2022 revision

ISO 27001, done for you

ISO 27001 is the international standard for an information security management system. It is the framework European and global buyers ask for, and the one that most rewards being run properly rather than assembled at the last minute.

$990 a month. One framework, start to finish.

What ISO 27001 actually is

ISO 27001 certifies that you operate an information security management system — an ISMS — against a defined scope, with a Statement of Applicability recording which Annex A controls apply and why. Certification is issued by an accredited certification body after a two-stage audit, and is maintained through annual surveillance audits over a three-year cycle.

Who needs it

Companies selling into Europe, the UK and much of Asia, where ISO 27001 is often preferred over SOC 2. Also anyone who wants one certification that a wide range of international buyers already recognise.

How long it takes

Certification requires a functioning ISMS with real records behind it — management reviews, a risk assessment, internal audit — before a certification body will schedule Stage 1. That evidence takes time to accumulate. We will give you a realistic date once we have scoped you, including the parts that depend on your certification body's availability rather than on us.

What we do for your ISO 27001 program

  • Define the ISMS scope and produce the Statement of Applicability, with a written justification for every exclusion
  • Run the risk assessment and maintain the risk treatment plan
  • Draft the policy set the standard requires, tailored to how you actually operate
  • Collect the operating evidence — access reviews, change records, supplier assessments — continuously rather than in a panic before Stage 2
  • Prepare you for Stage 1 and Stage 2, and keep the ISMS alive through surveillance audits

ISO 27001 questions we get asked

Is ISO 27001 better than SOC 2?
Neither is better; they answer different buyers. SOC 2 is an attestation report, most requested in North America. ISO 27001 is a certification against an international standard, more often requested in Europe and Asia. If you are asked for both, much of the underlying evidence is shared, which is what our multi-framework tier is for.
Do you issue the certificate?
No. ISO 27001 certificates are issued by accredited certification bodies, which you engage separately. We build and run the ISMS, prepare the evidence, and support you through both audit stages. We take no referral fee from any certification body.
What is a Statement of Applicability?
The document recording which Annex A controls apply to your ISMS, which do not, and the justification for each decision. Auditors read it closely, and a thin or copy-pasted justification is one of the fastest ways to attract findings.
What happens after certification?
The certificate runs on a three-year cycle with annual surveillance audits. The ISMS has to keep operating — reviews, risk updates, internal audits. That ongoing work is what our monitoring is for, rather than a scramble each year.

Stop project-managing your own audit.

Tell us you need ISO 27001. We take it from there.