ISO/IEC 27001:2022

Get to ISO 27001 certification without the guesswork

We run a gap assessment against the management system clauses and all 93 Annex A controls, then build the Statement of Applicability and roadmap you need for a certification audit.

Book a ISO 27001 assessmentSee a sample report
VersionISO/IEC 27001:2022
Maintained byISO and IEC
StructureClauses 4–10 · 93 Annex A controls
Suited toOrganisations needing certification for customers or tenders
01 · The framework

Annex A control themes

The 2022 revision groups Annex A into four themes. Clauses 4 to 10 set the requirements for running the information security management system (ISMS) itself.

A.5Organisational controls37 controls
A.6People controls8 controls
A.7Physical controls14 controls
A.8Technological controls34 controls
02 · Certification

The road to certification

Certification is issued by an accredited certification body. We get you ready for each stage and support you through it.

Gap assessmentWeeks 1–3Clause and control review, scope definition and a draft Statement of Applicability.
Stage 1 auditReadinessThe certification body reviews your ISMS documentation and scope.
Stage 2 auditCertificationThe auditor tests that controls are operating effectively.
03 · How we assess

Evidence first, interviews second

Every rating is backed by evidence from your environment, so the result reflects what is running, not what the policy says. A baseline typically takes two weeks.

  1. 01ScopeAgree the target, the systems in scope and who we need to speak to.
  2. 02CollectInterviews, document review and live data from Pulse and Trace.
  3. 03ScoreRate every requirement against your target, with evidence for each rating.
  4. 04ReportA prioritised roadmap and a short board briefing.
04 · What you receive

A result you can act on

Findings map across frameworks, so work done for ISO 27001 counts towards the others you hold.

✓Scored gap analysisStatus for every requirement against your target, backed by evidence.
✓Prioritised roadmapP1 to P3 work packages with owners, dates and exit criteria.
✓Board briefingA short summary of where you stand and the decisions needed.
✓Evidence kept currentResults live in Attest and update as your environment changes.
Often assessed together
SOC 2 CIS 18 (CIS Controls v8.1) NIS2 Directive

Know where you stand against ISO 27001 in two weeks

A baseline assessment with a prioritised roadmap and a board-ready summary.

Book a ISO 27001 assessment