Build

    ISO/IEC 27001 implementation

    We build the information security management system that ISO/IEC 27001 certifies — the risk process, the controls, the documentation and the evidence — and take you through to a successful certification audit. Delivered by lead implementers who have done it before, not by consultants reading the standard alongside you.

    Duration

    Typically 4–9 months to certification audit, depending on scope and starting position

    Built on

    ISO/IEC 27001:2022 · ISO/IEC 27002:2022 · ISO/IEC 27005 · ISO 19011

    Indicative price

    €25,000–65,000 per engagement

    Who this is for

    • CISO or security manager

      Owns the certification and will be the one in the room with the auditor.

    • CIO or IT director

      Has to absorb the control requirements without stopping delivery.

    • Quality or compliance manager

      Already runs other management systems and wants this one to sit alongside them rather than duplicate them.

    • CEO or owner

      Is certifying because a client, a tender or an insurer asked, and wants the shortest defensible route.

    Most failed certifications fail on evidence, not on controls

    Almost every organisation that sets out to certify against ISO/IEC 27001 already has most of the controls. Firewalls are configured, access is managed, backups run, people have been told not to reuse passwords. What is missing is almost never the security itself. It is the ability to demonstrate, in a form an auditor accepts, that the security is deliberate, documented and operating.

    That distinction is the whole standard. ISO/IEC 27001 does not certify that you are secure — no standard can. It certifies that you have a management system: that you decided what needed protecting, assessed what could go wrong, chose controls on the basis of that assessment, recorded why you chose them, made someone accountable, and checked afterwards whether it worked. An auditor is testing that chain of reasoning, not the strength of your firewall rules.

    This is why so many first attempts stall at Stage 1. The documentation describes an organisation that does not quite exist: a risk assessment produced once and never revisited, a Statement of Applicability that justifies every control in identical words, policies written for a different company and lightly renamed. None of that survives a competent auditor, and the finding is never 'your security is bad' — it is 'you cannot show me how you decided'.

    The second common failure is scope. Set too wide, it drags systems, sites and suppliers into the audit that add nothing commercially and a great deal of work. Set too narrow, it produces a certificate your clients read and dismiss, because the thing they care about sits outside the boundary. Scope is the highest-leverage decision in the whole programme and it is made in the first week.

    We build the management system so that it is defensible and so that it is the smallest one that does the job. The aim is not the thickest documentation set. It is a system your own people can operate after we leave, and that survives the surveillance audits in years two and three without being rebuilt.

    How we do it

    1. 01

      Scope and mandate

      1 week

      We fix the boundary — which entities, sites, services, systems and people are in, and which are deliberately out — and write the justification for each exclusion. We confirm who owns the ISMS, what leadership commitment means here in practice, and what the certification is commercially for. Scope is settled in writing at this point, because changing it later is the most expensive mistake available.

    2. 02

      Gap analysis

      2–3 weeks

      We test your current position against every clause of the standard and against Annex A, and produce a finding-by-finding view of where you stand. This is not a maturity score out of five. It is a list of what is missing, what exists but is undocumented, and what exists and is fine — with the effort each gap represents.

    3. 03

      Risk assessment

      2–3 weeks

      We establish risk criteria your organisation can apply consistently, identify risks against the assets and processes in scope, and analyse them using a documented method so it can be repeated. Most of the value is in the criteria: a scale everyone interprets the same way is what makes next year's assessment cheaper than this one.

    4. 04

      Risk treatment and Statement of Applicability

      2 weeks

      Every risk gets a treatment decision, an owner and a date. Controls are selected because the assessment pointed at them, and the Statement of Applicability records that reasoning control by control — including the ones you exclude. This is the document an auditor reads first and the one most organisations write last.

    5. 05

      Documentation and policies

      3–5 weeks

      The policies, procedures and records the standard requires, and nothing beyond them. We write them to match how your organisation actually works, because a policy describing a process nobody follows is a nonconformity waiting to be found. Where documents already exist, we amend rather than replace.

    6. 06

      Implementation and awareness

      4–8 weeks

      Closing the technical and organisational gaps, with your teams doing the work and us alongside. Competence and awareness belong here rather than at the end: the auditor will ask people at random what they do and why, and their answers are evidence.

