Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Certify Your Security Programme

ISO 27001 Certification and ISMS Consulting

ISO 27001 is the global benchmark for managing information security. We take you from first gap assessment to a certified ISMS, and stay with you through the audit and beyond.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

ISO/IEC 27001 sets out how to run an information security management system, or ISMS: a living set of policies, controls, and risk decisions that protect your data. Certification tells customers and partners that an independent auditor checked your security and signed off. It matters because more contracts now demand it, and because the discipline genuinely lowers your risk. We help you build an ISMS that fits how you actually work, not a binder that sits on a shelf.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the ISO 27001 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Gap Assessment. We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead. Activities: Define the ISMS scope and boundaries; Interview control owners across teams; Assess maturity against clauses 4 to 10; Test current state against the 93 Annex A controls; Rank gaps by effort and risk. Hands over Gap Assessment Report. Phase 2, Risk Assessment and Treatment. We run a structured risk assessment and agree how you treat each risk. This feeds your Statement of Applicability and risk treatment plan. Activities: Build the asset and risk inventory; Score risks by likelihood and impact; Agree treat, tolerate, transfer, or terminate for each; Select applicable Annex A controls; Draft the Statement of Applicability. Hands over Risk Treatment Plan and Statement of Applicability. Phase 3, Control Design and Documentation. We design the policies, procedures, and controls you need. Everything maps back to a clause or an Annex A control so nothing is orphaned. Activities: Draft the information security policy set; Write procedures for access, change, and incidents; Map every document to a clause or control; Define roles and the risk acceptance criteria. Hands over ISMS Policy and Procedure Set. Phase 4, Implementation Support. We help you roll out controls and start collecting evidence. You build the day-to-day habits that keep the ISMS running. Activities: Roll out controls across in-scope systems; Configure a compliance platform for evidence; Run security awareness training; Start access reviews and log collection. Hands over Operating Controls and Evidence Trail. Phase 5, Internal Audit and Management Review. We run an internal audit, log findings, and prepare your management review. This is your dress rehearsal before the certification body arrives. Activities: Plan and run the internal audit programme; Log nonconformities and corrective actions; Prepare management review inputs; Verify remediation before certification. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification and Surveillance. We support you through Stage 1 and Stage 2 audits, then help you sustain the ISMS across annual surveillance visits. Activities: Prepare evidence for the Stage 1 documentation review; Support the Stage 2 certification audit; Close any audit findings raised; Plan annual surveillance and continual improvement. Hands over ISO 27001 Certificate. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Gap Assessment

We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.

What Happens In This Phase

  • Define the ISMS scope and boundaries
  • Interview control owners across teams
  • Assess maturity against clauses 4 to 10
  • Test current state against the 93 Annex A controls
  • Rank gaps by effort and risk

The Handover

Gap Assessment Report

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Gap Assessment

    We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.

    OutputGap Assessment Report

    Activities

    • Define the ISMS scope and boundaries
    • Interview control owners across teams
    • Assess maturity against clauses 4 to 10
    • Test current state against the 93 Annex A controls
    • Rank gaps by effort and risk
  2. 02

    Risk Assessment and Treatment

    We run a structured risk assessment and agree how you treat each risk. This feeds your Statement of Applicability and risk treatment plan.

    OutputRisk Treatment Plan and Statement of Applicability

    Activities

    • Build the asset and risk inventory
    • Score risks by likelihood and impact
    • Agree treat, tolerate, transfer, or terminate for each
    • Select applicable Annex A controls
    • Draft the Statement of Applicability
  3. 03

    Control Design and Documentation

    We design the policies, procedures, and controls you need. Everything maps back to a clause or an Annex A control so nothing is orphaned.

    OutputISMS Policy and Procedure Set

    Activities

    • Draft the information security policy set
    • Write procedures for access, change, and incidents
    • Map every document to a clause or control
    • Define roles and the risk acceptance criteria
  4. 04

    Implementation Support

    We help you roll out controls and start collecting evidence. You build the day-to-day habits that keep the ISMS running.

    OutputOperating Controls and Evidence Trail

    Activities

    • Roll out controls across in-scope systems
    • Configure a compliance platform for evidence
    • Run security awareness training
    • Start access reviews and log collection
  5. 05

    Internal Audit and Management Review

    We run an internal audit, log findings, and prepare your management review. This is your dress rehearsal before the certification body arrives.

    OutputInternal Audit Report and Management Review Record

    Activities

    • Plan and run the internal audit programme
    • Log nonconformities and corrective actions
    • Prepare management review inputs
    • Verify remediation before certification
  6. 06

    Certification and Surveillance

    We support you through Stage 1 and Stage 2 audits, then help you sustain the ISMS across annual surveillance visits.

    OutputISO 27001 Certificate

    Activities

    • Prepare evidence for the Stage 1 documentation review
    • Support the Stage 2 certification audit
    • Close any audit findings raised
    • Plan annual surveillance and continual improvement

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the ISO 27001 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Sprinto, Scrut, Jira, Confluence, OneTrust, Microsoft Purview. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27001 Annex A, ISO/IEC 27005, ISO/IEC 27017, NIST CSF.

What We Run

8 tools

  • Vanta
  • Drata
  • Sprinto
  • Scrut
  • Jira
  • Confluence
  • OneTrust
  • Microsoft Purview

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • ISO/IEC 27001:2022
  • ISO/IEC 27002:2022
  • ISO/IEC 27001 Annex A
  • ISO/IEC 27005
  • ISO/IEC 27017
  • NIST CSF
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Gap assessment report
  • Statement of Applicability
  • Risk treatment plan
  • ISMS policy and procedure set
  • Certification audit support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How long does ISO 27001 certification take?

Most organisations reach certification in three to six months, depending on your size and how many controls already exist. We give you a realistic timeline after the gap assessment.

What is the Statement of Applicability?

It is the document that lists every Annex A control, says whether you apply it, and explains why. Auditors read it closely, so we help you get it right.

What is the difference between Stage 1 and Stage 2 audits?

Stage 1 checks that your documents and ISMS design are ready. Stage 2 tests whether your controls actually work in practice. You need to pass both.

Keep Moving Through Compliance

Service 1 of 13 in this practice area