How we work
Nine phases. No mystery.
Every engagement runs the same way, and you can see the whole thing before you sign anything. Below is the full model for a combined certification-and-testing programme; single-service engagements are a subset of it.
- Phase 01
Scoping call
30–45 minutes · free
We find out who is asking for what, a specific customer, a procurement gate, a board requirement, and what your environment actually looks like. If certification is premature for you, this is where we say so.
Outputs
- Understanding of the driver behind the requirement
- High-level view of your product, environments and team
- An honest read on timeline feasibility
- Phase 02
Proposal & scope statement
Within 3 working days · free
A written proposal with a defined scope, a fixed price, named consultants and a delivery schedule. Everything we will do, and everything we will not, written down before anyone signs.
Outputs
- Fixed-scope, fixed-price proposal
- Named delivery team
- Delivery schedule with milestone dates
- Phase 03
Discovery & gap analysis
Weeks 1–3
We map your assets, environments, data flows and existing controls, then assess them against the standard control-by-control. In parallel we build the threat model that will drive both the risk register and the testing scope.
Outputs
- Asset and environment inventory
- Control-by-control gap analysis with effort estimates
- Threat model and prioritized remediation backlog
- Phase 04
Build the management system
Weeks 2–10
ISMS scope, Statement of Applicability, risk methodology and register, and the full policy set, written to match how your team already works rather than dropped in as a template.
Outputs
- Signed ISMS scope and Statement of Applicability
- Risk register with owners and treatment decisions
- Complete policy and procedure library
- Phase 05
Security testing
Weeks 6–12 · 1–3 weeks of testing
Manual-first penetration testing against the application, API and cloud estate. Scheduled deliberately early enough that findings can be remediated and retested before the external audit.
Outputs
- Technical findings report with reproduction steps
- Executive summary for leadership and customers
- Evidence mapped to Annex A 8.8 and 8.29
- Phase 06
Remediation
Ongoing through the programme
We work alongside your engineers to close technical findings and control gaps, access reviews, logging, asset inventory, onboarding and offboarding, vendor due diligence. Not a handover document; a working relationship.
Outputs
- Closed findings with verification evidence
- Implemented technical and organisational controls
- Evidence pack building continuously, not retroactively
- Phase 07
Internal audit & management review
Weeks 10–14
The mandatory internal audit, run properly, plus a facilitated management review that produces the records Stage 1 will ask for on its first day.
Outputs
- Internal audit report with nonconformities and actions
- Management review minutes and decisions
- Corrective action tracking
- Phase 08
External audit support
Weeks 14–20+
Help selecting an accredited certification body, preparing your team for auditor interviews, and sitting with you through Stage 1 and Stage 2 to respond to findings while the auditor is still in the room.
Outputs
- Certification body selection and engagement support
- Auditor interview preparation for each control owner
- Live support through Stage 1 and Stage 2
- Phase 09
Retest & continuous assurance
Post-certification
Every finding retested and the report reissued with verified fix status. Then, if you want it, annual internal audit, risk refresh, management review and surveillance audit prep so the certificate does not quietly lapse.
Outputs
- Reissued report confirming fix status
- Customer-shareable attestation letter
- Surveillance audit readiness each year
Working with us
How the engagement actually feels.
The process diagram is the easy part. These four things are what clients say made the difference.
No surprise scope changes
If we find something genuinely outside scope, we tell you and quote it separately. We do not silently expand the engagement and invoice for it later.
One shared channel
A shared Slack or Teams channel with the actual consultants in it. Not a ticket portal, not a weekly status email written by an account manager.
Evidence as we go
Evidence is collected continuously through the programme rather than assembled in a panic the week before Stage 1.
Your team keeps the knowledge
We document decisions, run the handover, and make sure the ISMS is not living in our heads when the engagement ends.
Questions
About the process.
Expect two to four hours a week from a main point of contact, plus short sessions with control owners, usually engineering, people ops and finance. We do the heavy lifting; what we cannot do is make decisions on your behalf or provide evidence that only your team can generate.
Tell us the date on the scoping call. We will work backwards from it and tell you honestly whether it is achievable. Sometimes the right answer is to move the date rather than turn up to Stage 2 unprepared, a failed audit costs more than a rescheduled one.
Yes. We work alongside whichever platform you use. The tool handles evidence collection and drift monitoring; we handle the scoping, risk work, policy writing, internal audit and auditor-facing judgement it cannot.
We are there for it. Minor nonconformities usually get a corrective action plan and a deadline; we write the plan and drive the fix. Major nonconformities are rare when the internal audit was run properly, which is precisely why we do not skip it.
Know exactly what an auditor, and an attacker, would find.
Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.
No sales sequence. A scoping call and a written proposal cost nothing.