    7. 07

      Internal audit and management review

      2 weeks

      We run the internal audit, or train your people to run it, and hold the management review. Both are mandatory clauses, both are commonly skipped or staged, and skipping either is a reliable way to fail Stage 1. You keep the records they produce.

    8. 08

      Certification audit support

      Stage 1 and Stage 2

      We assemble the evidence pack, brief the people the auditor will interview, and are present through both stages. Findings are ours to answer with you — we do not hand over at the door.

    Named artefacts

    What you receive

    • ISMS scope statement, with documented justification for every exclusion
    • Gap analysis report against all clauses and all Annex A controls
    • Risk assessment methodology and documented risk criteria
    • Risk register, populated and owned
    • Risk treatment plan with named owners and dates
    • Statement of Applicability covering every Annex A control, with the reasoning for each inclusion and exclusion
    • The mandatory policy set, written to your operating reality
    • Procedures and records required by the standard — incident management, access control, supplier security, business continuity, change management
    • Competence and awareness programme, with attendance evidence
    • Internal audit programme and the report from the first cycle
    • Management review minutes and decisions
    • Certification evidence pack, organised the way an auditor reads it

    What we need from you

    • An executive sponsor with the authority to settle scope and to release budget for the treatment plan.
    • A named ISMS owner inside your organisation. We can hold this during the programme, but not after it.
    • Roughly half a day a week from IT, HR, legal and operations during the documentation and implementation phases.
    • Access to existing policies, contracts, asset inventories and incident records — including the ones you consider embarrassing. Those are usually the informative ones.
    • Honesty about what is actually done versus what is written down. We will find the difference anyway, and finding it in week two is far cheaper than the auditor finding it in month nine.
    • A decision on your certification body and target audit dates by the end of the gap analysis, because their calendars drive ours.

    What changes

    1. 01A certifiable management system, with its evidence assembled rather than reconstructed under time pressure.
    2. 02A scope you can explain to a client in one sentence and defend to an auditor in one page.
    3. 03A risk assessment your own people can repeat next year without us.
    4. 04Security decisions that are traceable — anyone can see why a given control exists.
    5. 05Procurement questionnaires answered from documents that already exist.
    6. 06A system that survives the year two and year three surveillance audits without a rebuild.

    What it costs

    €25,000–65,000 per engagement

    All prices exclude VAT.

    Questions

    How long does certification take from a standing start?

    Four to nine months to the Stage 2 audit for most mid-sized organisations, and the variable is rarely our speed. It is how quickly your organisation closes the gaps the assessment finds, and how early you book the certification body — their calendars are often eight to twelve weeks out. A single-site organisation with existing documentation moves faster; several entities and a wide scope should plan for the upper end.

    Do we need ISO 27001 if we already comply with NIS2?

    They answer different questions and neither replaces the other. NIS2 is law and applies whether or not you are certified. ISO/IEC 27001 is a voluntary standard that certifies a management system. In practice it is the most efficient way to build what the NIS2 duty of care requires, because the risk process, the controls and the evidence are the same body of work — and it produces a certificate a client's procurement team recognises, which the law does not.

    Can you audit us as well as implement?

    No, and nobody reputable can. The certification audit must be performed by an accredited certification body independent of the people who built the system. We implement, we run your internal audit or train your people to run it, and we support you through the external audit — but the certificate is issued by the certification body, not by us.

    Who actually does the work, your people or ours?

    Both, deliberately. We write the management system and run the process; your people make the decisions and close the technical gaps. A system built entirely by consultants fails its first surveillance audit, because nobody inside the organisation knows why anything was decided.

    What does it cost?

    €25,000–65,000 per engagement. The range reflects scope and starting position. It excludes the certification body's own fees, which you pay them directly and which depend on your headcount and number of sites — we tell you what to expect there before you commit.

    What happens after certification?

    Surveillance audits in years one and two, recertification in year three, and the internal audit and management review cycle you now owe annually. We can hand over entirely, stay on retainer as your vCISO, or run the ISMS as a managed service.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.