
ISO 27001 Readiness & Internal Audit
Problem
Most first-time certifications fail the same way. A policy template pack gets bought, filled in, and filed — and the certification auditor finds no evidence anyone actually lives by it. The documents exist. The management system does not.
The second surprise arrives later: Clause 9.2 requires an internal audit before the external one. Companies routinely discover this weeks before the auditor is booked, with no independent party available to run it.
Solution
We build the ISMS in the order the standard actually reads: scope first, then risk method, then controls — so the Statement of Applicability reflects decisions you made rather than boxes you ticked.
Then we run the internal audit that Clause 9.2 requires, as an independent party, and give you a findings report with corrective actions your management review can act on. By the time the certification body arrives, nothing in your ISMS is new information.
Agenda
Execution
Certification is a project, not a workshop. We work alongside your team over six to twelve months depending on scope and starting maturity — you own the ISMS at the end, not us.
You receive:
Gap report against clauses 4–10 and Annex A.
ISMS documentation set including scope, SoA and risk register.
Internal audit report with findings and corrective actions.
Management review pack ready for Clause 9.3.


Target Audience
First-time certifiers: a customer or tender made ISO 27001 non-negotiable.
Companies with a stalled ISMS: documentation exists, nothing operates.
Certified organisations: who need an independent internal auditor each cycle.
Teams facing NIS2 or TISAX too: one control set, mapped across all three.
ROI & Business Impact
Why Invest in This?
Audit Confidence
The internal audit finds what the certification auditor would have found — while it still costs you nothing but time.
Contract Access
ISO 27001 is a procurement precondition in most enterprise and public-sector tenders. No certificate, no shortlist.
No Rework
A scope set correctly at the start is the single biggest lever on total certification cost. Most overruns start here.
Pricing
Scoped Around Your Team.
Every engagement is scoped to your team, your industry, and your risk profile. Tell us what you need and we’ll put together a concrete offer.
FAQ
Common Questions
Do you issue the certificate?
How long does the whole thing take?
Can you act as our internal auditor on an ongoing basis?
We bought a policy template pack. Is that a head start?
That's not all









