Certification-Ready Before the Auditor Arrives

Certification-Ready Before the Auditor Arrives

Certification-Ready Before the Auditor Arrives

Gap analysis against Annex A, ISMS build-out, and the internal audit the standard requires — so your certification audit holds no surprises.

Gap analysis against Annex A, ISMS build-out, and the internal audit the standard requires — so your certification audit holds no surprises.

Aligned with ISO/IEC 27001:2022 & Annex A

Aligned with ISO/IEC 27001:2022 & Annex A

A vast archive wall of identical drawers with one drawer open and lit

ISO 27001 Readiness & Internal Audit

Problem

The Binder Nobody Reads

The Binder Nobody Reads

Most first-time certifications fail the same way. A policy template pack gets bought, filled in, and filed — and the certification auditor finds no evidence anyone actually lives by it. The documents exist. The management system does not.

The second surprise arrives later: Clause 9.2 requires an internal audit before the external one. Companies routinely discover this weeks before the auditor is booked, with no independent party available to run it.

Solution

An ISMS That Survives Contact With an Auditor

An ISMS That Survives Contact With an Auditor

We build the ISMS in the order the standard actually reads: scope first, then risk method, then controls — so the Statement of Applicability reflects decisions you made rather than boxes you ticked.

Then we run the internal audit that Clause 9.2 requires, as an independent party, and give you a findings report with corrective actions your management review can act on. By the time the certification body arrives, nothing in your ISMS is new information.

Agenda

How It Works

How It Works

01

Scoping & Gap Analysis

  • Scope definition — the decision that drives total cost more than any other.

  • Gap analysis against clauses 4–10 and all 93 Annex A controls.

  • Credit for what you already have: existing policies, tooling, practices.

  • A realistic timeline and effort estimate to certification-readiness.

01

Scoping & Gap Analysis

  • Scope definition — the decision that drives total cost more than any other.

  • Gap analysis against clauses 4–10 and all 93 Annex A controls.

  • Credit for what you already have: existing policies, tooling, practices.

  • A realistic timeline and effort estimate to certification-readiness.

02

ISMS Build-Out

  • Risk assessment method and risk register, applied to your real assets.

  • Statement of Applicability with documented justifications.

  • Policy set written for your organisation, not lifted from a template.

  • Evidence routines — so records accumulate as you work, not the week before the audit.

02

ISMS Build-Out

  • Risk assessment method and risk register, applied to your real assets.

  • Statement of Applicability with documented justifications.

  • Policy set written for your organisation, not lifted from a template.

  • Evidence routines — so records accumulate as you work, not the week before the audit.

03

Internal Audit (Clause 9.2)

  • Independent internal audit as required by Clause 9.2.

  • Findings classified by severity, with corrective actions.

  • Conducted the way a certification auditor would: sampling, interviews, evidence.

03

Internal Audit (Clause 9.2)

  • Independent internal audit as required by Clause 9.2.

  • Findings classified by severity, with corrective actions.

  • Conducted the way a certification auditor would: sampling, interviews, evidence.

04

Management Review & Handover

  • Management review input pack per Clause 9.3.

  • Certification body selection and Stage 1 / Stage 2 preparation.

  • Handover to your internal owner, with the operating rhythm documented.

04

Management Review & Handover

  • Management review input pack per Clause 9.3.

  • Certification body selection and Stage 1 / Stage 2 preparation.

  • Handover to your internal owner, with the operating rhythm documented.

4

Management Review & Handover

  • Management review input pack per Clause 9.3.

  • Certification body selection and Stage 1 / Stage 2 preparation.

  • Handover to your internal owner, with the operating rhythm documented.

Execution

Your Team Runs It. We Make It Work.

Your Team Runs It. We Make It Work.

Certification is a project, not a workshop. We work alongside your team over six to twelve months depending on scope and starting maturity — you own the ISMS at the end, not us.

You receive:

  • Gap report against clauses 4–10 and Annex A.

  • ISMS documentation set including scope, SoA and risk register.

  • Internal audit report with findings and corrective actions.

  • Management review pack ready for Clause 9.3.

Target Audience

Ideal For:

Ideal For:

  • First-time certifiers: a customer or tender made ISO 27001 non-negotiable.

  • Companies with a stalled ISMS: documentation exists, nothing operates.

  • Certified organisations: who need an independent internal auditor each cycle.

  • Teams facing NIS2 or TISAX too: one control set, mapped across all three.

ROI & Business Impact

Why Invest in This?

Audit Confidence

The internal audit finds what the certification auditor would have found — while it still costs you nothing but time.

Contract Access

ISO 27001 is a procurement precondition in most enterprise and public-sector tenders. No certificate, no shortlist.

No Rework

A scope set correctly at the start is the single biggest lever on total certification cost. Most overruns start here.

Pricing

Scoped Around Your Team.

Every engagement is scoped to your team, your industry, and your risk profile. Tell us what you need and we’ll put together a concrete offer.

ISO 27001 Readiness

Gap analysis, ISMS build-out and internal audit

  • Format: project engagement alongside your team, remote or on site.

  • Duration: typically six to twelve months to certification-readiness.

  • Scope: clauses 4–10, all 93 Annex A controls, internal audit.

  • Deliverables: gap report, ISMS documentation, internal audit report.

  • Independence: we prepare you; an accredited body certifies you.

ISO 27001 Readiness

Gap analysis, ISMS build-out and internal audit

  • Format: project engagement alongside your team, remote or on site.

  • Duration: typically six to twelve months to certification-readiness.

  • Scope: clauses 4–10, all 93 Annex A controls, internal audit.

  • Deliverables: gap report, ISMS documentation, internal audit report.

  • Independence: we prepare you; an accredited body certifies you.

ISO 27001 Readiness

Gap analysis, ISMS build-out and internal audit

  • Format: project engagement alongside your team, remote or on site.

  • Duration: typically six to twelve months to certification-readiness.

  • Scope: clauses 4–10, all 93 Annex A controls, internal audit.

  • Deliverables: gap report, ISMS documentation, internal audit report.

  • Independence: we prepare you; an accredited body certifies you.

FAQ

Common Questions

Do you issue the certificate?
How long does the whole thing take?
Can you act as our internal auditor on an ongoing basis?
We bought a policy template pack. Is that a head start?

That's not all

Continue the Journey

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.