The journey

Six deliberate steps. One certificate. A programme that endures.

Our median client reaches Stage 2 in fourteen weeks. Some move faster; others, with greater complexity, take longer. In every case, the pace is yours.

Discovery

Week 0

A confidential conversation under NDA. We understand your business, your appetite, your existing controls and the commercial reasons certification is now on the table. You leave with a scoping memorandum — no obligation, no invoice.

Deliverables
  • Confidential scoping memorandum
  • Proposed ISMS scope statement
  • Indicative roadmap and investment

Gap Analysis

Weeks 1–3

A forensic baseline against all 93 Annex A controls of ISO/IEC 27001:2022 and clauses 4–10. Evidence-based, interview-driven, and delivered as a board-ready document with prioritised remediation.

Deliverables
  • Gap analysis report with heat-map
  • Prioritised remediation roadmap
  • Executive briefing pack

Risk & Design

Weeks 3–6

A risk assessment and treatment plan tailored to your threat landscape. An ISMS architecture that reflects how your organisation actually makes decisions — not a template lifted from another client.

Deliverables
  • Risk register and treatment plan
  • Statement of Applicability (SoA)
  • ISMS policy suite

Implementation

Weeks 4–11

Controls deployed alongside your teams. Technical, organisational, people, physical and supplier controls — each with evidence captured as work proceeds, not reconstructed retrospectively.

Deliverables
  • Operational controls embedded
  • Evidence library with auditor index
  • Staff awareness programme

Internal Audit

Weeks 10–12

A full internal audit against the standard, followed by a management review. We rehearse auditor questions with your leaders so the certification body encounters a team that is demonstrably in control.

Deliverables
  • Internal audit report
  • Management review minutes
  • Corrective action programme

Certification

Weeks 12–14+

Liaison with an accredited certification body through Stage 1 (documentation review) and Stage 2 (implementation audit). We sit alongside you in every interview. Post-certification, we remain your partner through surveillance audits and recertification.

Deliverables
  • Stage 1 & 2 audit partnership
  • ISO/IEC 27001:2022 certificate
  • Three-year surveillance plan