ISO 27001 implementation and certification readiness
From current state to a passed certification audit, with a fixed scope agreed before we start.
For organisations that are already certified: an independent internal audit, preparation for surveillance and recertification visits, the transition from the 2013 edition to ISO/IEC 27001:2022, and a retained ISMS manager when you do not have one.
A full audit of your ISMS against the standard and your own policies, with a report your certification body will accept as evidence. We audit, and we keep the audit independent: we do not fix the findings in the same engagement unless you ask us to.
A readiness review three to six weeks before the external audit: open nonconformities, overdue risk reviews, missing records and controls that have drifted since the last visit.
Restructuring the Statement of Applicability to the 93 controls, updating the risk treatment plan and policies, and briefing your team on what the auditor will look for under the new edition.
A retained number of days each month to run risk reviews, supplier reviews, incident follow-up, metrics and the management review on your behalf.
From current state to a passed certification audit, with a fixed scope agreed before we start.
Get ready for Sri Lanka’s PDPA, whose core obligations commence on 1 January 2027, and align the work with ISO 27001 so you do it once.
Business impact analysis, continuity plans and exercises that prove the plans work. Certifiable to ISO 22301 if you need the certificate.
Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.