Six deliberate steps. One certificate. A programme that endures.
Our median client reaches Stage 2 in fourteen weeks. Some move faster; others, with greater complexity, take longer. In every case, the pace is yours.
Discovery
A confidential conversation under NDA. We understand your business, your appetite, your existing controls and the commercial reasons certification is now on the table. You leave with a scoping memorandum — no obligation, no invoice.
- —Confidential scoping memorandum
- —Proposed ISMS scope statement
- —Indicative roadmap and investment
Gap Analysis
A forensic baseline against all 93 Annex A controls of ISO/IEC 27001:2022 and clauses 4–10. Evidence-based, interview-driven, and delivered as a board-ready document with prioritised remediation.
- —Gap analysis report with heat-map
- —Prioritised remediation roadmap
- —Executive briefing pack
Risk & Design
A risk assessment and treatment plan tailored to your threat landscape. An ISMS architecture that reflects how your organisation actually makes decisions — not a template lifted from another client.
- —Risk register and treatment plan
- —Statement of Applicability (SoA)
- —ISMS policy suite
Implementation
Controls deployed alongside your teams. Technical, organisational, people, physical and supplier controls — each with evidence captured as work proceeds, not reconstructed retrospectively.
- —Operational controls embedded
- —Evidence library with auditor index
- —Staff awareness programme
Internal Audit
A full internal audit against the standard, followed by a management review. We rehearse auditor questions with your leaders so the certification body encounters a team that is demonstrably in control.
- —Internal audit report
- —Management review minutes
- —Corrective action programme
Certification
Liaison with an accredited certification body through Stage 1 (documentation review) and Stage 2 (implementation audit). We sit alongside you in every interview. Post-certification, we remain your partner through surveillance audits and recertification.
- —Stage 1 & 2 audit partnership
- —ISO/IEC 27001:2022 certificate
- —Three-year surveillance plan
