P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Flagship certification

ISO/IEC 27001 Implementation and Remediation

Full-cycle ISO/IEC 27001 consultancy: gap analysis, ISMS implementation, remediation of failed audits, and internal audit cycles, led by a Lead Auditor with six programmes taken through certification.

ISO/IEC 27001 fails in predictable places: scope drawn too wide, controls documented but not operated, and internal audits that do not test what the certification auditor will. This engagement covers the full cycle: implementation from zero, remediation of a struggling programme, or rescue after a failed audit.

Frameworks covered

ISO/IEC 27001:2022

The management system clauses and all 93 Annex A controls

ISO/IEC 27002

Implementation guidance applied control by control

SOC 2 crosswalk

Evidence mapped once, reused for both frameworks

How the engagement runs

  1. 1

    Gap analysis

    Every clause and control assessed against three honest states: absent, documented but not operating, and operating with evidence.

  2. 2

    Scope and risk assessment

    A defensible ISMS scope, an asset-based risk assessment, and a risk register your teams can maintain without a consultant on retainer.

  3. 3

    Implementation and remediation

    Controls built or repaired in priority order, with policies people actually follow and evidence pipelines that run themselves.

  4. 4

    Internal audit

    Audit cycles run the way the external auditor will run them, so findings surface while they are cheap to fix.

  5. 5

    Certification and surveillance

    Pre-audit review, audit-day support, and a surveillance calendar so year two does not become a scramble.

What you walk away with

  • Clause-by-clause gap report with nonconformity severity
  • Complete ISMS documentation set: policies, risk register, Statement of Applicability
  • Remediation plan with owners, dates, and effort estimates
  • Internal audit reports to certification standard
  • Audit-day support and surveillance calendar

How this plays out

Example scenario

A fintech needed certification inside nine months to unblock two enterprise deals that required it contractually.

The work: Tight scope, risk assessment in the first month, controls implemented in dependency order, and internal audit at month six against the certification standard.

Stage 1 and stage 2 passed first time; both enterprise contracts closed with the certificate attached.

Example scenario

An established firm failed stage 2 with major nonconformities in supplier management and access control, with the auditor returning in four months.

The work: Remediation triage: the majors closed with operating evidence, not paperwork, and a mock re-audit two weeks before the real one.

Certification achieved at the return visit; the remediation register became the firm's standing improvement process.

Start the conversation

A short call to understand your situation; a clear scope if the engagement fits, and a straight answer if it does not.

Plan your certification

Share this

Send it to whoever owns the budget or the risk.

← All services

What certification actually tests

Not whether your security is good. Whether you can demonstrate that you decide about it deliberately, act on those decisions, and check that the actions worked.

That distinction decides how a readiness engagement is run. An organisation with modest controls and honest records passes. One with excellent controls and no evidence that anybody chose them does not, and is usually more surprised.

Record every requirement in one of three states

AbsentNothing exists.Honest, and cheap to plan around.Documented, not operatingA policy exists. Nobody has run it.Reads as done on a spreadsheet.Operating, with evidenceIt ran, and left a record.The only state that survives an audit.RECORD EVERY REQUIREMENT IN ONE OF THREE STATESMost organisations sit here, and most findings come from here.A two-state assessment, present against absent, puts this column in the wrong one and flatters the result.An auditor does not ask whether a procedure exists. They ask when it last ran, and to see what it produced.
Most readiness assessments use two, present and absent, and that is why they overstate. A written procedure nobody has run is not a control. An assessor does not ask whether a document exists; they ask when it last ran and to see what it produced.

The middle column is where most organisations sit and where most nonconformities come from. A readiness assessment that cannot distinguish it from the right-hand column is telling you what you want to hear.

The 2022 revision, and why the transition matters

Annex A was restructured in the 2022 revision, from 114 controls in fourteen clauses to 93 in four themes, with eleven controls that did not exist before.

Certificates issued against the 2013 version ceased to be valid on 31 October 2025. An organisation still working from 2013-era documentation is preparing for an audit that no longer exists, and the newer controls are the ones most likely to be genuinely absent rather than merely undocumented: threat intelligence, information security for cloud services, ICT readiness for business continuity, secure coding.

Where the time actually goes

Six to twelve months from a standing start, and the constraint is operating history rather than documentation.

A risk assessment is evidenced by having been made, with owners and dates. An internal audit has to have found something. A management review has to have decided something. None of it can be produced retrospectively, and no budget compresses it, which is why the honest advice is often to start the parts that accrue time before deciding whether to certify at all.

The Statement of Applicability is the document that takes longest and is judged hardest, because it is where an assessor reads whether somebody made a decision about each control or wrote one sentence ninety-three times.

Whether you need this at all

Worth asking, because the answer is frequently no.

Organisations routinely begin an ISO 27001 programme when the customer asking for assurance would have accepted Cyber Essentials Plus and a documented supplier process, at a fraction of the cost and in a quarter of the time. The question to answer first is what the person asking actually needs, and that is usually a shorter conversation than the programme it replaces.

Where certification genuinely is required, starting with an honest picture of the gap is cheaper than starting with a consultant's template, because the template describes an organisation you do not have.

How the engagement runs

An assessment produces a gap picture scored against what an auditor would raise rather than as a percentage, because a number like 68% ready is not actionable and flatters by averaging a missing risk assessment against a well-written policy.

The output is sequenced by dependency and effort, not by clause number, and it is dated. A readiness assessment loses accuracy within months, and one used to commit to a certification timeline after it has gone stale is worse than none.

Performed personally, by a practitioner who audits to this standard.