ISO 27001:2022 Information Security Management
ISO 27001 consulting focused on standing up a real Information Security Management System (ISMS) — not a shelfware binder. We help you scope the ISMS, run a defensible risk assessment, map Annex A controls to your operations, and get certification-ready with a Stage 1 / Stage 2 auditor.
Common reasons teams come to us
- An EMEA or enterprise buyer requires ISO/IEC 27001:2022 certification to move forward.
- The team already has SOC 2 and wants to reuse evidence for ISO 27001 without duplicating work.
- An inherited ISMS exists on paper but no one operates it — internal audit and management review are overdue.
- Scope, risk methodology, and Statement of Applicability need to be defensible ahead of Stage 1.
- Annex A 2022 controls have not been re-mapped since the standard update.
- A certification body has been selected and the Stage 2 audit date is now on the calendar.
Talk through your scope, timeline, and customer pressure on a 30-minute call.
- SaaS and fintech teams pursuing ISO/IEC 27001:2022 certification
- Payments and health-tech companies with EMEA or regulated B2B buyers
- Teams selling into EMEA where ISO 27001 is table stakes
- Companies aligning SOC 2 and ISO 27001 evidence to reduce duplicate work
- Security leaders replacing an inherited ISMS that no one actually runs
- ISMS scoping — products, locations, and third parties in and out of scope
- Information security risk assessment and risk treatment plan
- Annex A (ISO 27001:2022) control selection and mapping
- Statement of Applicability (SoA)
- Policy, procedure, and record set aligned to clauses 4–10
- Internal audit and management review support
- Certification body selection and Stage 1 / Stage 2 audit prep
What ISO 27001 readiness covers
ISMS scope & context
Products, locations, teams, and third parties clearly in or out of scope for the ISMS.
Risk assessment & treatment
Defensible risk methodology, assessment, and treatment plan aligned to clauses 6 and 8.
Annex A (2022) mapping
Control selection across the four 2022 themes, mapped to how you actually operate.
Statement of Applicability
Complete SoA justifying inclusion and exclusion of every Annex A control.
Policies, procedures & records
Right-sized policy set and evidence trail aligned to clauses 4–10.
Internal audit & management review
Working internal audit programme and management review pack ready for Stage 1.
Stage 2 audit on the calendar and gaps still open?
We come in fast, prioritize what actually blocks certification, and hand your auditor a clean package.
- Turn ISO 27001 into a working management system, not a compliance shelf
- Reuse SOC 2 evidence where possible to reduce duplicate effort
- Enter Stage 1 confident in scope, SoA, and risk methodology
- Give sales a certification badge enterprise and EMEA buyers expect
- ISMS scope statement
- Risk assessment, treatment plan, and Statement of Applicability
- Policy set and procedure library
- Internal audit plan and management review pack
A clear path from scope to remediation
- 01
Scope
Define ISMS boundaries — products, locations, teams, and third parties.
- 02
Assess
Run the information security risk assessment and treatment plan.
- 03
Build
Select Annex A controls, produce the SoA, and align policies and procedures.
- 04
Operate
Run internal audits and management review before the external auditor arrives.
- 05
Certify
Support certification-body selection and Stage 1 / Stage 2 audits.
Explore other ControlSolid services
SOC 2 Readiness
SOC 2 readiness for SaaS teams — Trust Services Criteria gap assessment, policy and control build-out, evidence library, and audit-ready handoff.
Learn more →PCI DSS & Payment Security
Payment security readiness across PCI DSS v4, PCI SSF (Secure Software Standard & Secure SLC — the PA-DSS successor), PCI 3DS, PCI PIN, and P2PE.
Learn more →- ControlSolid home →Overview of readiness, advisory, and assessment services.
- SOC 2 Type 1 & Type 2 readiness →Reuse ISMS controls and evidence to reduce SOC 2 duplication.
- Security assessments & gap analysis →Pre-ISMS baseline against NIST CSF, CIS Controls, and ISO 27001 Annex A.
- Application & cloud security reviews →Cloud and SDLC evidence that feeds directly into Annex A technical controls.
- vCISO & customer security reviews →Ongoing management review support and customer questionnaire coverage post-certification.
- Resources & guides →Deep dives on payment security, digital identity, and readiness planning.
Questions we hear most
- How long does ISO 27001 certification take end to end?
- For a first-time ISMS in a focused SaaS or fintech environment, plan on 4–8 weeks for scoping, risk assessment, and SoA; 8–16 weeks to build out policies, controls, and evidence; then Stage 1 and Stage 2 audits across another 6–10 weeks. Total time to certificate is typically 5–8 months depending on maturity and audit lead times.
- Do you help us pick a certification body?
- Yes. We help you shortlist accredited certification bodies, compare cost and scheduling, and prepare the Stage 1 and Stage 2 audit package. We stay independent of the certification body to preserve the auditor's objectivity.
- Can we reuse SOC 2 evidence for ISO 27001?
- Yes — and you should. SOC 2 common criteria and ISO 27001 Annex A overlap significantly. A properly designed evidence library can serve both, reducing duplicate work across access reviews, change management, vendor management, incident response, and risk assessment.
- What's the difference between ISO 27001:2013 and ISO 27001:2022?
- ISO 27001:2022 restructures Annex A into four themes (Organizational, People, Physical, Technological), consolidates controls from 114 to 93, and adds 11 new controls covering threat intelligence, cloud services, ICT readiness, secure coding, and more. Any active certificate must be transitioned to the 2022 version by the deadline set by your certification body.
- Do you provide the ISO 27001 certificate?
- No. ISO 27001 certificates are issued by accredited certification bodies. ControlSolid provides advisory-first readiness — scoping, risk assessment, SoA, policy build-out, internal audit, and Stage 1 / Stage 2 preparation — and coordinates a clean handoff to the certification body.
- What's the smallest scope we can certify?
- Scope can be as narrow as a single product, environment, or business unit — as long as the ISMS boundary is defensible and interfaces to out-of-scope areas are documented. Starting narrow and expanding is a common pattern for SaaS teams under EMEA enterprise sales pressure.
Need a clear view of your security gaps?
Start with a focused readiness call. We'll discuss your customer pressure, compliance goals, application risk, and the best next step.