Certifiable standard

ISO 27001 Readiness

A customer, an investor, or a market outside the US has asked for the certificate. You get a management system that will actually pass Stage 2, not a folder of policies describing one.

Who this applies to. Organizations that need an internationally recognized certification, usually because a customer, an investor, or a market outside the US has asked for one.

What ISO 27001 actually asks of you

ISO 27001 certifies a management system, not a control set. That distinction is the thing most organizations get wrong, and it is why projects that start as a documentation exercise tend to fail their first audit. The auditor is checking whether you run a process for identifying risk, deciding what to do about it, and reviewing whether it worked. The controls in Annex A are the output of that process, not a substitute for it.

The practical consequence is that evidence has to exist over time. An internal audit, a management review, a risk assessment that was actually performed and acted on: these are records with dates, and they cannot be produced retrospectively the week before the certification body arrives.

Most of our ISO engagements start with an organization that has good security and no management system. The security work is often close to done. The system around it is what needs building.

The engagement

What readiness covers

Scope definition

Deciding what the ISMS covers, which is the single decision that governs cost. A scope drawn around one product and its supporting functions is a materially different engagement from one drawn around an entire company.

Risk assessment methodology

A repeatable method for identifying, evaluating, and treating risk, documented well enough that a different person could run it next year and reach comparable results. Auditors test the method, not just the output.

Statement of Applicability

Every Annex A control, with a decision recorded for each: applied, or excluded with a justification that holds. This is the document a certification body reads first.

Control implementation

Closing the gaps the risk assessment surfaced, sequenced so the controls that need a period of operating evidence start early rather than last.

Internal audit and management review

The two records most often missing at Stage 1. Both are required, both need to have genuinely happened, and both need to show something was decided as a result.

Certification body liaison

Preparing for Stage 1 and Stage 2, including what to expect from each and how to handle findings. You engage the certification body directly, and their independence from us is what makes the certificate worth having.

What you are left holding

Deliverables

  • Defined ISMS scope and boundary documentation
  • Risk assessment methodology and a completed risk register
  • Statement of Applicability covering every Annex A control
  • Policy set mapped to the controls it implements
  • Internal audit report and management review minutes
  • Remediation plan with owners and dates for anything still open

FAQ

ISO 27001 questions we get asked

How long does ISO 27001 certification take?

For a scoped ISMS in an organization with an existing IT function, six to nine months from start to Stage 2 is realistic. The floor is set by evidence: some records have to exist over a period, and no amount of budget compresses that.

The variables that move it most are scope and how much of the work your team absorbs. An enterprise-wide scope with no dedicated security staff runs considerably longer.

Do you issue the certificate?

No. Certification is issued by an accredited certification body following a Stage 1 and Stage 2 audit. We prepare you for that audit and have no role in its outcome, which is what makes the result mean anything.

How does ISO 27001 relate to SOC 2?

They answer similar questions for different audiences. ISO 27001 is a certification against an international standard and travels well outside the US. SOC 2 is an attestation report produced by a CPA firm and is what most US customers ask for.

The underlying control work overlaps substantially. If both are likely, map the controls once and collect evidence once rather than running two programs.

Start with scope, not with a proposal

The first conversation is about what is actually in scope, because that governs the cost of everything after it.

Talk to an expert