ISO/IEC 27001:2022

ISO/IEC 27001 implementation, ready for certification

A customer asks for the certificate, and your information security management system mostly exists in documents. We implement ISO/IEC 27001 so that the controls run in your systems and the certification auditor sees evidence, not just policies.

// In short

ISO/IEC 27001 is the standard for an information security management system

The certificate is issued by an accredited certification body after an audit, not by us. We take you to readiness: ISMS scope, risk assessment, a Statement of Applicability for the 93 controls in Annex A (2022 edition), controls with evidence, internal audit and management review. For companies whose customers require the certificate, or that want one management system that also serves NIS2 and DORA.

What implementation covers

  1. ISMS scope

    The boundaries of the system: sites, processes, systems and suppliers. Too wide costs money, too narrow will not convince the customer.

  2. Risk assessment and treatment

    A method, a risk register with owners and a risk treatment plan that management approves in writing.

  3. Statement of Applicability (SoA)

    The 93 controls of Annex A, 2022 edition: which ones you apply, how, and why you exclude the rest.

  4. Controls in your systems

    Access, backups, logging, change and supplier management, with evidence taken straight from the systems.

  5. Internal audit and management review

    Both are required before certification. The internal audit is run by someone who did not implement the controls under review.

  6. Certification audit

    The certification body audits in two stages: documentation first, then the system in operation. We prepare you for both.

// Where we start

First step and internal audit

  1. 01Implementation

    Gap analysis against ISO/IEC 27001:2022

    We check which requirements of the standard already work and what is missing, and map out the path to certification. FutureCode Evidence Box can prepare a draft SoA together with an evidence index.

    • Requirements of clauses 4-10
    • The 93 controls of Annex A
    • Evidence you already have in your systems

    First step, 5 weeks

    Gap analysis and a draft Statement of Applicability

    • Gap analysis with priorities
    • Draft Statement of Applicability (SoA)
    • Roadmap to the certification audit

    Key deliverable: one control implemented in a system, together with its evidence

    Request the first step
  2. 02Internal audit

    ISMS internal audit

    Objective, which means run by people who did not implement the controls under review. If we implemented your ISMS, we tell you who can audit it.

    • Audit program and plan
    • Evidence samples from your systems
    • Nonconformities with root cause and a fix date
    • Report for the management review
    Independence rules

// ISO and NIS2

ISO/IEC 27001 helps with NIS2, but does not replace the audit

The standard and the Polish KSC Act (NIS2 in Poland) share a core: risk, incidents, business continuity, suppliers and assets. They differ in who assesses you and what is a legal duty.

What ISO gives you for KSC

  • ISMS, risk register and SoA support Article 8 of the KSC Act
  • The same system evidence serves both
  • No second management system alongside the first

What ISO does not replace

  • The formal audit under Article 15 of the KSC Act
  • Entry in the register of entities
  • Incident reporting within the statutory deadlines
  • Annual, documented management training (Article 8e)

ISO/IEC 42001 for AI

  • The standard for an AI management system
  • Same clause structure as ISO/IEC 27001
  • Both systems can be run together
  • A good start is an AI inventory: AI governance and AI security

The full list of KSC duties is on our NIS2 compliance in Poland page.

// Qualifications

Team credentials

Our audits are led by certified auditors. We run internal audits only where we did not implement the controls under review. Our team also holds certifications in security, data protection and process management.

Certifications held by our team

  • CISA (Certified Information Systems Auditor)ISACA
  • IODO (Polish data protection officer certificate)
  • CompTIA Security+CompTIA
  • ITILAXELOS / PeopleCert
  • REQBRequirements Engineering Qualifications Board
  • SAFeScaled Agile
  • ISTQBInternational Software Testing Qualifications Board

// Scope

What we do, and what we don't

We agree the scope and date in writing before we start.

We do

  • ISMS scope and risk assessment
  • Statement of Applicability (SoA) for 93 controls
  • Controls implemented in your systems, with evidence
  • Internal audit of an ISMS we did not implement
  • Preparation for both stages of the certification audit

We don't

  • Certification: an accredited certification body issues the certificate
  • Internal audit of an ISMS we implemented ourselves
  • Template policies with no link to your systems
  • Promises about the result of the certification audit

If all you need is a certificate for the wall, we'll be upfront about that on the first call.

// FAQ

Questions about ISO/IEC 27001

How long does ISO 27001 implementation take?

It depends on the ISMS scope and what already works. After the first step (5 weeks) you get a roadmap with dates. The system has to run for a while before certification: the certification body wants to see the results of the internal audit and the management review.

What does certification cost, and who issues it?

An accredited certification body issues the certificate, not us. Its price depends mainly on the number of people and sites in scope, because they drive the number of audit days. We quote our part, the preparation, as a fixed scope before we start.

Can we combine ISO 27001 with NIS2 in Poland?

Yes, and it is usually the cheapest route. One ISMS covers the standard and a large part of Article 8 of the Polish KSC Act. The ISO certificate does not replace the formal KSC audit under Article 15, though.

Do you run internal audits?

Yes, if we did not implement the controls under review. The standard requires internal audits to be objective and impartial. If we implemented your ISMS, we tell you who can run the internal audit.

Do we need a GRC tool?

Not at the start. You can keep the risk register, Statement of Applicability and obligations register in tools you already have. A tool makes sense once you know who will use it and how.

From the blog: ISO and audit

Let's start with an ISO/IEC 27001 gap analysis

In 30 minutes we agree the ISMS scope and what goes into the first step.

Book a 30-minute call

Prefer to start in writing?

Describe your situation and we will send back the scope and date of the first step. We reply within one business day.

Request the first step