We support you in setting up an Information Security Management System (ISMS) aligned with ISO/IEC 27001, maturing an existing one, and getting ready for the certification audit.

// Why it matters

Why ISO 27001 Consulting matters

Information security is more than technical controls: it needs ownership, processes, risk management and continual improvement. ISO 27001 brings these together in an auditable management system aligned with your goals. It is widely chosen to build trust with customers and partners and to meet tender and contract requirements.

// Scope

What does it cover?

Scope and context

We define the ISMS scope based on your objectives, stakeholder expectations and legal requirements.

Gap analysis

We compare your current state with the standard and prioritise the gaps.

Risk assessment

We assess assets, threats and vulnerabilities and prepare the risk treatment plan.

Documentation

We write policies, procedures and instructions that fit how your organisation really works.

Implementing controls

We select the applicable Annex A controls and support their implementation.

Internal audit and review

We set up internal audit and management review and prepare you before the certification audit.

// Method

How do we proceed?

  1. Kick-off and scopeWe define objectives, scope and the project team, and agree the timeline.
  2. Gap analysis and risk assessmentWe map the current state and risks and set the order of work.
  3. Building the systemWe put policies, procedures, controls and awareness activities in place.
  4. Internal audit and reviewWe test the system with an independent view and close the findings.
  5. Audit readiness and sustainingWe prepare you for the certification audit and set up the continual improvement cycle.
// Deliverables

What do we deliver?

  • Gap analysis report
  • Risk assessment and treatment plan
  • Statement of Applicability (SoA)
  • Policy, procedure and instruction set
  • Internal audit report
  • Management review outputs
// Who is it for?

Who is this service for?

IT and software companiesOrganisations whose tenders and contracts require ISO 27001Service providers that process customer dataPublic institutionsOrganisations that want to raise their security maturity
// FAQ

Frequently asked questions

Do you issue the certificate?

No. ISO 27001 certificates are issued by independent certification bodies. We provide consulting to build the system and prepare you for the audit.

How long does it take?

It depends on your scope, size and current maturity. After the gap analysis we give you a realistic timeline.

Can you improve an existing system?

Yes. We also help mature an existing ISMS and run internal audits.

// Related services

Services you can combine

// Information request

Get information about ISO 27001 Consulting

Fill in the short form and we will get back to you as soon as possible. For a more detailed preliminary assessment you can also use the needs-analysis form below.

    Open the detailed needs-analysis form

    If you share your current situation in a few questions, we can give you a clearer preliminary assessment and scope proposal.

      Existing documentation

      Let’s talk about ISO 27001 Consulting

      Share your needs and current situation, and we will define the right scope and roadmap together.