Skip to main content

Cyber Resilience & Supplier Assurance

ISO/IEC 27001 Readiness

A proportionate information security management system, evidenced and ready for independent certification — built around how your organisation actually works, not a template library.
Readiness path
  1. Scope
  2. Assess
  3. Prioritise
  4. Build
  5. Evidence
  6. Test
  7. Ready

IG-Smart supports ISO/IEC 27001 readiness, governance, remediation and assurance preparation. Certification is awarded by an independent accredited certification body, not by IG-Smart.

For technology, SaaS and RegTech suppliers, and any organisation whose customers, tenders or Board now expect ISO/IEC 27001.

Ready for certification — without over-engineering

Enterprise customers and procurement teams increasingly ask for ISO/IEC 27001. The risk is building an ISMS that is too heavy to run, or too thin to pass an independent audit.

IG-Smart defines a sensible scope, assesses your current position against the standard, prioritises the gaps, helps build the governance, risk and control arrangements, and tests whether the evidence will stand up before your certification body arrives.

Readiness support improves your position; it does not guarantee certification. The certification audit and decision rest with the accredited certification body you appoint.

The readiness path

From requirement to certification-ready

Each stage produces evidence you keep — and makes clear what your organisation decides and owns.

Scope

What happens
The ISMS boundary, organisational context and interested parties are agreed.
What IG-Smart does
Facilitates scoping with leadership, IT and operations.
What the organisation owns
Approving scope and objectives.
Typical output
ISMS scope and context statement.

Assess

What happens
Current arrangements are compared with the clauses and Annex A controls of ISO/IEC 27001:2022.
What IG-Smart does
Runs interviews, document review and walkthroughs.
What the organisation owns
Access to people, systems and records.
Typical output
ISO/IEC 27001 Readiness Assessment.

Prioritise

What happens
Gaps are ranked by risk, effort and audit significance.
What IG-Smart does
Builds the remediation plan and owner map.
What the organisation owns
Agreeing priorities, resources and timescales.
Typical output
Gap & Remediation Register.

Build

What happens
Leadership roles, risk methodology, risk treatment, control applicability, policies and procedures are put in place.
What IG-Smart does
Supports design and drafting proportionate to your organisation.
What the organisation owns
Approving policies and accepting risk.
Typical output
ISMS Governance & Responsibility Map; Risk Treatment / Control Readiness Record.

Evidence

What happens
Records that show the ISMS operating are gathered and indexed.
What IG-Smart does
Tracks evidence against each requirement.
What the organisation owns
Producing and retaining operational records.
Typical output
Evidence Tracker.

Test

What happens
An internal readiness review checks whether the ISMS and its evidence would withstand audit; corrective actions follow.
What IG-Smart does
Performs the readiness review where independence allows and supports management review preparation.
What the organisation owns
Corrective action and management review.
Typical output
Readiness review findings and corrective-action log.

Ready

What happens
Leadership sees the residual gaps and decides when to engage the certification body.
What IG-Smart does
Reports the readiness position and certification-audit preparation.
What the organisation owns
Appointing the certification body and the audit decision.
Typical output
Executive Readiness Summary.

IG-Smart provides readiness, implementation support and assurance preparation. The certification audit and award are carried out only by an independent accredited certification body. Where IG-Smart has helped implement an ISMS, it does not also act as its independent internal auditor in the same cycle.

When organisations engage us

Signals that it is time to act

  1. A customer, tender or framework requires ISO/IEC 27001
  2. Enterprise procurement questionnaires are slowing sales
  3. The Board wants a recognised security-management standard
  4. An existing ISMS has drifted or was built for the 2013 edition
  5. You are not sure what scope to certify
  6. A certification audit date is set and readiness is unclear
  7. Security responsibilities sit with one person and are not documented
  8. Investors or acquirers are asking about security governance

What the service covers

Outcomes the service is built to deliver

ISMS scope and context
Boundary, organisational context, interested parties and objectives.
Leadership and accountability
Roles, responsibilities and governance forums that make the ISMS run.
Risk methodology, assessment and treatment
A repeatable method, a current risk assessment and a treatment plan owners accept.
Control applicability
Annex A control selection and justification, aligned to your actual risks.
Policies, procedures and evidence
Proportionate documentation and the operating records an auditor will ask to see.
Readiness review and audit preparation
Internal readiness review, corrective action, management review preparation and certification-audit briefing.

How we deliver

Assess → Build → Manage → Assure → Improve

  1. Assess

    Scope the ISMS and assess the current position.

  2. Build

    Put governance, risk treatment, controls and documentation in place.

  3. Manage

    Track remediation and evidence until the ISMS is operating.

  4. Assure

    Review readiness and prepare for the certification audit.

  5. Improve

    Support surveillance-audit preparation and continual improvement, where agreed.

