ISO 27001

Certification that describes what you do.

We take organisations in Pakistan and the Gulf from a first gap assessment to a management system an accredited body can certify, built around how the business actually runs rather than around a template.

Gap assessmentScope and statement of applicabilityEvidence modelInternal audit
Be clear what the certificate is

It certifies a management system, against a scope you choose.

That is worth understanding before you start, because the scope decision shapes everything that follows and is the one most often made carelessly. Two certified organisations can have very different security postures and both certificates are valid.

Scope too wide

Every system in the organisation pulled in, an eighteen month programme, and a team that loses its sponsor in month seven.

Scope too narrow

A certificate that technically holds and does not cover the service your customer is asking about, which they will notice when they read the statement of applicability.

A policy set nobody follows

Documents copied from a template that describe a different organisation. The gap between the document and the practice is where most findings live.

How the engagement runs

From gap assessment to the certification audit.

01

Scope and gap assessment

What is being certified and why, then an honest read of where you stand against Annex A. The scope decision is made deliberately here, with the commercial reason for certification on the table, because that reason is what should determine it.

02

Risk assessment and statement of applicability

A risk method your own people can run again next year without us, and a statement of applicability that reflects real decisions rather than every control marked applicable to avoid an argument.

03

Controls, policies and the evidence model

Policies drafted to describe what your organisation actually does, and evidence produced as a by product of normal work. Evidence that depends on somebody remembering to collect it stops happening the first busy quarter.

04

Internal audit and management review

Run properly rather than as a formality, because these are the two things a certification body examines first and the two most often produced the week before.

05

Certification audit support

Stage one and stage two, with us retrieving evidence alongside your team. We do not issue certificates and we are not an accredited body, so we will help you choose one and we have no interest in which you pick.

If you also answer to a national framework

State the control once and let it answer both.

Most organisations we work with answer to more than one obligation. Running a separate programme per framework is how a small team loses a year, and the four copies of one answer drift apart until they genuinely disagree.

We map the overlap explicitly, so evidence gathered for ISO counts everywhere else that asks for it. For organisations in Pakistan that usually means PISF, and in Qatar the National Information Assurance programme our ComplianceVault work covers.

SCOPE DELIBERATELY

Driven by the commercial reason you are certifying, not by what is easiest to pass.

YOUR OWN SYSTEM

A method your people can run next year without calling us back.

INDEPENDENT OF THE AUDITOR

We prepare you. We do not certify, and we have no stake in which body you choose.

Questions we get asked

Before you get in touch

The questions that come up most often, answered the way we would answer them on a call.

Do you issue the certificate?

No. Certification comes from an accredited body, and we are not one. We prepare you, help you choose a body, and sit with you through stage one and stage two. We have no stake in which body you pick.

How do we decide the scope?

From the commercial reason you are certifying. A tender, a customer requirement or a regulator each point at a different scope, and that decision does more to determine the length of the programme than anything else.

Should we start with ISO 27001 or NIST CSF?

They do different jobs. ISO 27001 is a certifiable management system and answers somebody outside. NIST CSF describes where you stand and answers your own leadership. If a contract is driving this, it is almost always ISO 27001.

We failed a surveillance audit. Can you help?

Yes, and a failed audit is an unusually clear list of what to do next. Organisations that read the findings honestly tend to come out of the following audit in a much better position than they went into the first.

What happens after certification?

The system has to keep running, which is the part most programmes underestimate. We design the evidence model so it is produced as a by product of normal work rather than depending on somebody remembering to collect it.

Start with the reason

Tell us why you are certifying and we will tell you what it takes.

A tender, a customer requirement, a regulator, or a decision to put the house in order. Each one points at a different scope, and getting that right at the start is most of the difference between a six month programme and an eighteen month one.