ISO/IEC 27001: Information Security Management System
We implement your Information Security Management System, author the Statement of Applicability and Annex A controls, run the internal audit, and prepare you for a certificate issued by our partner (a certification body accredited by an IAF MLA signatory accreditation body). Achieving ISO 27001 certification demonstrates that information security is managed as a governed, risk-based programme.
Overview
ISO 27001 is the international standard for an Information Security Management System (ISMS). The ISO 27001 standard specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS using a risk management process. Certification demonstrates that you manage information security as a governed, risk-based, continually improving system. It is what enterprise procurement teams and regulated customers ask for when a vendor assessment form lands in your inbox.
We implement the full ISMS from the ground up. That means defining scope and context, running the information security risk assessment applying a risk management process aligned to the 27001 standard, authoring the Statement of Applicability mapped to all Annex A controls, and producing the complete set of mandatory documented information. We then run the internal audit and management review that the standard requires before the external audit. Our consultants have done this across information technology, SaaS, and regulated industries, which means we know where the ISO 27001 requirements catch teams unprepared.
The Stage 1 documentation review and Stage 2 implementation audit are conducted by our partner certification body, accredited by an IAF MLA signatory. Accredited certification bodies conduct conformity assessments against the ISO 27001 standard requirements. We support you through both stages and through any corrective actions raised by the auditor, so there are no surprises on audit day. The ISO 27001 certificate issued by the partner is valid for three years, with annual surveillance audits thereafter.
What’s included
- ISMS scope, context, and interested-party analysis
- Information security risk assessment and risk treatment plan
- Statement of Applicability mapped to all Annex A controls (ISO 27001 controls)
- Mandatory ISMS documentation and security policy set
- Internal audit and management review
- Stage 1 and Stage 2 certification audit preparation and support
- Certification through our partner certification body, accredited by an IAF MLA signatory
How we work
-
01
Gap analysis
We map your current security posture against ISO 27001 requirements and the Annex A controls, identify the gaps, and define the ISMS scope. You get a clear picture of effort before any work begins. This ISO 27001 lead implementer phase sets the foundation for everything that follows.
-
02
Build the ISMS
We run the risk assessment, author the Statement of Applicability, and produce the mandatory documented information the 27001 standard requires. Where controls require configuration or technical implementation, we define the requirement and your team carries out the change inside your environment. Best practice is to treat this as a management process, not a one-time documentation exercise.
-
03
Internal audit and management review
We conduct the ISO 27001 internal audit and management review required by the standard. Findings are closed before the external audit so the certification body and auditor sees a mature system, not a work in progress.
-
04
Certification audit
Our partner certification body, accredited by an IAF MLA signatory, conducts the Stage 1 documentation review and Stage 2 on-site audit. We attend alongside you, respond to auditor queries, and manage any corrective action requests to closure. The ISO 27001 certification process concludes with the certificate issued by the partner.
What you get
- ISMS scope statement and risk assessment
- Statement of Applicability and risk treatment plan
- Complete ISMS documentation set
- Internal audit report and management review records
- Certification audit support and accredited ISO 27001 certificate (issued by the partner)
Frequently asked questions
Who issues the ISO 27001 certificate?
Accredited certification bodies issue the ISO 27001 certificates after a successful Stage 2 audit. Onyx Security Labs implements the ISMS and prepares you for the audit. We do not issue the certificate ourselves. We deliver certification through our partner (a certification body accredited by an IAF MLA signatory accreditation body), so the certificate carries a recognised accreditation mark that your customers and regulators can verify. The ISO 27001 certification is valid for three years.
How long does the ISO 27001 certification process take?
It depends on your scope and starting maturity. We give you a realistic timeline after the gap analysis, not before. The ISO 27001 certification process is split into a Stage 1 documentation review and a Stage 2 implementation audit, typically separated by several weeks for remediation. Getting ISO 27001 certified from a standing start usually takes four to twelve months.
Do we have to apply every Annex A control?
No. The Statement of Applicability documents which ISO 27001 controls apply, which do not, and the justification for each exclusion. Exclusions must be grounded in your risk assessment. Onyx Security Labs authors the SoA with you so every inclusion and exclusion is defensible. The ISO 27001 requirements do not mandate every control, only that you document and justify your selections.
What are the benefits of ISO 27001 certification?
The benefits of ISO 27001 include a formal, auditable ISMS that satisfies enterprise customer procurement requirements, demonstrates information security maturity to regulators, and gives your internal teams a consistent management process for identifying and treating information security risk. Achieving ISO 27001 certification also aligns well with ISO 22301 and other management-system standards if you pursue additional certifications later.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international management-system standard with a formal certification process conducted by accredited certification bodies. SOC 2 is a US-origin attestation report issued by a licensed CPA firm. Some customers require one, some require both. We can advise on which makes sense for your markets.
Credentials held by our team










How ready is your security and compliance?
Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.
Ready to simplify security and compliance?
Pick a service, book a scope call, or ask a question. Whatever order works.