BlueSteel Cybersecurity

ISO/IEC 27001:2022

ISO 27001

ISO 27001 certifies an Information Security Management System, not a checklist. That distinction is where most programs underestimate the work: the auditor is assessing whether you run a managed system, including the risk treatment, the internal audits and the management reviews.

What the engagement covers

Organisations selling internationally or to enterprise buyers. Typical timeline: 6 to 12 months to certification.

  • Scoping the ISMS so the boundary is defensible and no larger than it needs to be
  • Risk assessment and risk treatment plan, with the Statement of Applicability that follows from it
  • Annex A control implementation against the 2022 control set
  • Internal audit programme and management review, which certification bodies check and clients routinely forget
  • Stage 1 and Stage 2 audit support, and the surveillance cycle afterwards

Phases

Where an engagement sits at any point, in the language your assessor uses.

  • Scoping and gap assessment
  • Risk treatment and control implementation
  • Internal audit and management review
  • Stage 2 passed, certificate issued

Related reading

Common questions

Is ISO 27001 the same as SOC 2?

No. SOC 2 produces an attestation report from a CPA firm about controls over a period. ISO 27001 produces a certificate from an accredited body confirming you operate a management system. Buyers in the US usually ask for SOC 2, buyers outside it usually ask for ISO 27001, and organisations selling to both often need both. The underlying control work overlaps heavily.

What is the Statement of Applicability?

The document listing every Annex A control, whether it applies to you, and why. It is the spine of the certification and the first thing an auditor reads. Written properly it makes the audit shorter; written as a formality it makes it longer.

Does certification expire?

Certificates run on a three year cycle with surveillance audits in between. The system has to keep running, which is why organisations that treat certification as a project rather than a programme struggle at the first surveillance audit.

START HERE

Do not guess how far away you are.

A scored assessment against the ISO 27001 control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, but nothing obliges you to.

See what an assessment covers

5.0 out of 5

Across 17 verified client reviews on Clutch.

  • Quality 4.9
  • Schedule 5.0
  • Cost 4.9
  • Willing to refer 5.0

Read the reviews

Start with a scope

Bring the deadline and who is asking for it. Thirty minutes.