ISO 27001:2022
Full ISMS implementation: scoping, gap assessment, risk assessment and treatment, Statement of Applicability, policy set, internal audit, management review, and support through Stage 1 and Stage 2.
Governance, Risk & Compliance
Most compliance programmes produce a folder of documents that describe an organisation nobody works in. We build the controls first and let the documentation describe what is actually happening.
Getting certified is a solvable problem. Enough consultants, enough templates and enough time in the month before the audit will get almost anyone through a Stage 2. The difficulty arrives afterwards, when the same evidence has to be produced again, and again, and the person who assembled it the first time has moved on and left a shared drive full of screenshots with no dates on them.
This is why we build for the surveillance audit rather than the certification audit. Controls should produce their own evidence as a by-product of operating — access reviews that log themselves, vulnerability scans that record their own history, change approvals that live in the system where changes actually happen. If evidence has to be assembled by hand, it will be assembled by hand once, badly, in the week before the auditor arrives.
The platform side of this matters more than it sounds. SemperWise One™ maps controls to live signals across ISO 27001, SOC 2, HIPAA, GDPR and DPDP, collects the evidence continuously, and tells you the day a control drifts rather than eleven months later. Our security testing feeds the same register, so a penetration test finding and a control failure are the same object rather than two teams’ separate problems.
Coverage
Most clients need one certification and two or three others satisfied contractually. Controls overlap heavily, so we implement once and map to everything.
Full ISMS implementation: scoping, gap assessment, risk assessment and treatment, Statement of Applicability, policy set, internal audit, management review, and support through Stage 1 and Stage 2.
Readiness against the trust services criteria, control design, evidence preparation and auditor liaison — the standard request from North American enterprise buyers.
India’s data protection law: consent and notice architecture, data-principal rights workflows, breach notification readiness and Significant Data Fiduciary obligations where they apply.
Records of processing, lawful basis, DPIAs, subject-rights handling and cross-border transfer mechanisms for Indian companies serving EU customers.
Security and Privacy Rule readiness for healthcare organisations and their business associates, with technical safeguards actually tested rather than merely asserted.
Scope reduction and segmentation review, gap assessment against the current version, and the quarterly testing rhythm that keeps it valid.
Used where a maturity view is more useful than a certificate — common for organisations reporting to a board rather than a regulator.
AI management systems, for organisations whose enterprise customers have started asking how their AI features are governed.
Approach
A first ISO 27001 certification typically takes four to nine months depending on starting position and how much of the organisation is in scope.
What is being certified, which entities and systems are included, and what can be legitimately excluded. Getting this right is the single largest lever on cost.
Where you are against where you need to be, with each gap costed in effort rather than listed as a requirement.
A risk register your management team can actually discuss, with treatment decisions recorded and owned.
Controls built and documented, policies written to match how the organisation works, and evidence collection automated wherever the platform can do it.
Independent technical testing for the controls that require it, then an internal audit and management review that a certification body will accept.
Support through the external audit, then continuous monitoring so the surveillance audit is a review rather than a rebuild.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Every gap with an effort estimate and an owner, so the programme can be planned rather than discovered.
Written for your organisation, in language your staff will follow, not a renamed template pack.
Live, owned and reviewable — the document auditors examine most closely and clients maintain worst.
Controls monitored continuously in SemperWise One™, with evidence gathered as an artefact of operation.
Run properly, documented properly, and accepted by certification bodies.
We are in the room for Stage 1 and Stage 2, and we answer the technical questions so your team does not have to.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
Four to nine months for most organisations, driven by starting position and scope rather than by company size. A company with reasonable IT discipline, a clear scope and an internal owner who can give it real time can be audit-ready in about four months. A company starting from nothing, with a broad scope and no dedicated owner, should plan for nine. The certification body also needs Stage 1 and Stage 2 booked, with a gap between them, which adds calendar time you cannot compress.
Two separate costs. The certification body charges its own audit fee, which depends on scope and headcount and is paid directly to them — we do not mark it up. Our implementation fee depends on how much of the work you can absorb internally: organisations with an existing IT function and an engaged owner pay considerably less than those needing the whole programme delivered. We scope it properly and quote a fixed price rather than an hourly rate that grows.
No, and nobody legitimate can. The certification audit must be performed by an accredited certification body that is independent of whoever implemented the ISMS. We implement, we run your internal audit, and we support you through the external audit — but the certificate is issued by an independent body, and any firm offering to do both is offering you a worthless certificate.
It usually depends on who is asking. European, Indian and Middle Eastern enterprise buyers, and most tender processes, ask for ISO 27001. North American technology buyers ask for SOC 2. If you sell to both, start with ISO 27001 — it is a management system, so it gives you the structure — and add SOC 2 afterwards, which is considerably cheaper in that order than the reverse.
The Digital Personal Data Protection Act 2023 is India’s data protection law. It applies to any organisation processing the digital personal data of individuals in India, and to processing outside India where goods or services are offered to people in India. In practice that is almost every business with Indian customers or Indian employees. The obligations centre on consent and notice, data-principal rights, security safeguards, breach notification and additional duties for organisations designated as Significant Data Fiduciaries.
Yes, and it is a sensible first step — a gap assessment against your existing documentation costs a fraction of a full programme and tells you honestly how far you are. Be prepared for the common finding: the policies are fine, and nothing described in them is happening. Auditors test the operation of controls, not the existence of documents.
No. It makes you consistent, and consistency is a precondition for security, not a substitute for it. A compliant organisation has decided what its controls are and can show they operate. Whether those controls stop a competent attacker is a separate question, which is what testing answers. This is exactly why we do both, and why our testing findings feed the same risk register the compliance programme runs on.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.