Management system
ISO/IEC 27001 — Information Security Management
ISO/IEC 27001 is the certificate most enterprise buyers ask for by name. Earning it takes a working management system, not a folder of policies. We build that system with your team, prove it operates, and prepare you for an accredited certification body to assess it.
- Standard
- ISO/IEC 27001:2022
- Annex A controls
- 93
- Control themes
- 4
- Certificate cycle
- 3 years
What ISO/IEC 27001 actually requires
ISO/IEC 27001 is the international standard for an information security management system — an ISMS. Its core is not a control list but a cycle: you define a scope, assess risk against it, decide how to treat each risk, implement what you decided, measure whether it worked, and correct what did not. Clauses 4 to 10 hold those requirements, and an auditor tests them as a system rather than as a checklist.
Annex A supplies 93 controls in four themes — organisational, people, physical and technological. They are not all mandatory. You select controls to treat identified risk and record every inclusion and exclusion, with reasons, in a Statement of Applicability. The SoA is the document an auditor opens first, because it is where a management system either shows its reasoning or reveals it has none.
The current edition is ISO/IEC 27001:2022. The transition period for the 2013 edition closed on 31 October 2025, so certificates against 2013 are no longer valid and an organisation still holding one needs full certification rather than a transition audit.
What it will ask of you
None of this is paperwork for its own sake — each item is something an auditor will ask to see, and the absence of any one of them is a finding.
A scope you can defend
Which entities, sites, systems and people the ISMS covers, and why the boundary sits where it does. A scope drawn to be convenient rather than coherent is the first thing a competent auditor pulls at.
A risk assessment you repeat
A documented method, applied consistently, producing a risk treatment plan — and re-run on a schedule rather than once before the audit.
A Statement of Applicability
Every one of the 93 Annex A controls included or excluded, each with its reasoning. This is the document an auditor opens first, because it is where a management system either shows its thinking or reveals it has none.
Evidence that the system runs
Internal audits, management reviews, corrective actions and competence records — dated, and spread across the year rather than produced in the fortnight before Stage 2.
Why organisations hold it
- It clears enterprise procurement and vendor security reviews without a bespoke questionnaire each time.
- It is recognised internationally, so one certificate answers customers in several jurisdictions.
- It forces a defensible answer to "which risks did you accept, and who decided" — the question that matters after an incident.
- It gives the security function a budget argument grounded in a risk assessment rather than in fear.
- It integrates with ISO 22301 and ISO/IEC 27701, which share a clause structure, so the second system costs a fraction of the first.
Where we come in, and where we stop
ISO/IEC 17021-1 bars a certification body from certifying a management system it helped build. That separation is what makes the certificate worth holding, and it is the line this engagement is drawn around.
Ours
- Scope, gap assessment and the risk work
- The Statement of Applicability and the documented ISMS
- Implementing controls alongside your engineers
- Internal audit, management review and the evidence pack
- Rehearsing the audit with the people who will be interviewed
- Standing beside you through Stage 1, Stage 2 and each surveillance visit
An accredited certification body
- Stage 1 — reviewing your documentation and readiness
- Stage 2 — testing whether the ISMS is implemented and effective
- Issuing the certificate, and the surveillance audits that keep it
How certification works
Steps 1 to 6 are our work. Steps 7 and 8 belong to an accredited certification body, which must be independent of us and of you.
- 01Scope and gap assessmentWe agree what the ISMS covers — entities, sites, systems, people — then measure the current state against every clause and each Annex A control you will need. You get a written gap register with an owner and an effort estimate per line.
- 02Risk assessment and treatmentWe build the asset and risk picture with your teams, apply a consistent method, and produce the risk treatment plan and the Statement of Applicability. This is where a certification is won or lost.
- 03Documentation and controlsPolicies, procedures and records, written to be used rather than to be filed. We implement alongside your engineers instead of handing over a template pack.
- 04Awareness and competenceStaff briefings and role-specific training, with the attendance and competence records the standard requires as evidence.
- 05Internal auditA full internal audit against the standard, run the way the certification body will run it, with findings raised as nonconformities and tracked to closure.
- 06Management review and rehearsalWe prepare the management review, assemble the evidence pack, and rehearse the audit with the people who will be interviewed.
- 07Stage 1 — readinessThe certification body reviews your documentation and scope, and confirms you are ready for Stage 2. We support you through it and close what it raises.
- 08Stage 2 — certification auditThe certification body tests whether the ISMS is implemented and effective. On success it issues a certificate on a three-year cycle, with annual surveillance audits and recertification at the end.
What you get from us
- Scope statement and gap register with owners and effort
- Risk assessment, risk treatment plan and Statement of Applicability
- The full documented ISMS — policies, procedures, records
- Internal audit report and closed nonconformities
- Management review pack and the evidence bundle for Stage 2
- Support through Stage 1, Stage 2 and each surveillance audit
Common questions
How long does it take?
For an organisation of under 200 people with a contained scope, six to nine months from kick-off to a Stage 2 audit is realistic. The pacing constraint is rarely documentation; it is that some controls must be seen operating for a period before an auditor can test them.
Can you certify us?
No, and no consultancy can. ISO/IEC 17021-1 bars a certification body from certifying a management system it helped build. That separation is what gives the certificate value. We prepare you and will happily explain what to look for when you select an accredited body.
Do we need every one of the 93 Annex A controls?
No. You select controls to treat the risks your assessment identified, and record every exclusion with its justification in the Statement of Applicability. An organisation that claims all 93 without reasoning usually has not done the risk assessment.
We hold a 2013 certificate. Where does that leave us?
The transition window closed on 31 October 2025, so a 2013 certificate is no longer valid and a transition audit is no longer available. The route now is certification against ISO/IEC 27001:2022. Much of your existing system will carry over — the mapping work is a smaller job than a first implementation.
What happens after we are certified?
The certificate runs for three years with a surveillance audit each year, then a recertification audit. The system has to keep running — internal audits, management reviews, risk reassessment. We support that cycle if you want us to.
Related services
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
Related insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Technical testing
NIST SP 800-115: the four phases, and the one that is not a phase
The four-phase shape behind most credible test methodologies — and the phase that is not fourth at all.