What an engagement actually looks like
The plan below is for an ISO 27001 implementation at a single-site organisation of up to about 150 people. Other services follow the same shape with fewer steps. We agree the real dates with you at scoping and we do not promise a timeline we do not believe.
Scoping call and proposal
Week 0
A 45-minute call to understand your organisation, what is driving the project and what you already have. You receive a written proposal with a fixed scope, fixed fee and timeline within a week.
Gap assessment
Weeks 1 to 2
Interviews with department heads, a review of your documents and systems, and a gap report against the standard with a prioritised plan.
Design
Weeks 2 to 5
Risk assessment, Statement of Applicability, policies and procedures. You review and approve each document rather than receiving a bundle at the end.
Implementation
Weeks 5 to 12
Controls go in, staff are trained, and evidence starts to accumulate. We meet weekly and keep a shared tracker so nothing is a surprise.
Internal audit and management review
Weeks 12 to 14
We audit the system, you hold the management review, and findings are closed.
Certification audit
Weeks 14 to 16
Stage 1 (documentation) and Stage 2 (implementation) with the certification body you have chosen. We are in the room for both.
What we need from you
- One named owner for the project, usually the head of IT, operations or compliance, available two to four hours a week
- Access to the people who run your systems and processes for short interviews
- A management sponsor who will attend the kick-off and the management review
- Decisions within a week when we ask for them, so the plan holds
- Half a day of all staff for awareness training
What we will not do
- Issue the certificate. Only an accredited certification body can do that, after its own audit
- Audit our own implementation work in the same certification cycle
- Sell you software or hardware, or take a commission for recommending it
- Hand you a folder of generic policies and call it an ISMS
- Tell you that you are ready when you are not
Choosing a certification body
The certificate is only worth what the body behind it is worth. Your customers and regulators will look for a certificate from a body accredited by a member of the International Accreditation Forum. In Sri Lanka that includes Bureau Veritas, SGS, TUV, CEYCERT (accredited by the Sri Lanka Accreditation Board) and the Sri Lanka Standards Institution, among others. Cheap certificates from unaccredited issuers exist, and overseas clients increasingly reject them.
We help you request and compare quotes on accreditation, auditor availability, audit days and the three-year cycle cost. The choice is yours, and we have no financial relationship with any of them.
After the certificate
Certification is for three years, with a surveillance audit in each of the first two years and a recertification audit in the third. Each year you need an internal audit and a management review before the auditor arrives. Many clients keep us for exactly that, on a small retainer, through our internal audit and maintenance service.
Want the plan with your dates on it?
Book a scoping call and we will send a written proposal within a week: scope, deliverables, timeline and a fixed fee.
