The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Governance and compliance
From gap assessment to the audit, with a lead auditor alongside you.
We build the information security management system that ISO 27001 requires and prepare your company for the certification audit: scope, risk assessment, controls, evidence, and a dress rehearsal before the auditor arrives. The work is led by a BSI-credentialed lead auditor. In practice, that means you hear during the project what the auditor would say afterward, while fixing things is still cheap.
The work starts by comparing what the company already has against what the standard requires, and the gaps come out ranked by risk and effort. Then comes implementation: policies written in the language of the people who will follow them, controls in operation, training for the teams involved, and an evidence routine with owners and frequency, so the audit never turns into a last-minute scramble.
On your side, the project needs access to the documents that already exist, time from the owners of each area for interviews and validation, and someone internal who is accountable for the project. At the end, you receive the approved document set and the Statement of Applicability with the rationale for each control. It is the first document the auditor opens.
You choose the depth. You can hire just the gap assessment and execute with your internal team, go all the way to full implementation, or stay with us through the end, with the audit rehearsal and our presence during the certification body's fieldwork. In any format, the audit and the certificate always come from the independent body you hire.
The stages and deliverables below describe the Full compliance work modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.