01 · Compliance
ISO 27001 Certification
From no ISMS to a certificate auditors accept.
We run the entire ISO 27001:2022 programme for you: gap analysis, Statement of Applicability, policy set, risk treatment, internal audit, management review, and hands-on support through Stage 1 and Stage 2 with your certification body.
The context
Why this matters
Most SaaS teams meet ISO 27001 for the same reason: an enterprise deal stalls in procurement. The instinct is to buy a compliance tool and hope it fills itself in. It does not, a tool tracks evidence, it does not design a management system, run a risk assessment, or answer an auditor asking why a control was scoped out.
innsecs does the work. We build a lean ISMS sized to your actual company, not a 200-page template written for a bank. Every control we claim in the Statement of Applicability maps to something you genuinely operate, with evidence a Stage 2 auditor can follow without a guided tour.
Because we also run the penetration testing, Annex A 8.8 and 8.29 stop being a paperwork exercise. Your technical vulnerability management and secure-development evidence comes from real testing we performed against your product, not from a policy that says testing happens.
What is covered
Scope of the engagement
- 01
Gap analysis against ISO 27001:2022
A control-by-control read of where you stand today across all 93 Annex A controls and Clauses 4–10, delivered as a prioritized remediation backlog with owners and effort estimates.
- 02
Scope definition & Statement of Applicability
We draw the ISMS boundary tightly around the product, environments, and teams that matter, then justify every included and excluded control in language auditors accept.
- 03
Risk assessment & treatment plan
A repeatable risk methodology, a populated risk register tied to real threats to your architecture, and treatment decisions your leadership actually signs off on.
- 04
Policy & procedure set
Information security policy, access control, cryptography, supplier security, secure development, incident response, business continuity, and the rest, written to fit how your team already works.
- 05
Control implementation support
Hands-on help closing the technical gaps: access reviews, logging and monitoring, backup verification, asset inventory, onboarding and offboarding, and vendor due diligence.
- 06
Internal audit & management review
We run the mandatory internal audit and facilitate the management review, producing the records Stage 1 will ask for on day one.
- 07
Certification body liaison & audit support
Help selecting an accredited certification body, preparing your team for interviews, and sitting with you through Stage 1 and Stage 2 to handle findings as they come.
What you receive
Deliverables
Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.
- ISO 27001:2022 gap analysis report with prioritized remediation plan
- Defined ISMS scope and signed Statement of Applicability
- Risk assessment methodology, risk register and risk treatment plan
- Complete policy and procedure library, tailored to your organisation
- Evidence pack mapped control-by-control to Annex A
- Internal audit report and management review minutes
- Stage 1 and Stage 2 audit support, including nonconformity remediation
Questions
ISO 27001 Certification FAQ
No, and neither can any consultancy. The certificate is issued by an accredited certification body, which must be independent of the people who built your ISMS. We prepare you, run the internal audit, and support you through the external audit; the certification body makes the certification decision. We will help you choose and engage one.
For a SaaS company of 10–100 people starting with reasonable engineering hygiene, 12–20 weeks to audit-ready is realistic, plus the certification body's own scheduling for Stage 1 and Stage 2. Companies starting with no policies, no access reviews and no asset inventory should plan toward the longer end.
The standard does not name a pentest outright, but Annex A 8.8 (management of technical vulnerabilities) and 8.29 (security testing in development and acceptance) are extremely hard to evidence convincingly without one. Auditors expect to see it. We include it in the programme rather than leaving you to source it separately.
The tool and the consultancy solve different problems. Compliance platforms collect and monitor evidence very well. They do not scope your ISMS, run a defensible risk assessment, write policies that match your business, conduct your internal audit, or defend a control decision to an auditor. We work alongside whichever platform you use and fill in what it cannot do.
ISO 27001 certificates run on a three-year cycle with surveillance audits each year. We offer ongoing support that covers the annual internal audit, risk register refresh, management review, and surveillance audit preparation so the certificate does not quietly lapse.
Often paired with
SOC 2 Readiness
Type I and Type II readiness: control design, evidence discipline and auditor coordination, without the busywork.
Read more03Penetration Testing
Manual testing of web apps, APIs, mobile clients and authentication flows, with a report your engineers can act on.
Read more04Cloud Security Assessment
AWS, Azure, GCP, DigitalOcean, Linode and Vultr reviews covering IAM, exposure, data protection, logging and workloads.
Read moreKnow exactly what an auditor, and an attacker, would find.
Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.
No sales sequence. A scoping call and a written proposal cost nothing.