Home / Trust Certifications / ISO 27001:2022
Trust Certifications
ISO 27001:2022
Build an information security management system that works day to day, and take it through certification.

Overview
What it is and who needs it
ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS): the policies, processes and controls an organisation uses to manage information risk. Certification by an accredited certification body is widely accepted by customers as evidence that security is managed systematically.
We guide you from the first gap assessment to the certification audit, building an ISMS that fits the way you already work instead of a set of documents written only for the auditor.
Who needs it
- SaaS and technology companies selling to enterprise customers
- Organisations asked for ISO 27001 in tenders and contracts
- Businesses that want a recognised structure for managing security risk
- Teams preparing for PCI DSS or the DPDP Act that want a common foundation

Scope
What is covered
ISMS scope and context
The boundaries of the system, interested parties and the objectives it must meet.
Risk assessment and treatment
A repeatable method, a risk register and a treatment plan owned by the business.
Statement of Applicability
Which Annex A controls apply, why, and how each is implemented.
Policies and procedures
A concise document set that reflects how your organisation really operates.
Annex A controls
Implementation of the applicable controls across all four themes.
Awareness, audit and review
Staff training, internal audit and management review before certification.
Annex A
93 controls across four themes
The 2022 edition groups the Annex A controls into four themes. Your Statement of Applicability records which ones apply to you.
Our approach
How we work, step by step
01
Gap assessment
We compare current practice with the standard and report what is missing.
02
Scope definition
We agree which locations, teams, products and systems the ISMS will cover.
03
Risk assessment and treatment
Risks are identified, rated and assigned a treatment with an owner.
04
Statement of Applicability
Each Annex A control is marked as applicable or not, with justification.
05
Policies and procedures
Documents are written or updated to match how you work.
06
Annex A controls
Applicable controls from the 93 across four themes are implemented and evidenced.
07
Awareness training
Staff learn what the ISMS expects of them.
08
Internal audit
An independent internal audit tests the ISMS and records findings.
09
Management review
Leadership reviews performance, risks and audit results, and agrees actions.
10
Certification audit support
We prepare your team, attend the Stage 1 and Stage 2 audits and help to close nonconformities.
Deliverables
What you receive
- Gap assessment report and project plan
- ISMS scope statement, risk register and risk treatment plan
- Statement of Applicability
- Policy and procedure set
- Internal audit report and management review record
- Support through the Stage 1 and Stage 2 certification audits

Why iSecurify
Three reasons customers choose us
01
An ISMS that fits your business
Controls are designed around your existing tools and processes.
02
Experienced implementers
Our consultants have built and audited management systems across sectors.
03
With you through the audit
We stay until the certificate is issued and findings are closed.
Questions
Frequently asked questions
How long does certification take?
Most small and mid-size organisations take four to eight months from gap assessment to certification, depending on scope and how much is already in place.
Does iSecurify issue the certificate?
No. Certificates are issued by an accredited certification body after an independent audit. We prepare you and support you during that audit. Keeping consultancy and certification separate is what gives the certificate its value.
What changed in the 2022 edition?
Annex A was reorganised from 114 controls in 14 domains to 93 controls in four themes, including 11 new controls covering areas such as threat intelligence, cloud services, data masking and secure coding.
Do we need a full-time security team?
No. You need clear ownership and management commitment. Many customers run the ISMS with a small internal team and our continuing support.
What happens after certification?
The certificate is valid for three years, with surveillance audits in between and a recertification audit at the end. We can run internal audits and keep the ISMS current.
Customer stories
What our customers say
-
Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.
Swapon Adhikary
Director · The Hird
-
Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.
Krutarth Pandya
-
We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.
Nandeep Mehta
Organisations we work with
Talk to us about ISO 27001:2022.
Share a few details and a consultant will come back with a scope and next steps.
