
ISO 27001 Certification: A Practical Guide for 2026
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.
An audit is only valuable if it changes something. We deliver independent, evidence-based assessments — and then hand you a prioritised, costed remediation roadmap you can actually execute.
Our auditors have led regulatory assessments for banks, insurers, government entities and large enterprises, and know the difference between a finding that matters and a finding that fills a page.
The full capability list is published deliberately — it is what your procurement team needs to see, and what captures the long-tail searches your peers actually type.
Control-by-control assessment against the framework your regulator or customer actually cites.
Controls tested on the ground — configuration, evidence, walkthroughs and sampling.
Assurance grounded in technical fact, not questionnaires.
Where your data goes, who else touches it and whether that is defensible.
What you get at the end — and what happens next.
A free 45-minute discovery call with a senior consultant to understand the business driver, the constraints and the deadline — before any solution is proposed.
A written scope with deliverables, assumptions, exclusions, timeline, team composition and fixed pricing wherever the scope allows. No unpriced obligations.
A named engagement lead, a named delivery team and a kick-off that confirms access, stakeholders and reporting cadence.
Execution with weekly progress reporting, visible artefacts, and early escalation of anything that could affect timeline or cost.
Documented, auditable deliverables — findings registers, control mappings, runbooks, architecture documents and test evidence written to withstand scrutiny.
Handover and knowledge transfer, or managed operations under agreed SLAs — so the outcome holds after we leave.
Audit & Assessment covers the expertise and delivery. If you are evaluating the platforms themselves — what we deploy, which vendors we work with and how we select between them — see Industry Solutions.
VAPT, penetration testing, SOC as a Service, MDR, cloud security, IAM and PAM — protecting every layer of your estate.
ExploreISO 27001, SOC 2, PCI DSS, NIST CSF and GDPR programmes, automated on a modern GRC platform.
ExploreCloud strategy, landing zones, migration, Kubernetes, CI/CD, DevSecOps and FinOps across Azure, AWS, GCP and OCI.
ExploreAI and machine learning, data platforms, Power BI analytics, automation and digital workplace — with measurable outcomes.
Explore
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.

Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.
Describe what you are dealing with — a regulatory deadline, an audit finding, an incident, a migration or a capability gap. A senior consultant will respond within one business day.
We respond to every enquiry within one business day.