ISO/IEC 27001 readiness

We help your team build or improve an ISMS that meets ISO/IEC 27001:2022, with controls and evidence ready for your accredited certification body's audits.

On this page

What ISO/IEC 27001 is

ISO/IEC 27001 is the international standard for an information security management system (ISMS). It sets requirements for how an organization identifies information security risks, selects controls to treat them, and reviews and improves the system over time. The current edition is ISO/IEC 27001:2022.

Organizations pursue certification when customers, partners or tenders ask for it. Requests are common in international procurement and public sector contracts. An accredited certification body audits the ISMS against the standard and, if it conforms, issues a certificate for the scope you define.

Key facts

Clauses 4 to 10

The management system requirements: context of the organization, leadership, planning, support, operation, performance evaluation and improvement. All of them apply to every certified ISMS.

Annex A

93 reference controls in four themes: organizational (37), people (8), physical (14) and technological (34). You select controls through risk treatment.

Statement of Applicability

A required document that lists each Annex A control, whether it is included, the justification, and whether it is implemented.

Risk assessment and treatment

A defined, repeatable method to identify, analyze and evaluate risks, and a treatment plan approved by risk owners.

Internal audit and management review

The internal audit checks the ISMS against the standard and your own requirements. Management review records leadership decisions about the ISMS. Certification bodies expect both before the Stage 2 audit.

Certification cycle

Stage 1 reviews documentation and readiness. Stage 2 assesses whether the ISMS is implemented and effective. Certificates are valid for three years, with surveillance audits in between and a recertification audit before expiry.

2024 amendment

ISO/IEC 27001:2022/Amd 1:2024 adds a requirement to consider whether climate change is a relevant issue when defining context in clauses 4.1 and 4.2.

How readiness works with us

We help you define the ISMS scope: the products, services, locations, teams and systems included, and the interfaces and dependencies at the boundary. A clear scope statement decides what the certificate covers and what the auditor will examine.

What you receive

Each engagement has a fixed scope agreed at the start. These are the outputs your team keeps.

Gap assessment

  • ISMS scope statement draft
  • Status against clauses 4 to 10 and Annex A
  • Prioritized remediation plan with owners and target dates

ISMS documentation

  • Risk assessment method and risk register
  • Statement of Applicability
  • Policies and procedures updated where gaps exist

Controls and evidence

  • Controls implemented or improved in your environment
  • Evidence organized by clause and control for the auditor
  • Setup in your compliance platform if you use one

Testing and audit support

  • Pre-audit testing results
  • Support for internal audit and management review
  • Help during Stage 1, Stage 2 and corrective actions

Control areas we commonly implement

Access control and identity

Annex A 5.15 to 5.18, 8.2 and 8.5: access rules, identity lifecycle, MFA, privileged access and access reviews. We can deploy identity with Keycloak.

Vulnerability management

Annex A 8.8: scanning, patch timelines and tracking to closure. We also run application and cloud infrastructure security testing.

Logging and monitoring

Annex A 8.15 and 8.16: centralized logs, alerting and records of review. We deploy open-source monitoring such as Wazuh.

Incident management

Annex A 5.24 to 5.28: planning, assessment, response, lessons learned and evidence collection.

Supplier relationships

Annex A 5.19 to 5.23: supplier inventory, security terms in agreements, monitoring of suppliers and use of cloud services.

Change management

Annex A 8.32: approval, testing and records for changes to systems and software.

Backups

Annex A 8.13: backup schedules, restore tests and retention aligned with your requirements.

ISO/IEC 27001 and SOC 2 compared

Many controls overlap. If you plan both, we scope them together so one set of controls and evidence supports both audits.

TopicISO/IEC 27001SOC 2
ResultCertificate issued by an accredited certification bodyAttestation report with an opinion issued by a licensed CPA firm
BasisISMS requirements in clauses 4 to 10, plus controls selected from Annex A through risk treatmentTrust Services Criteria for the categories in scope
What customers seeThe certificate and scope statement, and often the Statement of Applicability on requestThe full report with system description, controls, tests and results, usually shared under NDA
CycleThree-year certificate with surveillance audits in betweenA new report for each period, often annually
Often requested byInternational customers and public sector buyersNorth American customers, especially for SaaS

Who does what

We help you build or improve the ISMS and prepare for the audits. We scope, assess, help implement controls, test them and support your team during the certification audit. We do not certify organizations or issue certificates.

Your certification body, accredited by a national accreditation body, performs the Stage 1 and Stage 2 audits, decides whether to certify, issues the certificate and runs the surveillance and recertification audits.

Your team owns the ISMS. Top management sets the information security policy and objectives, assigns roles and takes part in management review. Risk owners approve risk treatment. Control owners operate the controls and keep the records.

Common questions

How long does readiness take?

It depends on your scope and how mature your security program is today. During scoping we give you a plan with dates for each phase, including time for the internal audit and management review before Stage 2.

Can you work with our compliance platform?

Yes. If you use Vanta, Drata or a similar platform, we work inside it. We map controls, connect integrations and upload evidence. If you do not use one, we organize documents and records in a structure your auditor can follow.

Do you certify us?

No. An accredited certification body performs the certification audits and issues the certificate. We prepare your team and support you during the audits.

Can you help after certification?

Yes, through a retainer. We can help with risk reviews, internal audits, management review, corrective actions and preparation for surveillance and recertification audits.

Our certificate is to the 2013 edition. What now?

The transition period to ISO/IEC 27001:2022 ended on 31 October 2025, so certificates to the 2013 edition are no longer valid. Ask your certification body about the route to certification against the 2022 edition. We can assess you against it, update your Statement of Applicability to the new Annex A structure and prepare evidence for their audit.

What do we need to prepare?

A named owner on your side, a sponsor in top management, a draft of what you want the certificate to cover, and your current policies, asset inventory and vendor list. An NDA can be in place before we start.

How to prepare

Decide what the certificate needs to cover. Look at the customer and tender requests you have received and the products, sites and teams they relate to.

Gather what you already have: policies, an asset inventory, a vendor list, an architecture diagram, any existing risk register and records of past incidents. Gaps are expected. The gap assessment exists to find them.

Choose an internal owner for the ISMS and a sponsor in top management who can attend management review. If you have already selected a certification body, share their contact so we can align on audit dates early.

Surveillance and recertification

Certification starts a three-year cycle. The certification body runs surveillance audits in the years between initial certification and recertification, and a recertification audit before the certificate expires. Each surveillance audit covers part of the ISMS and checks that it is still operating.

To stay ready, keep the ISMS running between audits: review risks when your systems or business change, complete internal audits and management reviews on schedule, close corrective actions and keep control records current. We can support this work through a retainer.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.