Skip to content
SecuriFii

Management system

ISO/IEC 27001 — Information Security Management

ISO/IEC 27001 is the certificate most enterprise buyers ask for by name. Earning it takes a working management system, not a folder of policies. We build that system with your team, prove it operates, and prepare you for an accredited certification body to assess it.

Standard
ISO/IEC 27001:2022
Annex A controls
93
Control themes
4
Certificate cycle
3 years

What ISO/IEC 27001 actually requires

ISO/IEC 27001 is the international standard for an information security management system — an ISMS. Its core is not a control list but a cycle: you define a scope, assess risk against it, decide how to treat each risk, implement what you decided, measure whether it worked, and correct what did not. Clauses 4 to 10 hold those requirements, and an auditor tests them as a system rather than as a checklist.

Annex A supplies 93 controls in four themes — organisational, people, physical and technological. They are not all mandatory. You select controls to treat identified risk and record every inclusion and exclusion, with reasons, in a Statement of Applicability. The SoA is the document an auditor opens first, because it is where a management system either shows its reasoning or reveals it has none.

The current edition is ISO/IEC 27001:2022. The transition period for the 2013 edition closed on 31 October 2025, so certificates against 2013 are no longer valid and an organisation still holding one needs full certification rather than a transition audit.

What it will ask of you

None of this is paperwork for its own sake — each item is something an auditor will ask to see, and the absence of any one of them is a finding.

  • A scope you can defend

    Which entities, sites, systems and people the ISMS covers, and why the boundary sits where it does. A scope drawn to be convenient rather than coherent is the first thing a competent auditor pulls at.

  • A risk assessment you repeat

    A documented method, applied consistently, producing a risk treatment plan — and re-run on a schedule rather than once before the audit.

  • A Statement of Applicability

    Every one of the 93 Annex A controls included or excluded, each with its reasoning. This is the document an auditor opens first, because it is where a management system either shows its thinking or reveals it has none.

  • Evidence that the system runs

    Internal audits, management reviews, corrective actions and competence records — dated, and spread across the year rather than produced in the fortnight before Stage 2.

Why organisations hold it

  • It clears enterprise procurement and vendor security reviews without a bespoke questionnaire each time.
  • It is recognised internationally, so one certificate answers customers in several jurisdictions.
  • It forces a defensible answer to "which risks did you accept, and who decided" — the question that matters after an incident.
  • It gives the security function a budget argument grounded in a risk assessment rather than in fear.
  • It integrates with ISO 22301 and ISO/IEC 27701, which share a clause structure, so the second system costs a fraction of the first.

Where we come in, and where we stop

ISO/IEC 17021-1 bars a certification body from certifying a management system it helped build. That separation is what makes the certificate worth holding, and it is the line this engagement is drawn around.

Ours

  • Scope, gap assessment and the risk work
  • The Statement of Applicability and the documented ISMS
  • Implementing controls alongside your engineers
  • Internal audit, management review and the evidence pack
  • Rehearsing the audit with the people who will be interviewed
  • Standing beside you through Stage 1, Stage 2 and each surveillance visit

An accredited certification body

  • Stage 1 — reviewing your documentation and readiness
  • Stage 2 — testing whether the ISMS is implemented and effective
  • Issuing the certificate, and the surveillance audits that keep it

How certification works

Steps 1 to 6 are our work. Steps 7 and 8 belong to an accredited certification body, which must be independent of us and of you.

  1. 01Scope and gap assessmentWe agree what the ISMS covers — entities, sites, systems, people — then measure the current state against every clause and each Annex A control you will need. You get a written gap register with an owner and an effort estimate per line.
  2. 02Risk assessment and treatmentWe build the asset and risk picture with your teams, apply a consistent method, and produce the risk treatment plan and the Statement of Applicability. This is where a certification is won or lost.
  3. 03Documentation and controlsPolicies, procedures and records, written to be used rather than to be filed. We implement alongside your engineers instead of handing over a template pack.
  4. 04Awareness and competenceStaff briefings and role-specific training, with the attendance and competence records the standard requires as evidence.
  5. 05Internal auditA full internal audit against the standard, run the way the certification body will run it, with findings raised as nonconformities and tracked to closure.
  6. 06Management review and rehearsalWe prepare the management review, assemble the evidence pack, and rehearse the audit with the people who will be interviewed.
  7. 07Stage 1 — readinessThe certification body reviews your documentation and scope, and confirms you are ready for Stage 2. We support you through it and close what it raises.
  8. 08Stage 2 — certification auditThe certification body tests whether the ISMS is implemented and effective. On success it issues a certificate on a three-year cycle, with annual surveillance audits and recertification at the end.

What you get from us

  • Scope statement and gap register with owners and effort
  • Risk assessment, risk treatment plan and Statement of Applicability
  • The full documented ISMS — policies, procedures, records
  • Internal audit report and closed nonconformities
  • Management review pack and the evidence bundle for Stage 2
  • Support through Stage 1, Stage 2 and each surveillance audit

Common questions

How long does it take?

For an organisation of under 200 people with a contained scope, six to nine months from kick-off to a Stage 2 audit is realistic. The pacing constraint is rarely documentation; it is that some controls must be seen operating for a period before an auditor can test them.

Can you certify us?

No, and no consultancy can. ISO/IEC 17021-1 bars a certification body from certifying a management system it helped build. That separation is what gives the certificate value. We prepare you and will happily explain what to look for when you select an accredited body.

Do we need every one of the 93 Annex A controls?

No. You select controls to treat the risks your assessment identified, and record every exclusion with its justification in the Statement of Applicability. An organisation that claims all 93 without reasoning usually has not done the risk assessment.

We hold a 2013 certificate. Where does that leave us?

The transition window closed on 31 October 2025, so a 2013 certificate is no longer valid and a transition audit is no longer available. The route now is certification against ISO/IEC 27001:2022. Much of your existing system will carry over — the mapping work is a smaller job than a first implementation.

What happens after we are certified?

The certificate runs for three years with a surveillance audit each year, then a recertification audit. The system has to keep running — internal audits, management reviews, risk reassessment. We support that cycle if you want us to.

Related insights