ISO/IEC 27001

An ISMS that passes audit — and matches reality.

We help you build or mature an information security management system that reflects how you actually run, not a binder written for the certifier and forgotten the day after.

What we do

Whether you're pursuing certification for the first time or maturing an existing ISMS, we work from your real operations outward: scope the system honestly, run a gap assessment against the Annex A controls, build the risk assessment and treatment plan, and produce a Statement of Applicability you can defend. We prepare you for the Stage 1 and Stage 2 audits and stay vendor-neutral throughout — the controls we recommend are the ones you need, not the ones someone's paying us to sell.

Where it connects to PQC

The cryptographic inventory from a PQC readiness assessment is direct evidence for ISO 27001's cryptography controls (A.8). Clients often run the two together — the inventory does double duty, and quantum readiness becomes part of the ISMS rather than a separate project.

How we work

  • Gap assessment — where you stand against the standard today, with a prioritized path.
  • Risk assessment & treatment — a risk register and treatment plan that reflect your actual threat landscape.
  • Documentation — policies, the Statement of Applicability, and the evidence your auditor will ask for.
  • Audit readiness — preparation and support through Stage 1 and Stage 2.

Ready to get audit-ready?

Tell us where you are — first certification or maturing an existing ISMS — and we'll map the path.

Talk to us