Skip to content

01 · Compliance

ISO 27001 Certification

From no ISMS to a certificate auditors accept.

We run the entire ISO 27001:2022 programme for you: gap analysis, Statement of Applicability, policy set, risk treatment, internal audit, management review, and hands-on support through Stage 1 and Stage 2 with your certification body.

The context

Why this matters

Most SaaS teams meet ISO 27001 for the same reason: an enterprise deal stalls in procurement. The instinct is to buy a compliance tool and hope it fills itself in. It does not, a tool tracks evidence, it does not design a management system, run a risk assessment, or answer an auditor asking why a control was scoped out.

innsecs does the work. We build a lean ISMS sized to your actual company, not a 200-page template written for a bank. Every control we claim in the Statement of Applicability maps to something you genuinely operate, with evidence a Stage 2 auditor can follow without a guided tour.

Because we also run the penetration testing, Annex A 8.8 and 8.29 stop being a paperwork exercise. Your technical vulnerability management and secure-development evidence comes from real testing we performed against your product, not from a policy that says testing happens.

What is covered

Scope of the engagement

  1. 01

    Gap analysis against ISO 27001:2022

    A control-by-control read of where you stand today across all 93 Annex A controls and Clauses 4–10, delivered as a prioritized remediation backlog with owners and effort estimates.

  2. 02

    Scope definition & Statement of Applicability

    We draw the ISMS boundary tightly around the product, environments, and teams that matter, then justify every included and excluded control in language auditors accept.

  3. 03

    Risk assessment & treatment plan

    A repeatable risk methodology, a populated risk register tied to real threats to your architecture, and treatment decisions your leadership actually signs off on.

  4. 04

    Policy & procedure set

    Information security policy, access control, cryptography, supplier security, secure development, incident response, business continuity, and the rest, written to fit how your team already works.

  5. 05

    Control implementation support

    Hands-on help closing the technical gaps: access reviews, logging and monitoring, backup verification, asset inventory, onboarding and offboarding, and vendor due diligence.

  6. 06

    Internal audit & management review

    We run the mandatory internal audit and facilitate the management review, producing the records Stage 1 will ask for on day one.

  7. 07

    Certification body liaison & audit support

    Help selecting an accredited certification body, preparing your team for interviews, and sitting with you through Stage 1 and Stage 2 to handle findings as they come.

What you receive

Deliverables

Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.

  • ISO 27001:2022 gap analysis report with prioritized remediation plan
  • Defined ISMS scope and signed Statement of Applicability
  • Risk assessment methodology, risk register and risk treatment plan
  • Complete policy and procedure library, tailored to your organisation
  • Evidence pack mapped control-by-control to Annex A
  • Internal audit report and management review minutes
  • Stage 1 and Stage 2 audit support, including nonconformity remediation

Questions

ISO 27001 Certification FAQ

No, and neither can any consultancy. The certificate is issued by an accredited certification body, which must be independent of the people who built your ISMS. We prepare you, run the internal audit, and support you through the external audit; the certification body makes the certification decision. We will help you choose and engage one.

For a SaaS company of 10–100 people starting with reasonable engineering hygiene, 12–20 weeks to audit-ready is realistic, plus the certification body's own scheduling for Stage 1 and Stage 2. Companies starting with no policies, no access reviews and no asset inventory should plan toward the longer end.

The standard does not name a pentest outright, but Annex A 8.8 (management of technical vulnerabilities) and 8.29 (security testing in development and acceptance) are extremely hard to evidence convincingly without one. Auditors expect to see it. We include it in the programme rather than leaving you to source it separately.

The tool and the consultancy solve different problems. Compliance platforms collect and monitor evidence very well. They do not scope your ISMS, run a defensible risk assessment, write policies that match your business, conduct your internal audit, or defend a control decision to an auditor. We work alongside whichever platform you use and fill in what it cannot do.

ISO 27001 certificates run on a three-year cycle with surveillance audits each year. We offer ongoing support that covers the annual internal audit, risk register refresh, management review, and surveillance audit preparation so the certificate does not quietly lapse.

Know exactly what an auditor, and an attacker, would find.

Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.