Home / ISO 27001 certification
ISO 27001 certification · Consulting

ISO 27001 certification, prepared the way your auditor will look at it.

We take startups and scale-ups worldwide from gap analysis to a successful certification audit, with an ISMS sized for your company and evidence your auditor will accept.

ISO/IEC 27001:2022Led by an ISO 27001 Lead AuditorRemote, in English or French
From first call to certificate
01
Gap analysisWhere you stand against every clause and Annex A control.
02
Risk assessment and SoARisks, treatment plan and Statement of Applicability.
03
Policies and evidenceWhat the standard requires, sized for your team.
04
Internal audit and management reviewGaps closed before the auditor arrives.
05
Certification auditStage 1 and stage 2, with us by your side.
40+ISO 27001 internal audits delivered
Across
FinTechHealthTechAIHR servicesMarketplaces
Partners who trust us with their clients' audits
Why ISO 27001

The certificate your customers ask for, and a security programme that holds up.

Unblock enterprise deals

Large customers and public buyers increasingly require ISO 27001 in tenders and contracts. The certificate shortens procurement and security reviews.

Answer questionnaires once

Most security questionnaire questions map to ISO 27001 controls. Certified companies answer with evidence instead of starting from scratch each time.

Build security that scales

A management system with clear owners, risks and reviews, ready to support NIS2, DORA or GDPR expectations as you grow.

What's included

Everything the certification audit will look for

Deliverables are yours: editable, in your own tools, in English or French.

01

Scope and context

Organisation context, interested parties and an ISMS scope your auditor will accept, without over-reaching.

02

Gap analysis

A clause-by-clause review and a check of all 93 Annex A controls, with a prioritised, dated plan.

03

Risk assessment and treatment

A risk method your team can run again next year, a risk register and a treatment plan with named owners.

04

Statement of Applicability

Every Annex A control justified: included or excluded, implemented or planned, linked to its evidence.

05

Policies, procedures and evidence

The documented information the standard requires, sized for your company, plus the records that prove it runs.

06

Internal audit and management review

An independent internal audit and a management review, so stage 1 and stage 2 hold no surprises.

Adding HDS? We build both on one management system, in a single project. See HDS certification →
The auditor's advantage

Prepared by someone who runs certification audits.

Cyberbits Consulting is led by an ISO 27001 Lead Auditor who also audits for an accredited certification body. We know how auditors sample evidence, word their findings and judge whether an ISMS is really alive.

Evidence that matches what auditors sample. Records your team produces anyway, organised so they can be shown in minutes.
A scope you can defend in stage 1. Clear boundaries, interfaces and exclusions, with the reasoning written down.
A team ready for interviews. Process owners who know their part of the ISMS and can explain it with confidence.
No paperwork for its own sake. Only what the standard requires and what your auditor will actually read.
“He supported us throughout our ISO 27001 implementation, from prioritizing clauses and controls to shaping our documentation approach and preparing for the external audit. What stood out beyond his technical expertise was his style: responsive, genuinely supportive, and always available when we needed guidance.”
Kevin KonrathCo-Founder, Basqo
Method

A dated plan from the very first call

1

Scoping call

30 minutes, free. Your context, your deadline, a realistic scope.

2

Gap analysis

A clear picture of the gaps and a dated, prioritised plan.

3

Build

Regular check-ins, ready-to-use deliverables, and your team stays in ownership.

4

Certification

Internal audit, management review, then support during stage 1 and stage 2.

FAQ

ISO 27001 questions

How long does ISO 27001 certification take?

It depends on your starting point, your scope and how much time your team can give. The gap analysis gives you a realistic, dated plan.

How much does it cost?

Pricing is on request. After a free scoping call, we send a fixed-fee proposal based on your scope and starting point.

Can you also run our certification audit?

No. Impartiality rules prevent anyone from certifying a management system they helped build. We prepare you, and an independent accredited certification body certifies you.

What happens after certification?

The certificate is valid for three years, with surveillance audits in years one and two and a recertification audit in year three. Each year also needs an internal audit and a management review, which we can run for you.

Do we need a GRC platform?

No. We work with the tools you already use. If you use a GRC platform, we work inside it with you.

Let's talk about your certification deadline.

30 minutes, free, no commitment. You leave with a timeline and scope estimate.

  • Your context, your deadline, a realistic scope
  • ISO 27001, HDS or both: what applies to you
  • In English or French, by video call
Prefer email? info@cyberbitsconsulting.com Calendar not loading? Open the booking page
Cyberbits Consulting
ISO 27001 and HDS certification, internal audit