Skip to content
Udyat Technologies
Compliance
Compliance and regulation

ISO 27001 readiness, without the theatre

A certificate proves you have controls. Building controls worth having is a different project, and it is the one that matters.

Most of ISO 27001 is engineering and process work. The documentation is real but it is the smaller half, and doing it first produces a folder rather than security.

Typical timeline: Gap assessment 2–3 weeks, readiness 4–9 months

How it works

Controls first, documentation second

01Asset + data inventoryWhat you have, where02ControlsAccess · logging · suppliers03DocumentationDescribes what exists
Documenting first produces a folder describing a company you are not.
You are probably here because

These are the signs this is worth doing

If several of these are true, this is usually where the fastest return sits.

A customer or tender has made certification a requirement.
You have a policy set someone downloaded and nobody follows.
Access is granted freely and never reviewed.
There is no asset inventory, so scope is guesswork.
Nobody has tested whether you could detect an incident.
Backups exist; restores have never been rehearsed.

ISO 27001 usually arrives as a commercial requirement rather than a security ambition: a large customer asks, or a tender demands it, and suddenly there is a deadline. That framing is fine — it is how most good security programmes get funded — but it creates a specific risk.

The risk is optimising for the certificate. It is entirely possible to assemble a policy set, run a token risk assessment, and pass an audit while being no more secure than before. The auditor is sampling; the attacker is not.

Where the real work sits

In our experience these four take the longest and are least often started early enough.

Asset and data inventory

You cannot scope an ISMS without knowing what you have, where data lives, and who can reach it. This is tedious, it is the foundation of everything else, and it is routinely deferred.

Access control and review

Joiners, movers and leavers handled properly, least privilege applied, and periodic recertification that actually happens. Auditors test this hard because it fails often.

Logging and detection

Enough telemetry to notice an incident and reconstruct it afterwards. Most organisations discover during readiness that they could not answer basic questions about a breach.

Supplier management

A register of who processes your data, on what basis, with what assurance. Cloud and SaaS sprawl makes this bigger than teams expect.

What a gap assessment gives you

  • Scope defined honestly — what is in the ISMS and what is deliberately outside it.
  • A control-by-control gap list, ranked by risk rather than by ease.
  • The engineering work sized, separately from the documentation work.
  • A realistic timeline to Stage 1 and Stage 2, based on your actual starting point.
  • A view on whether certification is even the right instrument for what the customer is asking.

Build the controls, then document what you built. Doing it the other way round produces a folder that describes a company you are not.

When this is not worth doing

We would rather tell you now than three weeks into a project. This work is usually the wrong call if any of the following describes you.

  • Businesses with no commercial driver. Certification is expensive to obtain and to maintain; without a customer requirement the same money usually buys more security spent directly.
  • Anyone wanting documentation only. We will not write policies describing controls that do not exist, and an auditor will find the gap.
  • Teams that cannot commit ongoing ownership — an ISMS is a continuing obligation, not a project with an end date.
What this touches

The systems involved

We integrate rather than replace wherever it makes sense. These are the systems this work most commonly touches.

Cloud infrastructure (AWS, Azure, GCP)Identity and access managementLogging, monitoring and SIEMEndpoint and device managementVendor and sub-processor register
FAQ

ISO 27001 — questions we get asked

How long does certification take?

From a standing start, commonly four to nine months to Stage 2, depending overwhelmingly on how much technical remediation is needed. The documentation is weeks; the controls are months.

Do you issue the certificate?

No, and nobody who prepares you should. Certification comes from an accredited certification body, deliberately independent of whoever did the readiness work. We prepare you and support you through the audit.

Is SOC 2 or ISO 27001 the right one for us?

It usually depends on who is asking. ISO 27001 is the common request from European and Indian enterprise buyers; SOC 2 is more often asked for by North American ones. If both are being asked, the underlying controls overlap heavily.

Industries

Where this comes up most

The sectors where we most often do this work, and where the payback is usually clearest.

Next step

Thinking about iso 27001?

Start with a short conversation. We will tell you honestly whether this is the right place to begin, or whether something else pays back faster.