Scope definition
Deciding what the ISMS covers, which is the single decision that governs cost. A scope drawn around one product and its supporting functions is a materially different engagement from one drawn around an entire company.
Certifiable standard
A customer, an investor, or a market outside the US has asked for the certificate. You get a management system that will actually pass Stage 2, not a folder of policies describing one.
Who this applies to. Organizations that need an internationally recognized certification, usually because a customer, an investor, or a market outside the US has asked for one.
ISO 27001 certifies a management system, not a control set. That distinction is the thing most organizations get wrong, and it is why projects that start as a documentation exercise tend to fail their first audit. The auditor is checking whether you run a process for identifying risk, deciding what to do about it, and reviewing whether it worked. The controls in Annex A are the output of that process, not a substitute for it.
The practical consequence is that evidence has to exist over time. An internal audit, a management review, a risk assessment that was actually performed and acted on: these are records with dates, and they cannot be produced retrospectively the week before the certification body arrives.
Most of our ISO engagements start with an organization that has good security and no management system. The security work is often close to done. The system around it is what needs building.
The engagement
Deciding what the ISMS covers, which is the single decision that governs cost. A scope drawn around one product and its supporting functions is a materially different engagement from one drawn around an entire company.
A repeatable method for identifying, evaluating, and treating risk, documented well enough that a different person could run it next year and reach comparable results. Auditors test the method, not just the output.
Every Annex A control, with a decision recorded for each: applied, or excluded with a justification that holds. This is the document a certification body reads first.
Closing the gaps the risk assessment surfaced, sequenced so the controls that need a period of operating evidence start early rather than last.
The two records most often missing at Stage 1. Both are required, both need to have genuinely happened, and both need to show something was decided as a result.
Preparing for Stage 1 and Stage 2, including what to expect from each and how to handle findings. You engage the certification body directly, and their independence from us is what makes the certificate worth having.
What you are left holding
FAQ
For a scoped ISMS in an organization with an existing IT function, six to nine months from start to Stage 2 is realistic. The floor is set by evidence: some records have to exist over a period, and no amount of budget compresses that.
The variables that move it most are scope and how much of the work your team absorbs. An enterprise-wide scope with no dedicated security staff runs considerably longer.
No. Certification is issued by an accredited certification body following a Stage 1 and Stage 2 audit. We prepare you for that audit and have no role in its outcome, which is what makes the result mean anything.
They answer similar questions for different audiences. ISO 27001 is a certification against an international standard and travels well outside the US. SOC 2 is an attestation report produced by a CPA firm and is what most US customers ask for.
The underlying control work overlaps substantially. If both are likely, map the controls once and collect evidence once rather than running two programs.
Reviewed July 31, 2026. Primary sources: ISO/IEC 27001:2022 , ISO/IEC 27002:2022, the control set Annex A draws on .
The first conversation is about what is actually in scope, because that governs the cost of everything after it.