For the complete documentation index, see /llms.txt. Markdown version of this page: /en/services/iso27001.md.
← Back to services
Services

ISO 27001

From compliance burden to certification, in a focused programme fitted to your organisation.

Maximilian Sharoyan
Maximilian Sharoyan and Johan Vorgaard

I built the compliance core of Secured by FM CyberSecurity, and I have taken Norwegian SMBs from zero to certification-ready in roughly four weeks. ISO 27001 is a big job, but it does not have to be a slow one. What follows is the shape of a focused programme.

What we deliver

  • Johan Vorgaard
    Gap analysis against ISO 27001:2022

    We walk the Annex A controls against today's operation and document which are missing, which exist informally, and which are ready for the auditor.

  • Maximilian Sharoyan
    Statement of Applicability

    An SoA built on the real scope, with a written justification per control for inclusion or exclusion, not a template with your name pasted on top.

  • Johan Vorgaard
    ISMS documentation

    Policies, procedures, and roles written for your organisation, not for the auditor. We own the template set and keep it alive between audits.

  • Johan Vorgaard
    Control implementation with technical owners

    Every control gets a named customer-side owner and a concrete action plan, tied to the technical practices FM already operates.

  • Johan Vorgaard
    Internal audit and management review

    We run the internal audit, document findings, and prepare the management review so the minutes are ready before the certification auditor arrives.

  • Maximilian Sharoyan
    A GRC tool that keeps controls alive

    We set up Kertos or ServiceNow GRC so evidence accrues continuously, not as a panic sprint the week before the auditor shows up.

How we deliver this service

  • In a project

    A certification programme with a fixed scope, from gap analysis through the certification audit.

  • As part of a service

    Included in the Secured by FM CyberSecurity bundle with a certification guarantee, a refund if the main audit does not pass within the agreed window.

  • In a role at the customer

    An ISMS owner as a dedicated seat inside your organisation when the controls need to live on after certification.

Recent insights on ISO 27001

Talk to Max or Johan
Questions or inquiry? [email protected] Contact us →