ISO/IEC 27001:2022
A prospect wants ISO 27001 by a date. Here is how it gets there.
Gap analysis to an audit-ready ISMS for teams of 10 to 300, built in the platform that keeps collecting evidence after certification, with the certification body booked around your date.
93 controls: 89 applicable, 4 excluded with justification
- 5 Organisational
- 37 controls
- 37 / 37
- 6 People
- 8 controls
- 8 / 8
- 7 Physical
- 14 controls, 4 excluded: no owned premises
- 10 / 10
- 8 Technological
- 34 controls
- 34 / 34
Who this is for
Teams whose customers ask for the certificate, not the brochure.
A fit
- A SaaS company of 10 to 300 people whose enterprise prospect requires ISO 27001 before signing or renewing.
- An IT services or MSP business bidding for a public or regulated contract that lists ISO 27001 as a condition.
- A team on AWS, Google Cloud or Azure with GitHub and Google Workspace or Microsoft 365, where most evidence can be collected automatically.
Also a fit
- A company that already holds SOC 2 or has a GDPR programme and needs an ISMS for European and international customers.
- A company whose first certification attempt stalled on documentation nobody owned.
- A team that wants ISO 27001 and SOC 2 from one control set, with the second report mostly mapping.
Not a fit
- Organisations that need the certification audit itself. We prepare you; an accredited certification body audits and certifies.
- Companies with owned data centres or manufacturing sites. The physical controls need an on-site partner, which we would name in the quote.
- Teams that want a document pack without operating the controls. The auditor checks that the ISMS runs, and so do we.
What you walk away with
An ISMS the auditor can follow, and your team can run.
Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.
ISO 27001 readiness
14 deliverables, 8 to 10 weeksISMS scope and context statement
Interested parties, boundaries, interfaces
- DOCX
Information security policy and management commitment
Approved and communicated, with the record
- DOCX
Risk assessment method, risk register and treatment plan
Owners, likelihood, impact, treatment, residual risk
- CSV
Statement of Applicability for all 93 Annex A controls
Applicable or excluded, with justification and status
- CSV
Policy set for the controls you apply
Access, cryptography, secure development, supplier, acceptable use, and the rest your SoA selects
- DOCX
Procedures for access, change, incident, supplier and business continuity
Written for how your team actually works
- Procedure
Asset inventory and supplier register
Owners, classification, contract and review status
- CSV
Competence, awareness and training records
Who was trained on what, and when
- Platform
Internal audit programme and first internal audit report
Findings and corrective actions logged
Management review record
Inputs, decisions, actions, as clause 9.3 requires
Evidence linked to each control
From GitHub, cloud and identity systems where connected; uploaded where not
- Platform
Objectives, metrics and measurement plan
What you measure and how often
- DOCX
Certification body shortlist and audit plan
Stage 1 and Stage 2 booked around your date
- DOCX
Recorded hand-over and readiness sign-off
With whoever owns the ISMS afterwards
- Video
How it works
Ten weeks to hand-over. Then the auditor, then every year without us.
The certification audit is yours to contract; we book it around your date and join the calls.
- GRCTrail
- Hand-over
- Without us
Week 0
Scoping call
Scope, cloud footprint, what exists. Written fixed price within 3 business days.
Weeks 1 to 2
Assessment
Gap analysis against clauses 4 to 10 and Annex A. Risk method agreed. Implementation price confirmed.
Weeks 3 to 9
Implementation
Policies, procedures, SoA, evidence linked to each control. Two review sittings with your team.
Week 10
Internal audit, management review, hand-over
First internal audit, management review record, recorded hand-over, readiness sign-off.
Your auditor
Stage 1 and Stage 2
Booked around your date with the certification body you contract. We join the calls and fix findings against our work.
Every year
Surveillance audits
The ISMS keeps operating: reviews, internal audits, evidence collecting. In GRCTrail or in your export.
How we price
What moves the price
Three things we ask about on the call.
How much of the stack is cloud.
Controls on AWS, GitHub and Google Workspace are evidenced automatically; owned hardware is not.
What already exists.
A SOC 2 report or a working security programme shortens the work considerably.
Scope and sites.
One product and one office is the base case; each extra product, office or legal entity adds controls to evidence.
Never in our price, named in the quote so you can budget
- The Stage 1 and Stage 2 certification audit, contracted with an accredited certification body
- Penetration testing
- Formal legal opinions
- Acting as your information security officer after hand-over
Questions before the call
Who issues the ISO 27001 certificate?
An accredited certification body, after a Stage 1 and Stage 2 audit that you contract directly. We prepare the ISMS and evidence, help you choose the body, book the dates around your deadline and join the calls. We do not issue certificates.
Can a company of 15 people get certified?
Yes. The standard scales to the organisation. A narrow scope and a small control set still meet every clause. The work is the same shape; it is shorter.
Do we need SOC 2 as well?
Only if your customers ask for it. ISO 27001 is recognised worldwide; SOC 2 is expected mainly by US customers. The two share most controls, so adding SOC 2 readiness later is mostly mapping and evidence formatting.
What happens after certification?
The certificate is valid for three years with annual surveillance audits. The ISMS must keep operating: reviews, internal audits, evidence. In GRCTrail that schedule is tracked and evidence keeps collecting from connected systems. The documents remain yours either way.
What if the auditor raises a nonconformity?
If it is against work we delivered, we fix it at no extra charge; that is stated in the quote. If it concerns something outside the agreed scope, we tell you what it would take and you decide.
Last reviewed: October 2026
Tell us your date, your cloud footprint and what exists today.
You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.