← Solutions
CyberPopular

ISO 27001 readiness and certification

Build an information security management system that works for your business and takes you through ISO/IEC 27001:2022 certification.

Typical timing
4–9 months
Engagement
Phased programme
Delivery framework
User researchDiscoveryAlphaBetaLive

Implement an ISO/IEC 27001:2022 information security management system proportionate to your size and risk, and support you through the certification audit. The aim is a system people actually use, not a shelf of documents written for the auditor.

  • Enterprise customers require ISO 27001 before they will sign
  • Security questionnaires are slowing down sales
  • You want one framework to organise security, privacy and supplier risk
How it runs

Activities, step by step

The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.

  1. 02 · Discovery2–3 weeks

    Scope and gap analysis

    • ISMS scope and context defined
    • Gap analysis against clauses and Annex A controls
    • Implementation plan and certification body selected
  2. 03 · Alpha2–4 months

    Build the ISMS

    • Risk assessment and Statement of Applicability
    • Policies and procedures written with the teams who follow them
    • Controls implemented and evidence collected
  3. 04 · Beta4–8 weeks

    Prove it works

    • Internal audit and management review
    • Corrective actions closed
    • Stage 1 and Stage 2 certification audits supported
  4. 05 · LiveOngoing

    Maintain

    • Surveillance audit preparation
    • Risk and control reviews on a calendar
    • Continual improvement

Deliverables

What you keep at the end.

  • Information security management system
  • Risk assessment, treatment plan and Statement of Applicability
  • Policy and procedure set
  • Internal audit report
  • ISO/IEC 27001:2022 certification (issued by an accredited body)

Outcomes

What it is built to change.

  • Certification that unlocks enterprise and public sector deals
  • Faster answers to security questionnaires
  • Security run as a managed system, not a project