ISO 27001 readiness, without the theatre
A certificate proves you have controls. Building controls worth having is a different project, and it is the one that matters.
Most of ISO 27001 is engineering and process work. The documentation is real but it is the smaller half, and doing it first produces a folder rather than security.
Typical timeline: Gap assessment 2–3 weeks, readiness 4–9 months
Controls first, documentation second
These are the signs this is worth doing
If several of these are true, this is usually where the fastest return sits.
ISO 27001 usually arrives as a commercial requirement rather than a security ambition: a large customer asks, or a tender demands it, and suddenly there is a deadline. That framing is fine — it is how most good security programmes get funded — but it creates a specific risk.
The risk is optimising for the certificate. It is entirely possible to assemble a policy set, run a token risk assessment, and pass an audit while being no more secure than before. The auditor is sampling; the attacker is not.
Where the real work sits
In our experience these four take the longest and are least often started early enough.
Asset and data inventory
You cannot scope an ISMS without knowing what you have, where data lives, and who can reach it. This is tedious, it is the foundation of everything else, and it is routinely deferred.
Access control and review
Joiners, movers and leavers handled properly, least privilege applied, and periodic recertification that actually happens. Auditors test this hard because it fails often.
Logging and detection
Enough telemetry to notice an incident and reconstruct it afterwards. Most organisations discover during readiness that they could not answer basic questions about a breach.
Supplier management
A register of who processes your data, on what basis, with what assurance. Cloud and SaaS sprawl makes this bigger than teams expect.
What a gap assessment gives you
- Scope defined honestly — what is in the ISMS and what is deliberately outside it.
- A control-by-control gap list, ranked by risk rather than by ease.
- The engineering work sized, separately from the documentation work.
- A realistic timeline to Stage 1 and Stage 2, based on your actual starting point.
- A view on whether certification is even the right instrument for what the customer is asking.
Build the controls, then document what you built. Doing it the other way round produces a folder that describes a company you are not.
We would rather tell you now than three weeks into a project. This work is usually the wrong call if any of the following describes you.
- Businesses with no commercial driver. Certification is expensive to obtain and to maintain; without a customer requirement the same money usually buys more security spent directly.
- Anyone wanting documentation only. We will not write policies describing controls that do not exist, and an auditor will find the gap.
- Teams that cannot commit ongoing ownership — an ISMS is a continuing obligation, not a project with an end date.
The systems involved
We integrate rather than replace wherever it makes sense. These are the systems this work most commonly touches.
ISO 27001 — questions we get asked
How long does certification take?
From a standing start, commonly four to nine months to Stage 2, depending overwhelmingly on how much technical remediation is needed. The documentation is weeks; the controls are months.
Do you issue the certificate?
No, and nobody who prepares you should. Certification comes from an accredited certification body, deliberately independent of whoever did the readiness work. We prepare you and support you through the audit.
Is SOC 2 or ISO 27001 the right one for us?
It usually depends on who is asking. ISO 27001 is the common request from European and Indian enterprise buyers; SOC 2 is more often asked for by North American ones. If both are being asked, the underlying controls overlap heavily.
The services this work sits inside
Where this comes up most
The sectors where we most often do this work, and where the payback is usually clearest.
Others worth reading
SOC 2 for Indian SaaS companies
SOC 2 tests whether your controls operated over a period, not whether they exist today. That distinction changes when you have to start.
Read itComplianceDPDP Act compliance for software teams
Consent, retention, deletion, and breach notification are things your systems either do or do not do. A policy document does not implement any of them.
Read itThinking about iso 27001?
Start with a short conversation. We will tell you honestly whether this is the right place to begin, or whether something else pays back faster.