secureskies

An ISMS
someone reads.

ISO 27001 does not ask for perfect security. It asks for security that is demonstrably managed. We assess how far your organisation is from that, build the management system with you and support you through the stage 1 and stage 2 audits — documented as briefly as the standard allows.

FormatGap analysis · buildaudit support
StandardISO/IEC 27001:2022Annex A · 93 controls
ReferenceNIS2 evidencecustomer requirement
OutcomeCertification readinessplus a running ISMS
01 · Service

What is included.

Gap analysis, ISMS build, support through to the audit.

Gap analysis

Every requirement in clauses 4–10 and every Annex A control: met, partial, open — with evidence.

ISMS build

Scope, risk methodology, policies, statement of applicability, management review, internal audit.

Implementation support

Schedule and track the actions from risk treatment; coach the owners.

Audit support

Preparation, attendance at stage 1 and stage 2, handling of nonconformities.

02 · Process

Five steps,
one deliverable.

01

Scoping

Define the scope and its interfaces.

02

Gap analysis

Analysis against the standard and Annex A.

03

Build

ISMS documents and processes — as lean as the standard allows.

04

Operation

Run risk treatment, internal audit and management review.

05

Audit

Select the certification body, support stage 1 and stage 2.

03 · Who it fits

When this service
applies.

Companies whose customers require the certificate
NIS2 entities looking to structure their evidence
Organisations with an ISMS that exists on paper only
More services · Evaluate