From gap analysis to certificate — we design, implement and embed your Information Security Management System (ISMS) so you pass Stage 1 and Stage 2 audits first time. Practical controls, real documentation, no shelf-ware.
Current-state assessment against all ISO 27001:2022 clauses and Annex A controls with a prioritised remediation roadmap.
Scope statement, context, risk methodology, Statement of Applicability and the full ISMS document set.
Implementation guidance for the 93 Annex A controls — organisational, people, physical and technological.
Asset-based risk register, treatment plans and residual risk reporting for management review.
Conducting the mandatory internal audit cycle and chairing your first management review.
Mock audits, evidence packs and on-site support during your certification body audit.
Diagnose where you are vs the standard and build the remediation plan.
Policies, procedures, risk register, SoA and Annex A control implementation.
Run the full internal audit and management review cycle with evidence.
Support you through Stage 1 and Stage 2 with your chosen certification body.
Most organisations complete certification in 4–6 months from kickoff, depending on scope, size and current maturity. Larger groups typically take 6–9 months.
Yes — we'll recommend accredited certification bodies, coordinate the audit, attend Stage 1 and Stage 2 with you, and manage any findings.
Yes. We help organisations transition from ISO 27001:2013 to the 2022 version, including the new Annex A control set and required documentation updates.
Book a free consultation. We'll scope the work, agree timelines, and give you a clear path forward — no obligation.
Book a free ISO 27001 gap analysis