Skip to main content

ISO 27001 ISMS Readiness

Build an information security management system that holds up under audit. We assess the gap against ISO/IEC 27001:2022, build the ISMS and its documented information, and prepare the evidence an accredited certification body examines at Stage 1 and Stage 2.

Engagement brief

Governance, Risk & Compliance
Frameworks
ISO/IEC 27001ISO/IEC 27002SOC 2 (TSC)

Coverage that maps to real risk.

ISMS scope boundary: entities, sites, and systems
Clauses 4–10, including the climate additions in Amd 1:2024
Risk assessment and treatment method (6.1.2, 6.1.3)
Statement of Applicability across all 93 Annex A controls
Documented information and records (7.5)

How the engagement runs.

A disciplined, repeatable arc — so results are comparable and defensible.

  1. 01

    Gap assessment against clauses 4–10 and Annex A

  2. 02

    ISMS scoping, risk method, and Statement of Applicability

  3. 03

    Control implementation and documented-information build-out

  4. 04

    Internal audit programme and management review inputs (9.2, 9.3)

  5. 05

    Stage 1 and Stage 2 support, corrective-action planning

What you walk away with.

Gap assessment report across clauses 4–10 and Annex A
ISMS documentation set: scope, policy, and risk method
Risk register, treatment plan, and Statement of Applicability
Internal audit programme, management review pack, and evidence index

Every finding is rated on the CVSS severity scale:

  • CRITICAL9.0–10.0
  • HIGH7.0–8.9
  • MEDIUM4.0–6.9
  • LOW0.1–3.9
  • INFO0.0

Questions we hear a lot.

No, and no advisory firm can. The certificate comes from a certification body accredited for ISO/IEC 27001 — NABCB in India, or another IAF signatory such as UKAS or ANAB. Clause 9.2.2 also requires objective internal auditors, so we build the audit programme rather than audit our own work.

Tell us about your environment and we'll come back with a fixed scope, timeline, and price.