ISO 27001: implementing and certifying your information security management system
We support you from the gap analysis through to the certification audit. We design an ISMS that genuinely works in your company, without unnecessary bureaucracy and without losing focus on what matters: reducing real risk.
The problem with ISO 27001 projects that fail
Most failed ISO 27001 projects share the same pattern: a consultant delivers a pack of generic documents, the team signs them off without understanding them, and when the external auditor arrives the policies bear no relation to reality. Documenting for the sake of documenting does not reduce risk. We start with an honest gap analysis and build an ISMS that reflects how your company actually works, that the team understands and that the auditor validates.
ISO 27001 project phases
- Gap analysis: current posture vs. Annex A controls (ISO 27001:2022)
- Definition of the ISMS scope and the security policy
- Risk assessment and treatment (ISO 31000 methodology)
- Statement of Applicability (SoA)
- Implementation of technical and organizational controls
- Drafting of policies, procedures and records
- Internal audit prior to certification
- Support during the external audit (Stage 1 and Stage 2)
Our approach
- Honest gap analysis: We assess your real posture against the 93 controls of Annex A of ISO 27001:2022. No glossing over reality.
- Well-defined scope: Too broad and you never get there; too narrow and the certificate is useless for what you need. We define it precisely.
- Realistic risk management: We build the asset inventory and the risk assessment based on your operational reality, not on generic templates.
- Functional documentation: Policies and procedures designed to be useful and applicable, not to gather dust in a drawer.
- Audit readiness: We simulate the external audit and fix the deviations before the real auditor arrives.
Project deliverables
- Gap analysis report with a gap map
- Information Security Policy
- Risk assessment methodology and results
- Statement of Applicability (SoA)
- Complete documentation pack (30+ documents)
- Pre-certification internal audit report
Who asks us for ISO 27001?
- SaaS firms and startups that need certification to win enterprise clients or public tenders
- Professional services firms (legal, consulting, audit) that handle confidential data
- ICT suppliers to the public administration that need ISO 27001 as an alternative or complement to ENS
- Industrial companies with connected OT systems looking to extend the ISMS to production environments
- Organizations already working on NIS2 or DORA that want to integrate ISO 27001 by leveraging common controls
Frequently asked questions about ISO 27001
ISO 27001:2013 or ISO 27001:2022? Do we need to migrate?
The current version is ISO 27001:2022. Certificates issued under the 2013 version had until October 2025 to migrate. If you're just starting, go straight for the 2022 version.
How many internal resources does the project require?
You need an internal owner (usually the CISO or IT manager) with around 4 to 8 hours per week. The technical team takes part occasionally during the implementation of controls.
Does the ISO 27001 certificate have an expiry date?
The certificate is valid for 3 years, with annual surveillance audits (years 1 and 2) and a recertification audit in year 3.
Can you carry out the annual surveillance audits?
Yes. We offer maintenance contracts for surveillance audits, ISMS updates when things change and preparation for the three-yearly recertification.