Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

ISO/IEC 27001:2022 consulting

ISO 27001 consulting: from gap analysis to certification

We build your Information Security Management System (ISMS) from your actual processes and create the evidence the auditor will ask for alongside it. The engagement is led personally by an ISO/IEC 27001 Lead Auditor who has built ISMS programmes from the ground up five times.

ISO/IEC 27001:202293 Annex A controlsNIS2 Article 21 mappingGDPR
In brief

What is ISO/IEC 27001?

ISO/IEC 27001 is the international requirements standard for an Information Security Management System (ISMS). It lets an organisation protect its information assets in a systematic, measurable and sustainable way. The current edition is ISO/IEC 27001:2022; its Annex A contains 93 controls in four themes — organisational, people, physical and technological. The certificate is issued by an accredited certification body after Stage 1 and Stage 2 audits and is valid for three years, with annual surveillance audits.

Why it matters

What ISO/IEC 27001 gives your organisation

Regulatory alignment

Supports NIS2, GDPR, Turkish KVKK and sector obligations from a single system, rather than one project per obligation.

Customer confidence

Partners and customers get third-party assurance that their data is handled properly, and security questionnaires get shorter.

Risk reduction

Structured, prioritised protection against cyber attack, data leakage and operational disruption.

Commercial advantage

Certification is increasingly a precondition in EU tenders and supplier onboarding.

Supply chain access

A common language for entering European supply chains and for group-level security audits.

Security culture

Security embedded across the organisation, not confined to IT; people who know their role.

How we deliver

Seven steps to certification

Lead Auditor expertise and years of operational IT experience make the process fast and effective — and leave behind a system you can run yourselves.

  1. Current state and gap analysis

    Existing practice assessed against the requirements and Annex A controls, scored, with a prioritised remediation list.

  2. Risk analysis and treatment plan

    Assets, threats, vulnerabilities and impacts analysed; risks prioritised; treatment plan with named owners.

  3. Policy and procedure development

    ISMS documentation written to your actual processes; Statement of Applicability (SoA).

  4. Implementation and process improvement

    Requirements embedded into live operations, together with the teams who will run them.

  5. Internal audit and management review

    A full internal audit cycle before certification, with corrective actions closed.

  6. Certification support

    Certification body selection, Stage 1 and Stage 2 attendance, finding response and closure.

  7. Continual improvement

    Surveillance audit preparation and periodic review, so the system does not decay between cycles.

Engagement summary

Typical duration
4–9 months, depending on scope and maturity
Delivered as
Word and Excel; version-controlled, metadata cleaned, document IDs applied
Language
English by default for EU clients; Turkish available
Can be combined with
ISO/IEC 27701, ISO 22301, NIS2, GDPR

Our approach

  • Cost-effective delivery scaled to mid-sized organisations
  • Project management that minimises the load on your team
  • Solutions compatible with your existing technical estate
  • Focus on both regulatory compliance and operational efficiency
  • Statement of Applicability cross-mapped to NIS2 and national law where relevant
What you receive

What you hold at the end of the engagement

  • Scope document and context analysis
  • Information security policy and objectives
  • Risk management procedure, risk assessment report and treatment plan
  • Excel risk tool with dashboard and reference controls
  • Statement of Applicability covering all 93 controls
  • Access control, cryptography, backup and incident management policies
  • Asset inventory and information classification procedure
  • Supplier security assessment
  • Awareness training and attendance records
  • Internal audit programme, plan and report
  • Corrective action tracking and management review pack
  • Evidence register — a map of the records the auditor will ask for
Frequently asked questions

Questions we are asked

How long does ISO 27001 certification take?

For a mid-sized organisation, typically four to nine months, depending on scope, number of sites and the maturity of existing documentation. The longest item is accumulating records that show the system operating: at least one internal audit and one management review must be completed before the certification audit.

We still hold an ISO/IEC 27001:2013 certificate. What now?

The transition period for certificates issued against the 2013 edition ended on 31 October 2025. A certificate still based on the 2013 edition is no longer valid; the system must be updated to the 2022 edition and go through a certification audit again. A gap analysis against the revised Annex A takes a few days.

Does Infosec Academy issue the certificate?

No. The certificate is issued by an accredited certification body of your choice. Under ISO/IEC 17021-1 certification bodies may not provide consultancy, and we keep that separation strictly. We support you in selecting the body and throughout the audits.

Does ISO/IEC 27001 make us NIS2 compliant?

It covers much of it, but not all. Most Article 21 measures are met by ISO/IEC 27001 controls, but management-body accountability (Article 20), the 24/72-hour reporting chain (Article 23) and the technical detail of the national act need additional work. We cross-map the Statement of Applicability to NIS2 and the national act, so the work is done once.

We have a small team. How much of their time will it take?

We carry the project management and most of the documentation. Your side attends interviews, takes decisions and keeps records. Where it is better for your own team to do part of the work under our oversight — because they will run the system afterwards — we will propose that.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.