• Scope definition and context of the organization
• Gap assessment vs. ISO 27001:2022 & ISO 27002 controls
• Risk assessment methodology and treatment plan
• Statement of Applicability (SoA) development
• Policy, procedure and control design review
• Executive and stakeholder briefings
• ISMS awareness for staff and managers
• ISO 27001/27002 control implementation workshops
• Auditor readiness and internal audit skills
• Role-based training: risk owners, control owners
• ISMS implementation roadmap & PMO support
• Control implementation and evidence collection
• Metrics, monitoring and continual improvement
• Internal audit and management review preparation
• External audit-day readiness and support
• Understand business context & interested parties
• Define ISMS scope & objectives
• Establish governance & responsibilities
• Gap assessment vs. ISO 27001:2022
• Risk assessment & SoA drafting
• Remediation roadmap & milestones
• Policies, procedures & controls rollout
• Training & awareness activities
• Evidence collection & monitoring
• Internal audit & management review
• Certification body coordination
• Stage 1/2 prep, fixes & support
• ISMS Scope & Context Document
• Gap Assessment Report + prioritized roadmap
• Risk Register, criteria & treatment plan
• Statement of Applicability (SoA)
• Policy & procedure set (drafts/templates)
• Control design review & mapping matrix
• Tailored curricula & slide decks
• Hands-on control implementation workshops
• Attendance records & awareness materials
• Auditor readiness exercises
• Role-based guides for risk/control owners
• Implementation plan & PM cadence
• Evidence repository structure & templates
• KPI/metrics for ISMS performance
• Internal audit checklists & reports
• Management review pack
• Pre‑audit readiness review & fixes
Most engagements complete within 8–16 weeks, depending on scope and readiness.
Small teams: 4–8 weeks · Mid-size: 8–16 weeks · Enterprise: 16–24+ weeks.
Do you guarantee certification?
Certification decisions are made by accredited certification bodies. We maximize readiness by aligning your ISMS to ISO 27001 requirements, preparing evidence, and supporting you through Stage 1/2 audits.
Can you work with our existing tools and policies?
Yes. We adapt to your environment (e.g., Confluence, SharePoint, GRC tools) and can improve or replace artifacts where needed.
Do you provide training certificates?
We issue attendance records and, on request, individualized certificates for awareness and role-based sessions.
What if we only need a gap assessment?
We can deliver stand-alone assessments with a prioritized roadmap, which you can implement in-house or with our support later.
Do you work remotely?
Yes. We support clients worldwide via remote delivery, with on-site options where required.