
ISO 27001 Certification: A Practical Guide for 2026
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.
Compliance stops being painful when the evidence collects itself. We implement GRC platforms that turn control monitoring, risk reporting and audit preparation into continuous, automated processes.
Spreadsheet-based compliance works until you have a second framework, a second auditor or a second regulator. Then it quietly consumes a full-time role. GRC platforms solve that — but only when they are configured around your control framework rather than a generic template.
| Capability area | Technologies we work with |
|---|---|
| Partner technologies | CyberArrow (compliance automation, continuous control monitoring, awareness and audit readiness), Microsoft (Purview Compliance Manager, Defender, Entra ID as evidence sources) |
| GRC & compliance automation | CyberArrow, Microsoft Purview Compliance Manager, ServiceNow GRC/IRM, Archer, MetricStream, LogicGate, Vanta, Drata, Scrut |
| Risk management | ServiceNow IRM, Archer, MetricStream, Resolver, Riskonnect |
| Third-party risk | CyberArrow, ServiceNow VRM, Prevalent, SecurityScorecard, BitSight, Panorays |
| Privacy management | OneTrust, Microsoft Priva, TrustArc, Securiti |
| Awareness & human risk | CyberArrow Awareness, KnowBe4, Proofpoint Security Awareness, Microsoft Attack Simulator |
| Policy & document governance | CyberArrow, ServiceNow, SharePoint with Purview, Confluence with governance overlay |
This list is not exhaustive and it is not a commitment to any single platform. If you run something not listed here, ask — there is a good chance we have delivered on it. See our formal partnerships
This page covers the technology. For the consulting, delivery and operational expertise that goes with it, see Governance, Risk & Compliance.
A security solution is an architecture, not a product.
ExploreCloud is a set of design decisions, not a logo.
ExploreTransformation solutions are judged on adoption, not architecture diagrams.
ExploreInfrastructure solutions engineered for the workload, sized for the budget and documented for whoever runs them next.
Explore
What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.

Enterprise GRC suites and lightweight compliance automation tools solve different problems. How to work out which one you need — and avoid paying for the other.
Tell us what you are trying to achieve and what you already have in place. A senior consultant will come back within one business day with the realistic technology options and an honest view on cost.
We respond to every enquiry within one business day.