Certification, with an ISMS that actually operates
From gap analysis to certification audit, with the documents, the risk assessment and the evidence trail. We are certifying our own ISMS on the same method.
The challenge
Most ISO 27001 projects produce a shelf of documents that nobody follows. An auditor can tell the difference within an hour.
Scope — included and not included
Included
- Gap analysis
- Scope and context definition
- Risk assessment to ISO 27005
- Full policy and procedure set
- Statement of Applicability
- Evidence collection
- Internal audit
- Management review
- Certification audit support
Not included
- The certification audit fee itself
- Implementing technical controls, though we can quote separately
- Acting as your certification body
- Ongoing ISMS operation unless retained
How it works
01
Gap analysis
Where you stand against the standard, with a dated roadmap.
02
Risk assessment
ISO 27005 — the register and treatment plan that drive everything.
03
Build the ISMS
Policies, procedures, Statement of Applicability — sized to reality.
04
Operate and evidence
The ISMS runs and the evidence register fills.
05
Internal audit and certification
Internal audit, management review, auditor liaison through certification.
What you receive
- →Gap analysis with a dated roadmap
- →Risk register and treatment plan
- →Complete document set
- →Statement of Applicability
- →Evidence register
- →Internal audit report
- →Management review pack
- →Auditor liaison during certification
What we need from you
- ·An executive sponsor
- ·A named internal owner
- ·Access to process owners
- ·Roughly four hours per week from your side
Timeline and engagement
6 to 12 months depending on scope and starting point. Fixed scope with a retainer for the operating phase.
Standards, methods and tooling
ISO 27001:2022ISO 27005ISO 22301DrataOur own ISMS in certificationPortal hosted in Canada
Frequently asked questions