01Program
ISO 27001 consulting and implementation services, from gap assessment to certification audit
Implementation support for ISO/IEC 27001:2022: scoping the ISMS, risk assessment, the Statement of Applicability, control implementation with your teams, internal audit and support through the Stage 1 and Stage 2 audits. The certificate itself is issued by an accredited certification body, not by us.
- Name
- ISO 27001 Consulting
- Line
- 01 · Cybersecurity
- Type
- Outcome program, combines several practices
01The problem
An ISMS written for the auditor is abandoned after the audit.
Most first attempts at ISO 27001 start with a policy pack bought or copied from elsewhere. The documents describe a company that does not exist, control owners do not recognize their duties, and the risk assessment is a spreadsheet filled in once. The certificate may still be issued. The management system stops operating the week after.
The 2022 revision makes this harder to hide. Auditors sample evidence that controls operated during the period, look for a risk assessment that drives the Statement of Applicability, and expect the internal audit and management review to have happened before Stage 2.
02Scope
What the ISO 27001 program covers.
ISMS scoping and context
Boundaries, interested parties, legal and contractual requirements, and the information assets in scope, written so that the certificate covers what your customers care about.
Gap assessment against ISO/IEC 27001:2022
Clause-by-clause and Annex A review of what exists, what operates and what is missing, with a sequenced plan.
Risk assessment and treatment
A method your organization can repeat, a risk register tied to assets and threats, and treatment plans that lead to controls.
Statement of Applicability
Each of the 93 Annex A controls included or excluded with a reason, mapped to the risks that justify it.
Policy and control implementation
Short policies written for the people who follow them, and technical controls implemented with your IT, cloud and development teams.
Internal audit and management review
An independent internal audit of the management system, a management review with recorded decisions, and nonconformities closed before Stage 2.
Certification audit support
Preparation of evidence samples, auditor liaison during Stage 1 and Stage 2, and a response plan for any findings raised.
Transition and surveillance support
Moving an existing ISMS to the 2022 edition, and keeping it operating between surveillance audits.
03Approach
How an ISO 27001 engagement runs.
ISO/IEC 27001:2022 with ISO/IEC 27002:2022 for control guidance, ISO/IEC 27005 for risk management and ISO 19011 for internal audit practice. Controls are mapped once across ISO 27001, [SOC 2](/services/cybersecurity/soc-2) and the sector rules that apply to you, so one body of evidence serves several audits. The same mapping informs [JANUS](/products/janus), our GRC product in development.
Scope and gap
Agree what the certificate must cover, then measure the current state against every clause and control. The output is a dated plan, not a maturity score.
Risk and design
Run the risk assessment with the people who own the systems. Design the control set and the Statement of Applicability from the risks that result.
Implement with owners
Each control gets an owner, a procedure and a source of evidence. Where a control needs engineering, Onion cloud, IT and development teams can build it.
Operate and record
Access reviews, change approvals, supplier reviews, awareness training and incident handling run for long enough to produce evidence auditors can sample.
Audit internally
An internal audit and a management review are completed and recorded, and nonconformities are closed, before the certification body arrives.
Certification and beyond
Support through Stage 1 and Stage 2, then a calendar for the surveillance audits and the controls that must keep operating.
04Outcomes
What the ISO 27001 program is built to achieve.
- An ISMS scope statement and context analysis that match what customers ask for
- A repeatable risk assessment method, a risk register and treatment plans
- A Statement of Applicability with a reason for every inclusion and exclusion
- Policies, procedures and control evidence that come from normal operations
- Internal audit report, management review minutes and closed nonconformities
- A Stage 1 and Stage 2 audit entered with the gaps already known
When this work fits
- Companies asked for an ISO 27001 certificate during procurement or by a regulator
- Organizations with a security program and no management system around it
- Certified organizations moving to the 2022 edition or recovering from audit findings
- Teams that want ISO 27001 and SOC 2 from one control set
05Questions
ISO 27001: questions we are asked
Annex A was reorganized from 114 controls in 14 domains into 93 controls in four themes: organizational, people, physical and technological. Eleven controls are new, including threat intelligence, information security for use of cloud services, ICT readiness for business continuity, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. The management system clauses changed little. Certificates issued against the 2013 edition had to transition by October 2025, so new certifications are issued against 2022.
It depends on scope, how many controls already operate and how quickly risk treatment decisions are made. The management system must run for long enough to produce evidence, including a completed internal audit and management review, before Stage 2. The gap assessment ends with a dated plan for your situation rather than a generic estimate.
An accredited certification body, after a Stage 1 review of documentation and a Stage 2 audit of the operating management system. Onion Infosec provides readiness, implementation support and audit support, and does not issue certificates. Keeping those roles separate is what makes the certificate worth having.
No. Each Annex A control is included or excluded in the Statement of Applicability with a reason tied to your risk assessment and obligations. Most organizations apply most of them in some form, but the depth is proportionate to risk. Exclusions are legitimate when justified, and auditors check the justification, not the count.
Yes, and it saves effort. The control work overlaps heavily, so each control is implemented once and mapped to both. ISO 27001 adds the management system clauses and the Statement of Applicability; SOC 2 adds the Trust Services Criteria mapping, the system description and an observation period. See SOC 2 readiness and the guide to one control set for both.
Often alongside
Related services, industries and guides
Working with us
What every engagement rests on.
- Non-disclosure agreements
- Every engagement is governed by an NDA. Details of your environment, findings and deliverables stay within the engagement.
- Least-privilege access
- The minimum access the work requires, tied to named individuals and removed when the work ends.
- Telemetry stays in your tenant
- In security operations, our analysts work inside your SIEM, EDR or cloud console in preference to exporting logs to systems we run.
- End of engagement
- Access is handed back, and your information is returned or deleted as agreed with you.
Onion Information Security Solutions Private Limited · CIN U62099MH2025PTC443498 · Registered office in Mumbai, India
