Commercial & Industry / FOCUSED SERVICE

ISO/IEC 27001 Readiness

ISMS scoping, risk treatment, Statement of Applicability, and internal audit ahead of Stage 1 and Stage 2 certification audits to ISO/IEC 27001:2022.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for a company whose customers want an ISO/IEC 27001 certificate and that has controls but no management system around them. We define the boundary of your information security management system: which business units, locations, and systems it covers, and who depends on it. We assess your current practice against the standard’s management requirements and its full set of security controls, reusing work you have already done. We build the risk method, the risk register, and the treatment plan, and write the Statement of Applicability that explains why each control is in or out. Before your certification audit we run the internal audit and the management review the standard requires, so both exist when the assessor arrives. The certificate is decided by an independent body, not by us.

WHEN THIS IS THE RIGHT FIT

CTOs and compliance leads at software, engineering, and managed service companies selling into the UK, EU, or Asia-Pacific, where a tender or an enterprise contract names ISO/IEC 27001, and companies whose 2013-edition certificate lapsed and must start a new initial certification.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Fix the ISMS scope customers will read

We define the boundary by business unit, location, and system, list the parties who depend on it, and document the handoffs to functions left outside the scope, so the scope statement matches what your customers expect to see. Controls you already run for other frameworks are mapped across so nothing is built twice.

Assess the management system and its controls

We run the gap assessment as a rehearsal of both audit stages: your documentation first, then interviews and evidence for each security control. We build the risk register and treatment plan, then draft the Statement of Applicability control by control, recording why each is included or excluded and how far it is implemented.

Run the internal audit and prepare for Stage 1

We perform the internal audit the standard requires on your behalf, record any nonconformities and their corrective actions, and facilitate the management review, because the assessor expects both to already exist. You receive the audit report, the minutes, an evidence index by control, and a readiness memo, then support through the certification audit and the annual surveillance visits that follow.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Software, engineering, and managed service firms selling into UK, EU, or APAC markets
  • Companies with controls in place but no formal management system around them
  • CTOs and compliance leads answering tenders that name ISO/IEC 27001
  • Organizations holding a SOC 2 report and extending it toward certification
WHEN IT’S TIME TO ENGAGE
  • A tender or enterprise contract names an ISO/IEC 27001 certificate as required
  • A lapsed 2013-edition certificate forces a new initial certification
  • Expansion into a market where customers expect a recognized certificate
  • Leadership committed to certification and set a Stage 2 target date
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Information security management system scope and context, including the required climate consideration

  • Gap assessment of the full management system and all of the standard’s security controls

  • Risk methodology, risk register, acceptance criteria, and a documented risk treatment plan

  • Statement of Applicability justifying the inclusion or exclusion and status of every control

  • Policy set, management-system objectives, competence records, supplier requirements, and change-planning records

  • Internal audit and management review completed, with nonconformities and corrective actions recorded

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$18,000–$30,000

Under 50 employees, one office, mostly cloud tools

About 120–200 hours
Mid-size
$30,000–$51,000

50–250 employees, two or three offices, mix of cloud and on-site systems

About 200–340 hours
Large
$51,000–$82,500

250+ employees, several sites or business units in scope

About 340–550 hours
WHAT MOVES THE PRICE
  • Number of employees, sites, and business units in scope
  • Existing policies and controls from SOC 2 or other frameworks
  • Number of risks and controls that need new procedures
  • How quickly control owners can produce evidence
TYPICAL TIMELINE

3–6 months to reach Stage 1 readiness, plus time for the internal audit and management review

Stage 1 and Stage 2 audits are billed by an accredited certification body, roughly $3,000–$16,000+ for smaller firms, with surveillance audits about $6,000–$7,500 each.

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Scope statement and a gap report across the management system and its controls
  • Risk register, treatment plan, and Statement of Applicability ready for Stage 1
  • Internal audit report and management review minutes with corrective actions tracked
  • Evidence index by control, Stage 1 readiness memo, and nonconformity response support after Stage 2

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Can you certify us, or does your internal audit count as the certification audit?

Neither. Only an independent body that is authorized to issue this certificate can grant it, and you can verify any such body, and the certificates it has issued, through the standard’s public register. We prepare you for that audit and never sit on its side for a client we prepared. The internal audit we run is the one the standard requires you to keep; it is performed on your behalf and is not the independent assessment. In the audit itself, the first stage reviews your documentation and readiness while the second tests how your controls actually operate, and the certificate then runs three years with yearly check-ins.

We hold a SOC 2 report. How much of it carries over to ISO/IEC 27001?

Much of the control evidence carries over: access reviews, change management, logging, vendor management, and incident response all map from the Trust Services Criteria to the standard’s controls, and we map them once in the control matrix. What a SOC 2 report does not give you is the management system itself: the documented scope and context, the risk assessment and treatment, the Statement of Applicability, the management-system objectives, the internal audit, and the management review. Those are the parts we build, and they are what the first audit stage checks. Only the current 2022 edition can be certified; every 2013-edition certificate has now expired.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security