ISO/IEC 27001:2022 certification, built to pass Stage 2.
An information security management system your auditor accepts and your business can actually run — from gap assessment and Statement of Applicability to internal audit, mock Stage 2 and certification-body support.
Certification is an evidence exercise. Most failed audits are documentation and operating-record gaps, not missing technology.
ISO 27001 is the international standard for an information security management system: a governed cycle of scope, risk, controls, audit and improvement. Clients, insurers and tender panels increasingly treat the certificate as the entry ticket, and the same ISMS evidence carries directly into NIS2, DORA and CySEC ICT expectations. We build the system with your team, run a mock Stage 2 against the real criteria, and stay with you through the certification body's audit and the surveillance cycle that follows.
- Standard
- ISO/IEC 27001:2022 — Information security management systems
- Companion guidance
- ISO/IEC 27002:2022 — control implementation guidance
- Annex A controls
- 93 controls across 4 themes (organisational, people, physical, technological)
- Certification cycle
- Stage 1 + Stage 2 audit, then surveillance audits and a 3-year recertification
- Transition
- Certificates against the 2013 edition are no longer valid — 2022 is the current basis
- Typical first cycle
- 4 to 9 months from gap assessment to Stage 2, depending on scope and evidence maturity
- Who certifies
- An accredited certification body — never the consultancy that built your ISMS
ISO/IEC 27001:2022 readiness checklist
Tick what you already evidence. Download your marked-up copy as a working document — no email required — or send it to us for a scored review.
What the management-system clauses demand
Context of the organisation
Define what the ISMS covers, the internal and external issues that affect it, the interested parties (regulators, clients, insurers) and their requirements. The scope statement written here is printed on your certificate, so a vague scope creates audit pain later.
Leadership
Top management commitment, an approved information security policy, and clear roles and responsibilities. Auditors test this by interviewing leadership, not by reading the policy.
Planning
Risk assessment and risk treatment methodology, risk register, Statement of Applicability covering all 93 Annex A controls with justification for exclusions, and measurable security objectives.
Support
Resources, competence, awareness, communication and documented information control. Evidence of training and version-controlled documents is a common Stage 2 gap.
Operation
Run the risk assessment and treatment on a defined cadence, control planned changes, and manage outsourced processes — including cloud and managed service providers.
Performance evaluation
Monitoring and metrics, a complete internal audit programme covering the whole ISMS, and a management review with minuted inputs and outputs. Stage 2 cannot pass without both records.
Improvement
Nonconformity and corrective action records with root cause and effectiveness checks, plus demonstrated continual improvement of the ISMS.
93 controls across four themes
Organisational controls
Policies, roles, supplier and cloud security, threat intelligence, incident management, continuity and legal/regulatory compliance.
People controls
Screening, terms of employment, awareness and training, disciplinary process, remote working and confidentiality agreements.
Physical controls
Perimeters, entry controls, secure areas, equipment siting, clear desk and screen, storage media and secure disposal.
Technological controls
Identity and access, cryptography, logging and monitoring, secure development, configuration, backup, data leakage prevention and web filtering.
How we take a firm from zero to certified
Gap assessment
We measure your current state against every clause and all 93 Annex A controls, and hand back a prioritised remediation plan with owners and effort estimates.
Scope and risk
Scope statement, asset and information inventory, risk methodology, risk register and the Statement of Applicability that will anchor your audit.
Build and remediate
Policies, procedures and technical controls delivered as working practice, not shelfware — access reviews, logging, backup testing, supplier due diligence, secure development.
Operate and audit
Awareness training, internal audit programme, management review, corrective actions and a mock Stage 2 so nothing in the real audit is a surprise.
Certification support
Certification body selection, Stage 1 and Stage 2 attendance, findings response, then surveillance-cycle support to keep the certificate alive.
What firms ask before they commit
- How long does ISO 27001 certification take?
- For a small to mid-sized firm with a contained scope, four to nine months from gap assessment to the Stage 2 audit is realistic. Organisations with complex cloud estates, in-house development or multiple locations usually need longer, mostly because evidence of controls operating over time cannot be manufactured at the end.
- Does ISO 27001 make us NIS2 or DORA compliant?
- No, but it does most of the heavy lifting. An ISO 27001 ISMS gives you the governance, risk management, supplier assurance, incident handling and continuity foundations those regimes require. You still need the regime-specific obligations on top: NIS2 management-body accountability and national reporting, or DORA's Register of Information, incident reporting clocks and resilience testing.
- Can you certify us yourselves?
- No — and neither can any consultancy that builds your ISMS. Certification is issued by an accredited certification body that must be independent of the implementation work. We prepare you, run the mock audit and support you through Stage 1 and Stage 2.
- What does the 2022 version change?
- ISO/IEC 27001:2022 restructures Annex A into 93 controls across four themes and introduces controls such as threat intelligence, cloud services security, ICT readiness for business continuity, data leakage prevention, configuration management and secure coding. Certificates against the 2013 edition are no longer valid, so all current work targets the 2022 structure.
- What do auditors fail organisations on most often?
- Missing internal audit coverage, a management review that never happened, a Statement of Applicability that does not match reality, untested backups and access reviews with no evidence. Almost every major nonconformity we see is an evidence problem rather than a technology problem.
ISO 27001 delivery, from gap assessment to surveillance audits
- Gap assessment. Clause-by-clause and control-by-control review with a costed remediation roadmap.
- ISMS build. Scope, risk methodology, register, Statement of Applicability and the full policy set.
- Control implementation. Access reviews, logging, backup testing, hardening and supplier assurance delivered with your team.
- Internal audit. Independent internal audit programme and management review packs your auditor will accept.
- Mock Stage 2. A dry-run audit against the real criteria so findings surface before the certification body arrives.
- Certification support. Body selection, audit attendance, findings response and surveillance-cycle maintenance.
- vCISO retainer. Ongoing ownership of the ISMS so the certificate survives its second and third year.
- Framework reuse. Map ISMS evidence once and reuse it for NIS2, DORA and CySEC ICT expectations.
General information, not certification or legal advice. TheCyberCo prepares and supports organisations for audit; ISO/IEC 27001 certificates are issued only by an accredited certification body independent of the implementation work.