The challenge
Customers and partners increasingly require you to demonstrate that you handle information securely. ISO/IEC 27001 certification has become a prerequisite in many tenders and business relationships. But building a management system from scratch, understanding the requirements and preparing for a certification audit feels overwhelming without the right support.
What we do
We start with a gap analysis against the ISO/IEC 27001 standard, drawing on the full supporting framework. First we identify what information you need to protect and how critical it is. Then we assess what threats exist and how likely they are. Based on that, we implement the right controls and document everything. We build your management system step by step — using established risk assessment methods, a risk register with identified threats and decided measures, and ongoing follow-up. We train relevant staff and prepare you for the certification audit.
What you get
Gap analysis against the standard
We map where you stand today relative to ISO/IEC 27001 and identify what's missing.
Complete management system
We build policies, processes and controls that meet the standard's requirements — tailored to your business. Based on a structured assessment of your specific risks, so every measure is justified.
Certification preparation
We prepare you for the external audit — reviews, internal audit and corrective actions.
What's included
Considering ISO/IEC 27001?
We'll do a free gap analysis and tell you how far you have to go to certification.
Contact usFrequently asked questions
How long does it take to get certified?
Typically 6–12 months depending on the size of the business and how much is already in place.
Do we have to get certified?
Not necessarily. Many businesses implement the management system without formally certifying. We help you decide what gives the most value.
What do we get?
A complete management system — policies, risk register, controls and internal audit process. Everything documented and ready for the external certification audit.
Do we need to hire an information security officer?
Not necessarily. We can support you on an ongoing basis and help you build internal capability step by step.
We already have GDPR in place — does that help?
Yes. Much of your GDPR work supports ISO 27001 compliance. We identify what already exists and build from there.
How do you prepare us for the audit?
We conduct internal audits, identify gaps and address them before the external auditor arrives. You go in prepared.
Need help with ISO/IEC 27001?
Tell us about your situation and we'll give you an honest assessment. Free of charge, no obligation.