At full delivery capacity until the end of 2026.
ISO 27001 readiness
We build the ISMS, implement the controls, and prepare you for audit over time - structured so the system holds up when an auditor, a customer, or an incident tests it.
ISO 27001 works as a way of running security that your team uses day to day, not as a document project.
Where This Fits
Who this is for
This is you
Your company
- 20-50+ people and growing
- Security is becoming a real function
- You face formal demands for evidence
What is pushing you
- Enterprise customers expect certification
- Tenders require ISO 27001
- Investors raise it during due diligence
- Internal maturity makes it the next step
How we do it
-
Instead of a template ISMS bought off the shelf, we build an ISMS scoped to your real business.
-
Instead of treating certification as a one-off documentation exercise, we give every control a named, accountable owner.
-
Instead of a certificate over a system nobody actually runs, we leave you with a system that holds up at the next audit.
The Problem
The certificate is not the system
Most failed ISO 27001 projects fail the same way. The company buys a policy pack, fills in the names, and treats the standard as a documentation exercise. Then the auditor asks for the evidence that a control ran, and there is none, because nobody was ever made responsible for running it.
ISO 27001 is two things at once. Clauses 4 to 10 describe a management system ISMS Information Security Management System. The policies, risks, roles and review cycles that run security as a normal business function, rather than as a project that ends. : how security gets decided, reviewed and improved. Annex A lists the controls that system chooses from. A template gives you a version of the second and none of the first, and the first is what an auditor tests hardest.
Scope and context
Which parts of the business, which locations, which systems, and which interested parties the ISMS covers. A scope drawn too wide costs money for years; drawn too narrow, a customer rejects the certificate.
Risk assessment and treatment
A repeatable method, a risk register that names real risks rather than categories, and a treatment plan that says what is being done, by whom, and by when.
Statement of Applicability
Every Annex A control marked as applicable or not, with the justification and the implementation status. It is the first document an auditor opens and the one most often written last.
Roles, competence and awareness
Named owners for the ISMS and for each control, evidence that the people holding those roles are competent to hold them, and awareness activity that actually happened.
Internal audit and management review
An internal audit programme covering the whole system over the cycle, and a management review with real inputs: risks, incidents, objectives, audit findings, and decisions taken.
Nonconformity and improvement
Findings recorded, root causes identified, corrective actions closed. An ISMS with no findings in a year is not a clean system, it is an unused one.
Annex A adds 93 controls in four themes. You do not implement all of them. You justify each one, in writing, in the Statement of Applicability Statement of Applicability (SoA) The document listing every Annex A control, whether it applies to you, why, and whether it is implemented yet. Auditors and enterprise customers both read it first. .
Organisational
37 controls
Policies, supplier and cloud security, incident management, continuity, classification, and legal and contractual duties.
People
8 controls
Screening, terms of employment, awareness, disciplinary process, and what happens when someone leaves or changes role.
Physical
14 controls
Secure areas, equipment, clear desk and screen, media handling, and the physical side of remote working.
Technological
34 controls
Access control, cryptography, logging and monitoring, secure development, vulnerability management, backup, and network security.
The Audit
What certification actually tests
Certification is issued by an independent accredited body, not by an advisor. Knowing what that body looks at is what turns a readiness project from a guess into a plan.
Stage 1: documentation review
The auditor checks that the management system exists on paper and is ready to be tested: scope, policy set, risk assessment, Statement of Applicability, internal audit programme, and management review. The output is a list of what must be closed before Stage 2.
Stage 2: implementation audit
The auditor samples the controls and asks for evidence that they ran. Not "do you have an access review policy" but "show me the last three access reviews, and show me what happened to the accounts you found". This is where a template ISMS fails.
Surveillance and recertification
Certification runs on a three-year cycle with a surveillance audit in each of the two intervening years. The system has to keep producing evidence between audits, which is the part that lapses when the readiness project ends and nobody owns the ISMS.
Where our work stops is worth stating plainly. We build the system, prepare the evidence and coordinate with the certification body. We do not audit you and we do not issue the certificate: an advisor who does both is a conflict the accreditation rules exist to prevent. If certification is not actually the goal and you want working controls first, the CIS Controls baseline is the cheaper honest answer, and it converts into an ISMS later.
The Roadmap
Five phases
Readiness assessment
Scope, interested parties, customer and security drivers, an asset and process overview, existing controls, and a clear gap analysis against ISO 27001.
ISMS foundation
ISMS scope, risk methodology, asset register, risk register, statement of applicability, the policy set, and named control owners.
Control implementation
Access control, supplier management, incident management, backup and recovery, vulnerability management, logging and monitoring, security awareness, and secure development where relevant.
Evidence and internal audit preparation
Evidence collection, management review, internal audit support, corrective actions, and coordination with the certification body.
Retainer maintenance
Ongoing ISMS operations, quarterly risk register updates, control checks, supplier evidence, and audit readiness between certification cycles.
Start Here
How to start
The same four steps for every engagement here. You can stop after step two and owe nothing.
- 1
Run the Discovery Calculator
FreeAbout four minutes, no sign-up. It runs in your browser and nothing is sent anywhere unless you choose to send it.
- 2
Send me the result
FreeI reply with a recommendation for your situation - including when the honest answer is that you do not need me yet.
- 3
Starter Assessment (€1,900) or Starter Month (€2,900)
Fixed price, one-offThe paid entry, and the only one. It ends with a roadmap of the major milestones and a recommended retainer tier.
- 4
Continue on a retainer
From €950 a monthIf the roadmap makes sense to both of us, implementation runs inside the retained engagement. Part of what you paid for the starter door is credited against it.
How this becomes a retainer
An ISMS only holds if it is operated: the review cycle, the risk register, and audit readiness between certification cycles all keep running. The starter door produces the roadmap; the retained engagement is where it gets built. One senior practitioner, a fixed monthly hour cap, and a tier set after the starter door rather than guessed before it.
What is not included
Certification is issued by an independent accredited body, not by us. We prepare you for it and coordinate with the certification body; management owns risk acceptance and the final decisions.
Certification is a milestone. The real product is an ISMS your company actually uses.