ISO 27001

ISO 27001:2022 Information Security Management

ISO 27001 consulting focused on standing up a real Information Security Management System (ISMS) — not a shelfware binder. We help you scope the ISMS, run a defensible risk assessment, map Annex A controls to your operations, and get certification-ready with a Stage 1 / Stage 2 auditor.

Why teams engage us

Common reasons teams come to us

  • An EMEA or enterprise buyer requires ISO/IEC 27001:2022 certification to move forward.
  • The team already has SOC 2 and wants to reuse evidence for ISO 27001 without duplicating work.
  • An inherited ISMS exists on paper but no one operates it — internal audit and management review are overdue.
  • Scope, risk methodology, and Statement of Applicability need to be defensible ahead of Stage 1.
  • Annex A 2022 controls have not been re-mapped since the standard update.
  • A certification body has been selected and the Stage 2 audit date is now on the calendar.

Talk through your scope, timeline, and customer pressure on a 30-minute call.

Who it's for
  • SaaS and fintech teams pursuing ISO/IEC 27001:2022 certification
  • Payments and health-tech companies with EMEA or regulated B2B buyers
  • Teams selling into EMEA where ISO 27001 is table stakes
  • Companies aligning SOC 2 and ISO 27001 evidence to reduce duplicate work
  • Security leaders replacing an inherited ISMS that no one actually runs
What's included
  • ISMS scoping — products, locations, and third parties in and out of scope
  • Information security risk assessment and risk treatment plan
  • Annex A (ISO 27001:2022) control selection and mapping
  • Statement of Applicability (SoA)
  • Policy, procedure, and record set aligned to clauses 4–10
  • Internal audit and management review support
  • Certification body selection and Stage 1 / Stage 2 audit prep
Coverage

What ISO 27001 readiness covers

ISMS scope & context

Products, locations, teams, and third parties clearly in or out of scope for the ISMS.

Risk assessment & treatment

Defensible risk methodology, assessment, and treatment plan aligned to clauses 6 and 8.

Annex A (2022) mapping

Control selection across the four 2022 themes, mapped to how you actually operate.

Statement of Applicability

Complete SoA justifying inclusion and exclusion of every Annex A control.

Policies, procedures & records

Right-sized policy set and evidence trail aligned to clauses 4–10.

Internal audit & management review

Working internal audit programme and management review pack ready for Stage 1.

Stage 2 audit on the calendar and gaps still open?

We come in fast, prioritize what actually blocks certification, and hand your auditor a clean package.

Benefits
  • Turn ISO 27001 into a working management system, not a compliance shelf
  • Reuse SOC 2 evidence where possible to reduce duplicate effort
  • Enter Stage 1 confident in scope, SoA, and risk methodology
  • Give sales a certification badge enterprise and EMEA buyers expect
Typical outputs
  • ISMS scope statement
  • Risk assessment, treatment plan, and Statement of Applicability
  • Policy set and procedure library
  • Internal audit plan and management review pack
Process

A clear path from scope to remediation

  1. 01

    Scope

    Define ISMS boundaries — products, locations, teams, and third parties.

  2. 02

    Assess

    Run the information security risk assessment and treatment plan.

  3. 03

    Build

    Select Annex A controls, produce the SoA, and align policies and procedures.

  4. 04

    Operate

    Run internal audits and management review before the external auditor arrives.

  5. 05

    Certify

    Support certification-body selection and Stage 1 / Stage 2 audits.

FAQ

Questions we hear most

How long does ISO 27001 certification take end to end?
For a first-time ISMS in a focused SaaS or fintech environment, plan on 4–8 weeks for scoping, risk assessment, and SoA; 8–16 weeks to build out policies, controls, and evidence; then Stage 1 and Stage 2 audits across another 6–10 weeks. Total time to certificate is typically 5–8 months depending on maturity and audit lead times.
Do you help us pick a certification body?
Yes. We help you shortlist accredited certification bodies, compare cost and scheduling, and prepare the Stage 1 and Stage 2 audit package. We stay independent of the certification body to preserve the auditor's objectivity.
Can we reuse SOC 2 evidence for ISO 27001?
Yes — and you should. SOC 2 common criteria and ISO 27001 Annex A overlap significantly. A properly designed evidence library can serve both, reducing duplicate work across access reviews, change management, vendor management, incident response, and risk assessment.
What's the difference between ISO 27001:2013 and ISO 27001:2022?
ISO 27001:2022 restructures Annex A into four themes (Organizational, People, Physical, Technological), consolidates controls from 114 to 93, and adds 11 new controls covering threat intelligence, cloud services, ICT readiness, secure coding, and more. Any active certificate must be transitioned to the 2022 version by the deadline set by your certification body.
Do you provide the ISO 27001 certificate?
No. ISO 27001 certificates are issued by accredited certification bodies. ControlSolid provides advisory-first readiness — scoping, risk assessment, SoA, policy build-out, internal audit, and Stage 1 / Stage 2 preparation — and coordinates a clean handoff to the certification body.
What's the smallest scope we can certify?
Scope can be as narrow as a single product, environment, or business unit — as long as the ISMS boundary is defensible and interfaces to out-of-scope areas are documented. Starting narrow and expanding is a common pattern for SaaS teams under EMEA enterprise sales pressure.
Next step

Need a clear view of your security gaps?

Start with a focused readiness call. We'll discuss your customer pressure, compliance goals, application risk, and the best next step.