Get in touch
ISO/IEC 27001

ISO 27001: from gap analysis to certification readiness

We help you design, implement and audit an Information Security Management System (ISMS) and be ready for certification by an accredited body.

ISO/IEC 27001 is the international standard for information security management. Certification is granted by accredited certification bodies, not by the consultant; we get you to the point where you can pass the audit with confidence.

ISO 27001 does not replace NIS2, but the processes you build (risk assessment, policies, controls, internal audit) overlap to a large extent with the measures the Directive requires.

What is included
  • Gap analysis against ISO/IEC 27001:2022 and the Annex A controls
  • Defining the ISMS scope and context
  • Risk assessment and risk treatment plan
  • Statement of Applicability
  • Policies, procedures and documentation
  • Support with implementing controls and staff training
  • Internal audit by a certified ISO/IEC 27001:2022 Internal Auditor and management review
  • Preparation for the certification body audit

Frequently asked questions

What is ISO 27001?

ISO/IEC 27001 is the international standard that sets the requirements for an Information Security Management System: how an organisation identifies the risks to its information, selects controls, and monitors and improves them systematically.

Who grants the certification?

An accredited certification body, through an external audit. The consultant prepares the organisation and can carry out internal audits, but does not certify their own client.

How long does preparation take?

It depends on the size of the organisation, the scope and existing maturity. It is usually measured in months. We start with a gap analysis so we can give a realistic estimate.

How does ISO 27001 relate to NIS2?

They are different things: NIS2 is a legal obligation for those in scope, while ISO 27001 is a voluntary standard. A good ISMS covers to a large extent the risk-management measures the Directive asks for, but does not automatically ensure compliance.