Any organization that wants a recognized, auditable information security credential, most often to satisfy enterprise customer due diligence, win contracts that require it, or formalize a security program that's outgrown informal management.
A documented ISMS scope, a risk assessment and treatment methodology, a Statement of Applicability mapping which of the 93 Annex A controls apply and why, management review, internal audit, and evidence of continual improvement (the PDCA cycle).
Security decisions must be traceable to a documented risk assessment, not ad hoc judgment, and every control exclusion in the Statement of Applicability needs a defensible justification an auditor can challenge.
Gap assessment against Annex A controls, ISMS scope definition, risk assessment methodology build-out, and a readiness review ahead of the formal certification audit.
Gap analysis against Annex A controls and current ISMS maturity.
Draft the ISMS documentation, risk register, and Statement of Applicability.
Support through Stage 1 and Stage 2 certification audits with an accredited body.
Statement of Applicability, risk assessment and treatment plan, ISMS policy documentation, internal audit records, and management review minutes, all reviewable by the certification auditor.
Treating the Statement of Applicability as a formality rather than a defensible risk decision; under-scoping the ISMS boundary to exclude systems that should be in scope; letting documentation drift from actual practice between annual surveillance audits.
See exactly where your ISMS stands against Annex A before you schedule a certification audit.
Request a Gap Assessment →