Standards / ISO 27001

ISO/IEC 27001:2022 certification, built to pass Stage 2.

An information security management system your auditor accepts and your business can actually run — from gap assessment and Statement of Applicability to internal audit, mock Stage 2 and certification-body support.

ISO/IEC 27001:2022

Certification is an evidence exercise. Most failed audits are documentation and operating-record gaps, not missing technology.

ISO 27001 is the international standard for an information security management system: a governed cycle of scope, risk, controls, audit and improvement. Clients, insurers and tender panels increasingly treat the certificate as the entry ticket, and the same ISMS evidence carries directly into NIS2, DORA and CySEC ICT expectations. We build the system with your team, run a mock Stage 2 against the real criteria, and stay with you through the certification body's audit and the surveillance cycle that follows.

/ KEY.FACTS
Standard
ISO/IEC 27001:2022 — Information security management systems
Companion guidance
ISO/IEC 27002:2022 — control implementation guidance
Annex A controls
93 controls across 4 themes (organisational, people, physical, technological)
Certification cycle
Stage 1 + Stage 2 audit, then surveillance audits and a 3-year recertification
Transition
Certificates against the 2013 edition are no longer valid — 2022 is the current basis
Typical first cycle
4 to 9 months from gap assessment to Stage 2, depending on scope and evidence maturity
Who certifies
An accredited certification body — never the consultancy that built your ISMS
/ READINESS.CHECKLIST

ISO/IEC 27001:2022 readiness checklist

Tick what you already evidence. Download your marked-up copy as a working document — no email required — or send it to us for a scored review.

0%
0 / 38 items
Scope and context (Clause 4)
Leadership and policy (Clause 5)
Risk and Statement of Applicability (Clause 6)
Support and documentation (Clause 7)
Operational controls (Annex A.5 / A.6)
Physical controls (Annex A.7)
Technological controls (Annex A.8)
Assurance and improvement (Clauses 9–10)
/ SEND.FOR.REVIEW

Optional: send your completed checklist to our ISMS team for a free gap review and a realistic certification timeline.

/ CLAUSES

What the management-system clauses demand

CL 4

Context of the organisation

Define what the ISMS covers, the internal and external issues that affect it, the interested parties (regulators, clients, insurers) and their requirements. The scope statement written here is printed on your certificate, so a vague scope creates audit pain later.

CL 5

Leadership

Top management commitment, an approved information security policy, and clear roles and responsibilities. Auditors test this by interviewing leadership, not by reading the policy.

CL 6

Planning

Risk assessment and risk treatment methodology, risk register, Statement of Applicability covering all 93 Annex A controls with justification for exclusions, and measurable security objectives.

CL 7

Support

Resources, competence, awareness, communication and documented information control. Evidence of training and version-controlled documents is a common Stage 2 gap.

CL 8

Operation

Run the risk assessment and treatment on a defined cadence, control planned changes, and manage outsourced processes — including cloud and managed service providers.

CL 9

Performance evaluation

Monitoring and metrics, a complete internal audit programme covering the whole ISMS, and a management review with minuted inputs and outputs. Stage 2 cannot pass without both records.

CL 10

Improvement

Nonconformity and corrective action records with root cause and effectiveness checks, plus demonstrated continual improvement of the ISMS.

/ ANNEX.A

93 controls across four themes

A.5

Organisational controls

37 controls

Policies, roles, supplier and cloud security, threat intelligence, incident management, continuity and legal/regulatory compliance.

A.6

People controls

8 controls

Screening, terms of employment, awareness and training, disciplinary process, remote working and confidentiality agreements.

A.7

Physical controls

14 controls

Perimeters, entry controls, secure areas, equipment siting, clear desk and screen, storage media and secure disposal.

A.8

Technological controls

34 controls

Identity and access, cryptography, logging and monitoring, secure development, configuration, backup, data leakage prevention and web filtering.

/ HOW.WE.HELP

How we take a firm from zero to certified

01

Gap assessment

Weeks 1–3

We measure your current state against every clause and all 93 Annex A controls, and hand back a prioritised remediation plan with owners and effort estimates.

02

Scope and risk

Weeks 3–6

Scope statement, asset and information inventory, risk methodology, risk register and the Statement of Applicability that will anchor your audit.

03

Build and remediate

Weeks 6–20

Policies, procedures and technical controls delivered as working practice, not shelfware — access reviews, logging, backup testing, supplier due diligence, secure development.

04

Operate and audit

Weeks 16–28

Awareness training, internal audit programme, management review, corrective actions and a mock Stage 2 so nothing in the real audit is a surprise.

05

Certification support

Ongoing

Certification body selection, Stage 1 and Stage 2 attendance, findings response, then surveillance-cycle support to keep the certificate alive.

/ FAQ

What firms ask before they commit

How long does ISO 27001 certification take?
For a small to mid-sized firm with a contained scope, four to nine months from gap assessment to the Stage 2 audit is realistic. Organisations with complex cloud estates, in-house development or multiple locations usually need longer, mostly because evidence of controls operating over time cannot be manufactured at the end.
Does ISO 27001 make us NIS2 or DORA compliant?
No, but it does most of the heavy lifting. An ISO 27001 ISMS gives you the governance, risk management, supplier assurance, incident handling and continuity foundations those regimes require. You still need the regime-specific obligations on top: NIS2 management-body accountability and national reporting, or DORA's Register of Information, incident reporting clocks and resilience testing.
Can you certify us yourselves?
No — and neither can any consultancy that builds your ISMS. Certification is issued by an accredited certification body that must be independent of the implementation work. We prepare you, run the mock audit and support you through Stage 1 and Stage 2.
What does the 2022 version change?
ISO/IEC 27001:2022 restructures Annex A into 93 controls across four themes and introduces controls such as threat intelligence, cloud services security, ICT readiness for business continuity, data leakage prevention, configuration management and secure coding. Certificates against the 2013 edition are no longer valid, so all current work targets the 2022 structure.
What do auditors fail organisations on most often?
Missing internal audit coverage, a management review that never happened, a Statement of Applicability that does not match reality, untested backups and access reviews with no evidence. Almost every major nonconformity we see is an evidence problem rather than a technology problem.
/ THECYBERCO.SERVICE

ISO 27001 delivery, from gap assessment to surveillance audits

  • Gap assessment. Clause-by-clause and control-by-control review with a costed remediation roadmap.
  • ISMS build. Scope, risk methodology, register, Statement of Applicability and the full policy set.
  • Control implementation. Access reviews, logging, backup testing, hardening and supplier assurance delivered with your team.
  • Internal audit. Independent internal audit programme and management review packs your auditor will accept.
  • Mock Stage 2. A dry-run audit against the real criteria so findings surface before the certification body arrives.
  • Certification support. Body selection, audit attendance, findings response and surveillance-cycle maintenance.
  • vCISO retainer. Ongoing ownership of the ISMS so the certificate survives its second and third year.
  • Framework reuse. Map ISMS evidence once and reuse it for NIS2, DORA and CySEC ICT expectations.

General information, not certification or legal advice. TheCyberCo prepares and supports organisations for audit; ISO/IEC 27001 certificates are issued only by an accredited certification body independent of the implementation work.

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment