- Home
- Services
- Get compliant
- ISO 27001
ISO/IEC 27001:2022 Implementation & Audit Readiness
From gap assessment to certification audit: we build an ISMS that fits how your company actually works, then stay with you through Stage 1 and Stage 2.
Enterprise and international customers increasingly ask for ISO 27001 before they sign. Templates downloaded from the internet rarely survive an auditor's questions — and they do not make you more secure.
What we cover
Gap assessment
Clause-by-clause and Annex A review against ISO/IEC 27001:2022 (93 controls in 4 themes).
Risk assessment
Asset-based risk register, treatment plan and Statement of Applicability.
Policies & procedures
Written for your teams — short, usable and evidence-friendly.
Implementation support
Technical controls, logging, access reviews, supplier management, awareness training.
Internal audit
Independent internal audit and management review before the certification body arrives.
Certification support
We sit with you through Stage 1 and Stage 2 audits and close any findings.
Five clear steps, no surprises
Discover
Map data, systems, vendors and gaps.
Plan
Risk-based roadmap with owners.
Implement
Policies, controls and evidence.
Verify
Internal audit and readiness check.
Certify
Stand with you through the audit.
What you get
- Gap report and roadmap
- Complete ISMS documentation set
- Risk register & SoA
- Internal audit report
- Audit-day support
Pick how you'd like to work with us
Gap assessment
Two to four weeks: where you stand and a prioritised roadmap.
End-to-end programme
From gap assessment to audit-ready, with your team trained.
Virtual CISO / DPO support
Ongoing monthly support to keep evidence current.
Every engagement starts with a free scoping call and a fixed, written quote.
Where we've done this
Common questions
How long until we are certified?
Do you issue the certificate?
Find out how an attacker sees you — before they do.
Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.