What this covers.
We help organizations build defensible, auditable information security management systems. Our approach is pragmatic: control design that matches how your business actually operates, evidence pipelines that survive year-2 surveillance, and an audit experience that doesn't derail engineering. From scoping the ISMS to coaching your team through the certification audit, we own the path.
What we test.
Comprehensive coverage across the categories that matter — combined manual and tool-assisted testing.
Gap Analysis
Annex A and clause-by-clause assessment against your current control posture.
ISMS Design
Scope, policies, risk framework, statement of applicability, and KPI design.
Risk Treatment
Asset-driven risk register, treatment plans, residual-risk acceptance.
Evidence Engineering
Automated evidence pipelines so audit prep takes days, not months.
Internal Audit
Independent internal audit cycles aligned to certification requirements.
Audit Support
Stage-1 and Stage-2 audit coaching, on-call defense, and finding response.
How we run it.
A repeatable, well-documented process so your team always knows what's coming next.
Define ISMS boundary, stakeholders, and certification objectives.
Assess current controls against ISO requirements; produce remediation backlog.
Build policies, controls, and evidence pipelines with your owners.
Independent audit to surface and close findings before certification.
Stage-1 and Stage-2 support; ongoing surveillance audit readiness.
What you receive.
- Gap analysis and remediation backlog
- ISMS policy and procedure library
- Risk register and treatment plan
- Statement of Applicability
- Internal audit report and management review pack
- Stage-1 / Stage-2 audit support
Standards we map to.
Frequently asked.
How long does certification take?+
Typical timelines are 4–9 months depending on scope, control maturity, and evidence availability. We sequence work to hit your target audit date.
Do you work with our certifying body?+
Yes. We work with all major accredited bodies (BSI, Bureau Veritas, DNV, TÜV, etc.) and coordinate logistics on your behalf.