ISO 27001 Consulting
An ISMS that actually turns.ISO 27001 punishes improvisation: the certification body audits your management system's operating history, not your intentions. You need someone who has built ISMSs that pass Stage 2 — and who does the building, not just the advising.
Book a Call- 01
Scope and risk foundation
ISMS scope, risk methodology, and the initial risk assessment — built in working sessions with your team so the register reflects your real environment, not a template's.
- 02
SoA and implementation
All 93 Annex A controls dispositioned with justifications, then implemented in sprints on the platform: policies written, controls configured, evidence flowing.
- 03
The loop, operated
We run the clauses certification bodies actually test: internal audit, management review, corrective actions — producing the dated records Stage 2 samples.
- 04
Certification management
Certification-body selection, Stage 1 documentation review, Stage 2 fieldwork support, and the surveillance-audit calendar for years two and three.
- ISMS documentation set: scope, policy, risk methodology, risk register
- Statement of Applicability with per-control justifications
- Implemented controls with continuous evidence collection
- Completed internal audit and management review with records
- Certification-body selection and both audit stages managed
4–6 months to Stage 2, depending on scope and start point
- Companies selling into Europe or APAC where the certificate is table stakes
- SOC 2 holders adding ISO 27001 on the same control set
- Teams that stalled at the risk-assessment or internal-audit clauses
ISO 27001’s open secret: Stage 2 failures are rarely about missing controls — they’re about a management system with no operating history. The internal audit that happened the week before, the management review with no decisions, the risk register created retroactively; certification auditors read timestamps the way SOC 2 auditors do. Our engagements build the loop early and run it for real, so by Stage 2 your ISMS has months of genuine history — which is the actual product the certificate represents.
Framework Implementation — Implement SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR from one control set. Cross-framework mapping eliminates duplicate evidence work as you expand.
Risk Assessments — Run structured risk assessments, maintain a living risk register with owners and treatments, and generate the risk documentation every framework demands.
We have SOC 2 — how much of ISO 27001 is already done?
Most of the technical controls; little of the management system. The ISMS clauses — risk methodology, SoA, internal audit, management review — are net-new work, but with evidence mapping the combined program costs far less than two separate ones.
Do you perform the internal audit?
We run it with appropriate independence from the implementation work, or coordinate a third party if your certification body prefers stricter separation — decided upfront so Stage 1 raises no eyebrows.
What does ISO 27001 consulting cost?
Fixed scope after the scoping call. The honest comparison is against a compliance hire plus a certification consultant plus the calendar cost of learning the standard on the job.