: a living set of policies, controls, and risk decisions that protect your data. Certification tells customers and partners that an independent auditor checked your security and signed off. It matters because more contracts now demand it, and because the discipline genuinely lowers your risk. We help you build an ISMS that fits how you actually work, not a binder that sits on a shelf.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the ISO 27001 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Gap Assessment. We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead. Activities: Define the ISMS scope and boundaries; Interview control owners across teams; Assess maturity against clauses 4 to 10; Test current state against the 93 Annex A controls; Rank gaps by effort and risk. Hands over Gap Assessment Report. Phase 2, Risk Assessment and Treatment. We run a structured risk assessment and agree how you treat each risk. This feeds your Statement of Applicability and risk treatment plan. Activities: Build the asset and risk inventory; Score risks by likelihood and impact; Agree treat, tolerate, transfer, or terminate for each; Select applicable Annex A controls; Draft the Statement of Applicability. Hands over Risk Treatment Plan and Statement of Applicability. Phase 3, Control Design and Documentation. We design the policies, procedures, and controls you need. Everything maps back to a clause or an Annex A control so nothing is orphaned. Activities: Draft the information security policy set; Write procedures for access, change, and incidents; Map every document to a clause or control; Define roles and the risk acceptance criteria. Hands over ISMS Policy and Procedure Set. Phase 4, Implementation Support. We help you roll out controls and start collecting evidence. You build the day-to-day habits that keep the ISMS running. Activities: Roll out controls across in-scope systems; Configure a compliance platform for evidence; Run security awareness training; Start access reviews and log collection. Hands over Operating Controls and Evidence Trail. Phase 5, Internal Audit and Management Review. We run an internal audit, log findings, and prepare your management review. This is your dress rehearsal before the certification body arrives. Activities: Plan and run the internal audit programme; Log nonconformities and corrective actions; Prepare management review inputs; Verify remediation before certification. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification and Surveillance. We support you through Stage 1 and Stage 2 audits, then help you sustain the ISMS across annual surveillance visits. Activities: Prepare evidence for the Stage 1 documentation review; Support the Stage 2 certification audit; Close any audit findings raised; Plan annual surveillance and continual improvement. Hands over ISO 27001 Certificate. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Gap Assessment
We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.
What Happens In This Phase
- Define the ISMS scope and boundaries
- Interview control owners across teams
- Assess maturity against clauses 4 to 10
- Test current state against the 93 Annex A controls
- Rank gaps by effort and risk
The Handover
Gap Assessment Report
The next phase starts from this.
Phase 01 Scoping and Gap Assessment
We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.
What Happens In This Phase
- Define the ISMS scope and boundaries
- Interview control owners across teams
- Assess maturity against clauses 4 to 10
- Test current state against the 93 Annex A controls
- Rank gaps by effort and risk
The Handover
Gap Assessment Report
The next phase starts from this.
- 01
Scoping and Gap Assessment
We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.
OutputGap Assessment ReportActivities
- Define the ISMS scope and boundaries
- Interview control owners across teams
- Assess maturity against clauses 4 to 10
- Test current state against the 93 Annex A controls
- Rank gaps by effort and risk
- 02
Risk Assessment and Treatment
We run a structured risk assessment and agree how you treat each risk. This feeds your Statement of Applicability and risk treatment plan.
OutputRisk Treatment Plan and Statement of ApplicabilityActivities
- Build the asset and risk inventory
- Score risks by likelihood and impact
- Agree treat, tolerate, transfer, or terminate for each
- Select applicable Annex A controls
- Draft the Statement of Applicability
- 03
Control Design and Documentation
We design the policies, procedures, and controls you need. Everything maps back to a clause or an Annex A control so nothing is orphaned.
OutputISMS Policy and Procedure SetActivities
- Draft the information security policy set
- Write procedures for access, change, and incidents
- Map every document to a clause or control
- Define roles and the risk acceptance criteria
- 04
Implementation Support
We help you roll out controls and start collecting evidence. You build the day-to-day habits that keep the ISMS running.
OutputOperating Controls and Evidence TrailActivities
- Roll out controls across in-scope systems
- Configure a compliance platform for evidence
- Run security awareness training
- Start access reviews and log collection
- 05
Internal Audit and Management Review
We run an internal audit, log findings, and prepare your management review. This is your dress rehearsal before the certification body arrives.
OutputInternal Audit Report and Management Review RecordActivities
- Plan and run the internal audit programme
- Log nonconformities and corrective actions
- Prepare management review inputs
- Verify remediation before certification
- 06
Certification and Surveillance
We support you through Stage 1 and Stage 2 audits, then help you sustain the ISMS across annual surveillance visits.
OutputISO 27001 CertificateActivities
- Prepare evidence for the Stage 1 documentation review
- Support the Stage 2 certification audit
- Close any audit findings raised
- Plan annual surveillance and continual improvement
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the ISO 27001 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Sprinto, Scrut, Jira, Confluence, OneTrust, Microsoft Purview. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27001 Annex A, ISO/IEC 27005, ISO/IEC 27017, NIST CSF.
What We Run
8 tools
- Drata
- Sprinto
- Microsoft Purview
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
Deliverables
What You Receive
- Gap assessment report
- Statement of Applicability
- Risk treatment plan
- ISMS policy and procedure set
- Certification audit support
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How long does ISO 27001 certification take?
Most organisations reach certification in three to six months, depending on your size and how many controls already exist. We give you a realistic timeline after the gap assessment.
What is the Statement of Applicability?
It is the document that lists every Annex A control, says whether you apply it, and explains why. Auditors read it closely, so we help you get it right.
What is the difference between Stage 1 and Stage 2 audits?
Stage 1 checks that your documents and ISMS design are ready. Stage 2 tests whether your controls actually work in practice. You need to pass both.
Keep Moving Through Compliance
Service 1 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.