Latest alerts
  1. Home
  2. Services
  3. Get compliant
  4. ISO 27001
// get compliant · compliance & grc

ISO/IEC 27001:2022 Implementation & Audit Readiness

From gap assessment to certification audit: we build an ISMS that fits how your company actually works, then stay with you through Stage 1 and Stage 2.

ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/IEC 27005ISO/IEC 27701 (privacy extension)
// the problem

Enterprise and international customers increasingly ask for ISO 27001 before they sign. Templates downloaded from the internet rarely survive an auditor's questions — and they do not make you more secure.

Helps you meet: ISO/IEC 27001:2022
// scope

What we cover

Gap assessment

Clause-by-clause and Annex A review against ISO/IEC 27001:2022 (93 controls in 4 themes).

Risk assessment

Asset-based risk register, treatment plan and Statement of Applicability.

Policies & procedures

Written for your teams — short, usable and evidence-friendly.

Implementation support

Technical controls, logging, access reviews, supplier management, awareness training.

Internal audit

Independent internal audit and management review before the certification body arrives.

Certification support

We sit with you through Stage 1 and Stage 2 audits and close any findings.

// how it works

Five clear steps, no surprises

01

Discover

Map data, systems, vendors and gaps.

02

Plan

Risk-based roadmap with owners.

03

Implement

Policies, controls and evidence.

04

Verify

Internal audit and readiness check.

05

Certify

Stand with you through the audit.

// deliverables

What you get

  • Gap report and roadmap
  • Complete ISMS documentation set
  • Risk register & SoA
  • Internal audit report
  • Audit-day support
// standards & frameworks
ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/IEC 27005ISO/IEC 27701 (privacy extension)
// engagement models

Pick how you'd like to work with us

Gap assessment

Two to four weeks: where you stand and a prioritised roadmap.

Most popular

End-to-end programme

From gap assessment to audit-ready, with your team trained.

Virtual CISO / DPO support

Ongoing monthly support to keep evidence current.

Every engagement starts with a free scoping call and a fixed, written quote.

// faq

Common questions

How long until we are certified?
Most small and mid-size organisations are audit-ready in 3–6 months, depending on maturity and how quickly evidence can be produced.
Do you issue the certificate?
No — an accredited certification body does. We prepare you, and we keep the roles separate so the audit stays independent.
Get a quoteCall
// ready when you are

Find out how an attacker sees you — before they do.

Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.

Call Email Under attack? Free DPDP Check