Services

ISO 27001 implementation and certification readiness

We build your information security management system (ISMS) from where you are today to a passed Stage 2 audit. The scope, the deliverables and the fee are agreed before work begins, and we stay with you until the certificate is issued.

What we do

  1. Scoping and gap assessment

    We agree the ISMS scope with you (which sites, systems and teams are in), then assess your current controls against ISO/IEC 27001:2022 and its 93 Annex A controls. You get a written gap report and a plan with dates.

  2. Risk assessment and Statement of Applicability

    We run the risk assessment with your team, decide which controls apply and why, and produce the Statement of Applicability. It is the first document the certification auditor asks for.

  3. Policies, procedures and records

    We write or adapt the documents you actually need, in plain language and sized to your organisation. A 60-person software company does not need a 200-page policy set.

  4. Control implementation

    We work alongside your IT and operations staff to put the controls in place: access control, change management, supplier security, logging, backups, incident handling and the rest. Where a tool is needed we say so. Where it is not, we say that too.

  5. Awareness training

    Short sessions for all staff and a longer session for the people who will run the ISMS day to day.

  6. Internal audit and management review

    We perform the internal audit required by clause 9.2, help you hold the management review, and close the findings before the certification body arrives.

  7. Certification audit support

    We help you choose an accredited certification body, prepare the evidence pack, and sit with you through Stage 1 and Stage 2.

What you receive

  • Gap assessment report and project plan
  • ISMS scope statement, information security policy and supporting policies
  • Risk assessment method, risk register and risk treatment plan
  • Statement of Applicability covering all 93 Annex A controls
  • Procedures and templates for incidents, access, change, supplier review, backup and continuity
  • Internal audit report and management review minutes
  • Evidence index mapped to each clause and control

Common questions

Do you issue the certificate?
No. Certificates are issued by accredited certification bodies after an independent audit. We prepare you for that audit and we do not audit our own implementation work. In Sri Lanka you can choose from bodies such as Bureau Veritas, SGS, CEYCERT and the Sri Lanka Standards Institution, and we will help you compare them on accreditation, cost and audit schedule.
We hold a certificate to the 2013 edition. What does that mean now?
The 2013 edition was withdrawn, and every certificate had to transition to ISO/IEC 27001:2022 by 31 October 2025. If yours did not, it is no longer valid. We run transition projects that update the risk assessment, the Statement of Applicability and the controls to the 2022 structure, usually in six to ten weeks.
How much of our time does it take?
Plan for one named owner at two to four hours a week, short interviews with department heads during the gap and risk assessments, and about half a day for all staff during awareness training.
What does it cost?
We quote a fixed fee after a 45-minute scoping call, based on headcount, number of sites and how much you already have in place. The certification body charges its own audit fees separately. We will give you a realistic range for those too.

Related services

Business continuity and ISO 22301

Business impact analysis, continuity plans and exercises that prove the plans work. Certifiable to ISO 22301 if you need the certificate.

Not sure where you stand? Start with a scoping call.

Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.