ISO 27001 ISMS Readiness
Build an information security management system that holds up under audit. We assess the gap against ISO/IEC 27001:2022, build the ISMS and its documented information, and prepare the evidence an accredited certification body examines at Stage 1 and Stage 2.
Engagement brief
- Frameworks
- ISO/IEC 27001ISO/IEC 27002SOC 2 (TSC)
Coverage that maps to real risk.
How the engagement runs.
A disciplined, repeatable arc — so results are comparable and defensible.
- 01
Gap assessment against clauses 4–10 and Annex A
- 02
ISMS scoping, risk method, and Statement of Applicability
- 03
Control implementation and documented-information build-out
- 04
Internal audit programme and management review inputs (9.2, 9.3)
- 05
Stage 1 and Stage 2 support, corrective-action planning
What you walk away with.
Every finding is rated on the CVSS severity scale:
- CRITICAL9.0–10.0
- HIGH7.0–8.9
- MEDIUM4.0–6.9
- LOW0.1–3.9
- INFO0.0
Questions we hear a lot.
No, and no advisory firm can. The certificate comes from a certification body accredited for ISO/IEC 27001 — NABCB in India, or another IAF signatory such as UKAS or ANAB. Clause 9.2.2 also requires objective internal auditors, so we build the audit programme rather than audit our own work.
Tell us about your environment and we'll come back with a fixed scope, timeline, and price.