ISO 27001 Readiness & Gap Assessment
Rapid assessment of scope, ISMS maturity, Annex A coverage, and evidence readiness.
Deliverables: gap report, risk themes, quick wins, implementation roadmap
Typical duration: 1–2 weeks
ISMS Design (Scope, Context, Governance)
Define ISMS scope, boundaries, roles, governance, and leadership control to make audits smooth.
Deliverables: scope statement, ISMS governance/RACI, policy framework, KPI cadence
Typical duration: 1–3 weeks
Risk Assessment & Treatment
Build a defensible risk method, run risk workshops, and produce actionable risk treatment plans.
Deliverables: risk methodology, risk register, treatment plan, residual risk sign-off pack
Typical duration: 2–4 weeks
Statement of Applicability (SoA)
Create a clean, audit-friendly SoA with clear applicability logic and evidence pointers.
Deliverables: SoA, control mapping, evidence index, implementation tracker
Typical duration: 1–2 weeks
Policies, Standards & Procedures
Build a lean, usable documentation set (not shelfware) aligned to your operating model.
Deliverables: policy suite, key procedures, templates, document control approach
Typical duration: 2–6 weeks
Internal Audit & Management Review
Independent assurance before certification: findings, corrective actions, and management review inputs.
Deliverables: audit plan/report, NCs, corrective action tracker, MR pack
Typical duration: 1–2 weeks
Supplier & Third-Party Risk
Strengthen vendor due diligence, security clauses, and ongoing assurance for critical suppliers.
Deliverables: supplier risk model, due diligence pack, contract clauses
Typical duration: 2–4 weeks
Certification Support (Stage 1 & 2)
Hands-on support to organise evidence, coach process owners, and close audit findings fast.
Deliverables: audit evidence pack, interview coaching, audit attendance
Typical duration: 2–6 weeks