ISO 27001 consulting: from gap analysis to certification
We build your Information Security Management System (ISMS) from your actual processes and create the evidence the auditor will ask for alongside it. The engagement is led personally by an ISO/IEC 27001 Lead Auditor who has built ISMS programmes from the ground up five times.
What is ISO/IEC 27001?
ISO/IEC 27001 is the international requirements standard for an Information Security Management System (ISMS). It lets an organisation protect its information assets in a systematic, measurable and sustainable way. The current edition is ISO/IEC 27001:2022; its Annex A contains 93 controls in four themes — organisational, people, physical and technological. The certificate is issued by an accredited certification body after Stage 1 and Stage 2 audits and is valid for three years, with annual surveillance audits.
What ISO/IEC 27001 gives your organisation
Regulatory alignment
Supports NIS2, GDPR, Turkish KVKK and sector obligations from a single system, rather than one project per obligation.
Customer confidence
Partners and customers get third-party assurance that their data is handled properly, and security questionnaires get shorter.
Risk reduction
Structured, prioritised protection against cyber attack, data leakage and operational disruption.
Commercial advantage
Certification is increasingly a precondition in EU tenders and supplier onboarding.
Supply chain access
A common language for entering European supply chains and for group-level security audits.
Security culture
Security embedded across the organisation, not confined to IT; people who know their role.
Seven steps to certification
Lead Auditor expertise and years of operational IT experience make the process fast and effective — and leave behind a system you can run yourselves.
Current state and gap analysis
Existing practice assessed against the requirements and Annex A controls, scored, with a prioritised remediation list.
Risk analysis and treatment plan
Assets, threats, vulnerabilities and impacts analysed; risks prioritised; treatment plan with named owners.
Policy and procedure development
ISMS documentation written to your actual processes; Statement of Applicability (SoA).
Implementation and process improvement
Requirements embedded into live operations, together with the teams who will run them.
Internal audit and management review
A full internal audit cycle before certification, with corrective actions closed.
Certification support
Certification body selection, Stage 1 and Stage 2 attendance, finding response and closure.
Continual improvement
Surveillance audit preparation and periodic review, so the system does not decay between cycles.
Engagement summary
- Typical duration
- 4–9 months, depending on scope and maturity
- Delivered as
- Word and Excel; version-controlled, metadata cleaned, document IDs applied
- Language
- English by default for EU clients; Turkish available
- Can be combined with
- ISO/IEC 27701, ISO 22301, NIS2, GDPR
Our approach
- Cost-effective delivery scaled to mid-sized organisations
- Project management that minimises the load on your team
- Solutions compatible with your existing technical estate
- Focus on both regulatory compliance and operational efficiency
- Statement of Applicability cross-mapped to NIS2 and national law where relevant
What you hold at the end of the engagement
- Scope document and context analysis
- Information security policy and objectives
- Risk management procedure, risk assessment report and treatment plan
- Excel risk tool with dashboard and reference controls
- Statement of Applicability covering all 93 controls
- Access control, cryptography, backup and incident management policies
- Asset inventory and information classification procedure
- Supplier security assessment
- Awareness training and attendance records
- Internal audit programme, plan and report
- Corrective action tracking and management review pack
- Evidence register — a map of the records the auditor will ask for
Questions we are asked
How long does ISO 27001 certification take?
For a mid-sized organisation, typically four to nine months, depending on scope, number of sites and the maturity of existing documentation. The longest item is accumulating records that show the system operating: at least one internal audit and one management review must be completed before the certification audit.
We still hold an ISO/IEC 27001:2013 certificate. What now?
The transition period for certificates issued against the 2013 edition ended on 31 October 2025. A certificate still based on the 2013 edition is no longer valid; the system must be updated to the 2022 edition and go through a certification audit again. A gap analysis against the revised Annex A takes a few days.
Does Infosec Academy issue the certificate?
No. The certificate is issued by an accredited certification body of your choice. Under ISO/IEC 17021-1 certification bodies may not provide consultancy, and we keep that separation strictly. We support you in selecting the body and throughout the audits.
Does ISO/IEC 27001 make us NIS2 compliant?
It covers much of it, but not all. Most Article 21 measures are met by ISO/IEC 27001 controls, but management-body accountability (Article 20), the 24/72-hour reporting chain (Article 23) and the technical detail of the national act need additional work. We cross-map the Statement of Applicability to NIS2 and the national act, so the work is done once.
We have a small team. How much of their time will it take?
We carry the project management and most of the documentation. Your side attends interviews, takes decisions and keeps records. Where it is better for your own team to do part of the work under our oversight — because they will run the system afterwards — we will propose that.
Let us start with a scoping conversation
Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.