ISO 27001
From compliance burden to certification, in a focused programme fitted to your organisation.
I built the compliance core of Secured by FM CyberSecurity, and I have taken Norwegian SMBs from zero to certification-ready in four to six weeks. ISO 27001 is a big job, but it does not have to be a slow one. What follows is the shape of a focused programme.
What we deliver
-
Gap analysis against ISO 27001:2022We walk the Annex A controls against today's operation and document which are missing, which exist informally, and which are ready for the auditor.
-
Statement of ApplicabilityAn SoA built on the real scope, with a written justification per control for inclusion or exclusion, not a template with your name pasted on top.
-
ISMS documentationPolicies, procedures, and roles written for your organisation, not for the auditor. We own the template set and keep it alive between audits.
-
Control implementation with technical ownersEvery control gets a named customer-side owner and a concrete action plan, tied to the technical practices FM CyberSecurity already operates.
-
Internal audit and management reviewWe run the internal audit, document findings, and prepare the management review so the minutes are ready before the certification auditor arrives.
-
A GRC tool that keeps controls aliveWe set up Kertos or ServiceNow GRC so evidence accrues continuously, not as a panic sprint the week before the auditor shows up.
How we deliver this service
- In a project
A certification programme with a fixed scope, from gap analysis through the certification audit.
- As part of a service
Included in the Secured by FM CyberSecurity bundle with a certification guarantee. We cover the next attempt if you do not pass the certification audit within the agreed window.
- In a role at the customer
An ISMS owner as a dedicated seat inside your organisation when the controls need to live on after certification.
Recent insights on ISO 27001
- How long does ISO 27001 take?
The ISO 27001 timeline depends on your starting point, the controls you need to implement and the certification body's audit schedule.
- Where AI can help with ISO 27001 preparation
AI can help draft policies and organise evidence. People still need to make risk decisions, implement controls and verify that the records describe reality.
- ISO 27001 or NIS2 first?
Build shared security processes, but track legal duties and certification separately. Applicable legal deadlines take priority over commercial preferences.