ISO/IEC 27001 is the international standard for an information security management system (ISMS) and the foundation NIS2, DORA and TISAX all build on. The certificate opens doors to contracts and reassures customers. We build it on real security, not shelf-ware policies.
Risk-based security management, evidenced by audit. Verify exact requirements against the standard and your certification body.
ISO/IEC 27001:2022 is the current revision; versus 2013 it restructures Annex A into 93 controls across 4 themes.
The core is risk management: assessment, treatment and a Statement of Applicability (SoA) justifying the selected controls.
93 controls across four themes: organizational, people, physical and technological.
Issued by an accredited certification body after a successful audit; valid on a three-year cycle with surveillance audits.
The ISMS requires management commitment, measurable objectives and continual improvement.
An established ISMS greatly simplifies NIS2 / the Act and DORA compliance and TISAX preparation.
From ISMS design and risk analysis to implementing and operating the controls you'll pass the audit with.
The ISMS framework, risk assessment and treatment, and a Statement of Applicability (SoA) tailored to your organisation.
Technical controls: logging, identity management, vulnerability management and detection-as-code.
24/7 monitoring that fulfils the operational controls and produces evidence for surveillance audits.
Penetration tests and reviews that evidence control effectiveness and feed continual improvement.
ISO 27001 is the common base. We build the sector obligations on top of it.
Straight answers to what clients ask us most.
The 2022 revision restructures Annex A into 93 controls across four themes (organizational, people, physical, technological) and adds newer areas such as threat intelligence and cloud security. The transition period to the 2022 version ended on 31 October 2025; certificates to the 2013 version are no longer valid.
For small and mid-sized organisations it's typically several months, depending on your starting point, the ISMS scope and how fast controls are implemented. Design and implementation are followed by a two-stage certification audit.
It isn't mandatory, but an ISO 27001 ISMS covers a large share of NIS2 / the Act's requirements and makes meeting and evidencing them much easier. That's why we often recommend it as the common foundation.
Yes. An ISMS isn't a one-off. It needs operation, measurement and surveillance audits. Operationally (SOC/MDR, security engineering) we keep the controls working between audits, not just on audit day.
We design the ISMS, run the risk analysis, prepare the SoA and implement controls so you pass the audit and stay secure afterwards.