SECOMPSSECOMPS
Home/Services/ISO 27001
CMP 02

ISO 27001 certification.

The international standard for information security management. Heavier than SOC 2 up front, more durable afterwards, and the one European and Asian enterprise buyers recognise immediately.

At a glance

Timeline
6 to 9 months typical
Standard
ISO/IEC 27001:2022 with Annex A controls
Certification
Three-year cycle with annual surveillance audits
Our role
ISMS design, implementation and internal audit
Certification body
Independent, we prepare you for them
01Overview

What this actually is.

ISO 27001 certifies a management system, not a snapshot. That distinction is why it takes longer and why it holds up better: you are building a risk assessment process, a treatment plan and a review cycle that must demonstrably operate, year after year.

02Scope

What we cover.

Scope and contextBoundaries of the ISMS, interested parties, and the business context that determines what risk actually means for you.
Risk assessment methodologyA repeatable method your team can run without us, because you will be running it annually forever.
Statement of ApplicabilityEvery Annex A control justified as applicable or excluded, which is the document certification bodies scrutinise most closely.
Risk treatment planDecisions, owners and dates, tied to real risks rather than to a generic control list.
Policy and procedure setThe mandatory documented information, written to match your operation rather than a template company.
Control implementationTechnical and organisational controls across access, cryptography, operations, supplier and incident management.
Internal auditA full internal audit against the standard before the certification body arrives, so surprises happen with us and not with them.
Management reviewThe governance cycle that certification bodies check first and that most failed attempts never actually ran.
03Fit

Who needs this.

  • Companies selling into Europe, the UK, the Middle East or Asia
  • Organisations already holding SOC 2 and needing international recognition
  • Businesses where a tender or framework agreement requires certification
  • Teams wanting a durable programme rather than an annual scramble
04Questions

Frequently asked.

ISO 27001 or SOC 2?

Geography and buyer. North American enterprise buyers ask for SOC 2. European, UK, Middle Eastern and Asian buyers ask for ISO 27001. If you sell to both, do them together: the control overlap is substantial and the incremental cost of the second is far lower than the first.

What changed in the 2022 revision?

Annex A was restructured from 114 controls into 93 across four themes, with eleven new controls covering threat intelligence, cloud services, secure development and data leakage prevention. Existing certifications had a transition period, and new implementations should target 2022 directly.

Do we need a full-time security person?

Not necessarily, but you need a named owner with real authority. The most common cause of failure is an ISMS assigned to someone with no mandate to change how engineering or HR operate.

How much does certification cost?

Two costs: our readiness fee and the certification body's audit fee, which is driven by headcount and scope. We give you a realistic combined figure at the end of the gap assessment.

Find out what stands between you and certification.

Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.