The challenge behind the engagement.
This service is for a company whose customers want an ISO/IEC 27001 certificate and that has controls but no management system around them. We define the boundary of your information security management system: which business units, locations, and systems it covers, and who depends on it. We assess your current practice against the standard’s management requirements and its full set of security controls, reusing work you have already done. We build the risk method, the risk register, and the treatment plan, and write the Statement of Applicability that explains why each control is in or out. Before your certification audit we run the internal audit and the management review the standard requires, so both exist when the assessor arrives. The certificate is decided by an independent body, not by us.
CTOs and compliance leads at software, engineering, and managed service companies selling into the UK, EU, or Asia-Pacific, where a tender or an enterprise contract names ISO/IEC 27001, and companies whose 2013-edition certificate lapsed and must start a new initial certification.
What we do.
What you can use.
Fix the ISMS scope customers will read
We define the boundary by business unit, location, and system, list the parties who depend on it, and document the handoffs to functions left outside the scope, so the scope statement matches what your customers expect to see. Controls you already run for other frameworks are mapped across so nothing is built twice.
Assess the management system and its controls
We run the gap assessment as a rehearsal of both audit stages: your documentation first, then interviews and evidence for each security control. We build the risk register and treatment plan, then draft the Statement of Applicability control by control, recording why each is included or excluded and how far it is implemented.
Run the internal audit and prepare for Stage 1
We perform the internal audit the standard requires on your behalf, record any nonconformities and their corrective actions, and facilitate the management review, because the assessor expects both to already exist. You receive the audit report, the minutes, an evidence index by control, and a readiness memo, then support through the certification audit and the annual surveillance visits that follow.
Who it’s for.
When you need it.
- Software, engineering, and managed service firms selling into UK, EU, or APAC markets
- Companies with controls in place but no formal management system around them
- CTOs and compliance leads answering tenders that name ISO/IEC 27001
- Organizations holding a SOC 2 report and extending it toward certification
- A tender or enterprise contract names an ISO/IEC 27001 certificate as required
- A lapsed 2013-edition certificate forces a new initial certification
- Expansion into a market where customers expect a recognized certificate
- Leadership committed to certification and set a Stage 2 target date
What the scope can include.
- 01
Information security management system scope and context, including the required climate consideration
- 02
Gap assessment of the full management system and all of the standard’s security controls
- 03
Risk methodology, risk register, acceptance criteria, and a documented risk treatment plan
- 04
Statement of Applicability justifying the inclusion or exclusion and status of every control
- 05
Policy set, management-system objectives, competence records, supplier requirements, and change-planning records
- 06
Internal audit and management review completed, with nonconformities and corrective actions recorded
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Under 50 employees, one office, mostly cloud tools
About 120–200 hours50–250 employees, two or three offices, mix of cloud and on-site systems
About 200–340 hours250+ employees, several sites or business units in scope
About 340–550 hours- Number of employees, sites, and business units in scope
- Existing policies and controls from SOC 2 or other frameworks
- Number of risks and controls that need new procedures
- How quickly control owners can produce evidence
3–6 months to reach Stage 1 readiness, plus time for the internal audit and management review
Stage 1 and Stage 2 audits are billed by an accredited certification body, roughly $3,000–$16,000+ for smaller firms, with surveillance audits about $6,000–$7,500 each.
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Scope statement and a gap report across the management system and its controls
- Risk register, treatment plan, and Statement of Applicability ready for Stage 1
- Internal audit report and management review minutes with corrective actions tracked
- Evidence index by control, Stage 1 readiness memo, and nonconformity response support after Stage 2
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Can you certify us, or does your internal audit count as the certification audit?
Neither. Only an independent body that is authorized to issue this certificate can grant it, and you can verify any such body, and the certificates it has issued, through the standard’s public register. We prepare you for that audit and never sit on its side for a client we prepared. The internal audit we run is the one the standard requires you to keep; it is performed on your behalf and is not the independent assessment. In the audit itself, the first stage reviews your documentation and readiness while the second tests how your controls actually operate, and the certificate then runs three years with yearly check-ins.
We hold a SOC 2 report. How much of it carries over to ISO/IEC 27001?
Much of the control evidence carries over: access reviews, change management, logging, vendor management, and incident response all map from the Trust Services Criteria to the standard’s controls, and we map them once in the control matrix. What a SOC 2 report does not give you is the management system itself: the documented scope and context, the risk assessment and treatment, the Statement of Applicability, the management-system objectives, the internal audit, and the management review. Those are the parts we build, and they are what the first audit stage checks. Only the current 2022 edition can be certified; every 2013-edition certificate has now expired.
- 2017 Trust Services Criteria (With Revised Points of Focus – 2022) | Resources | AICPA & CIMA
- The Security Rule | HHS.gov
- Guidance on Risk Analysis | HHS.gov
- NIST SP 800-66 Rev. 2: Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide
- PCI Data Security Standard (PCI DSS)
- New Information Supplement: PCI DSS Scoping and Segmentation Guidance for Modern Network Architectures
- ISO/IEC 27001:2022 - Information security management systems
