
ISO 27001 Certification: A Practical Guide for 2026
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.
Regulation is no longer a compliance checkbox — it is a licence to operate. We build GRC programmes that satisfy your regulator while giving management a genuinely useful view of enterprise risk.
We do the heavy lifting: control design, policy architecture, risk registers, evidence collection, remediation tracking and reporting against ISO, NIST, SOC 2 and PCI DSS. And we automate it, so your team is not rebuilding the same spreadsheets every quarter.
The full capability list is published deliberately — it is what your procurement team needs to see, and what captures the long-tail searches your peers actually type.
Clear ownership, clear decision rights, clear escalation. We define who is accountable for what — and make it stick.
One risk language across IT, cyber, operations and third parties — quantified, prioritised and tracked to closure.
Deep, hands-on experience across the standards that matter to regulated industries.
From legal obligation to operating reality — records of processing, consent, data subject rights and cross-border transfer controls.
Your risk does not stop at your perimeter. We industrialise vendor due diligence so it scales.
Compliance evidence collected automatically, dashboards that are always current, and audits that stop consuming your calendar.
A free 45-minute discovery call with a senior consultant to understand the business driver, the constraints and the deadline — before any solution is proposed.
A written scope with deliverables, assumptions, exclusions, timeline, team composition and fixed pricing wherever the scope allows. No unpriced obligations.
A named engagement lead, a named delivery team and a kick-off that confirms access, stakeholders and reporting cadence.
Execution with weekly progress reporting, visible artefacts, and early escalation of anything that could affect timeline or cost.
Documented, auditable deliverables — findings registers, control mappings, runbooks, architecture documents and test evidence written to withstand scrutiny.
Handover and knowledge transfer, or managed operations under agreed SLAs — so the outcome holds after we leave.
Governance, Risk & Compliance covers the expertise and delivery. If you are evaluating the platforms themselves — what we deploy, which vendors we work with and how we select between them — see GRC Solutions.
VAPT, penetration testing, SOC as a Service, MDR, cloud security, IAM and PAM — protecting every layer of your estate.
ExploreCloud strategy, landing zones, migration, Kubernetes, CI/CD, DevSecOps and FinOps across Azure, AWS, GCP and OCI.
ExploreAI and machine learning, data platforms, Power BI analytics, automation and digital workplace — with measurable outcomes.
ExploreCustom web and mobile applications, APIs, microservices, UI/UX, low-code and QA automation, built and supported end to end.
Explore
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.

The new Govern function, a broader audience, stronger supply chain expectations — and a practical method for turning the framework into a programme your board can follow.
Describe what you are dealing with — a regulatory deadline, an audit finding, an incident, a migration or a capability gap. A senior consultant will respond within one business day.
We respond to every enquiry within one business day.