Scope boundaries

Included, and separately scoped where required

Included in the core service

  • Scoping and readiness assessment against ISO/IEC 27001:2022
  • Prioritised gap and remediation register
  • Risk assessment and treatment support
  • Control applicability and policy support
  • Evidence tracking
  • Readiness review and executive summary

Separately scoped where required

  • Certification audit and award (accredited certification body only)
  • Technical implementation of security tooling
  • Penetration testing (scoped separately)
  • Operating a security operations centre
  • Guaranteeing a certification outcome

Sample outputs

Example outputs you may receive

Representative reports, registers and records, so you can picture the output before you engage.

Illustrative structure — not a client document. Examples show the type, format and level of detail clients may receive. Exact outputs depend on the agreed scope.

Illustrative output

ISO/IEC 27001 Readiness Assessment

Position against each clause and Annex A theme, with the material gaps and audit significance.

  • Area
  • Requirement
  • Position
  • Gap

Likely format

  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Gap & Remediation Register

Every gap with owner, action, effort, target date and status.

  • Gap
  • Action
  • Owner
  • Due

Likely format

  • IG-Smart branded spreadsheet / register
  • Client-system capture (e.g. Jira) where used

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

ISMS Governance & Responsibility Map

Who owns, approves, operates and reviews each part of the ISMS.

  • Activity
  • Owner
  • Approver
  • Review

Likely format

  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Evidence Tracker

Required evidence per requirement, its location, owner and audit readiness.

  • Requirement
  • Evidence
  • Owner
  • Ready

Likely format

  • IG-Smart branded spreadsheet / register
  • Evidence pack / supporting records

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Risk Treatment / Control Readiness Record

Risks, chosen treatment, applicable controls and their implementation status.

  • Risk
  • Treatment
  • Control
  • Status

Likely format

  • IG-Smart branded spreadsheet / register
  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Executive Readiness Summary

Overall readiness, residual gaps, decisions needed and a recommended audit window.

  • Measure
  • Position
  • Direction
  • Decision needed

Likely format

  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Relevant evidence

Direct ISO/IEC 27001 readiness evidence, and related security assurance experience

Jigsaw Create is direct ISO/IEC 27001 readiness evidence. The other cases show related security governance and assurance capability and are not presented as ISO/IEC 27001 readiness engagements.

  • Named client · Technology / SaaS / RegTech

    Jigsaw Create

    ISO/IEC 27001 readiness, penetration testing and training

    ISO/IEC 27001 readiness and cyber assurance

    View the evidence: Jigsaw Create
  • Anonymised engagement

    A FTSE 100 organisation

    Three-stage governance and audit-readiness plan

    Audit-ready UK policies ahead of a third-party maturity assessment

    View the evidence: A FTSE 100 organisation
  • Named client · Higher Education / Research

    UCL

    IG audit, improvement plan, training and physical-security audit

    Helped shape and focus the final DSPT submission

    View the evidence: UCL

Explore all case studies →Request Relevant Evidence →

Evidence relevance

Your IG-Smart team

Specialist expertise, coordinated around your requirement

Subject-matter expertise is paired with a clear client and programme contact from initial scoping through delivery.

Subject-matter expert

Michael Abtar

CEO and Founder

Governance, risk and assurance specialist with more than 18 years' experience spanning privacy, cyber resilience, AI governance, digital transformation, healthcare and complex regulated organisations.

View profile

Subject-matter expert

Dr Bright Mawudor

Senior Cyber Security Consultant

Cybersecurity specialist with 10+ years' experience and founder of Africahackon, combining security engineering and technical assurance with expertise in cyber governance, resilience, vulnerability management and organisational risk.

View profile

Client & programme contact

Julia Andrade

Head of Client & Programme Success

A key point of contact from prospective-client scoping through programme and project delivery, coordinating practitioners, workstreams and client stakeholders.

View profile

Related needs

Where this naturally leads

Investment

ISO/IEC 27001 Readiness Assessment — Starting investment: £7,500 + VAT

Broader readiness and implementation programmes are scoped to requirement. Scope, deliverables, assumptions and fees are agreed in writing before work begins.

Talk to a Senior Practitioner How engagements & investment work

The fee depends on

  • ISMS scope, sites and entities
  • Current maturity and existing documentation
  • Number of systems, suppliers and teams in scope
  • Depth of implementation support required
  • Target audit date
  • Readiness review and audit-preparation support

Questions

Frequently asked questions

Does IG-Smart certify organisations to ISO/IEC 27001?

No. IG-Smart prepares organisations for certification. The certification audit and decision are made by an independent accredited certification body that you appoint.

Does readiness support guarantee certification?

No. It reduces the risk of surprises by testing your ISMS and evidence beforehand, but the outcome rests with the certification body.

Which edition of the standard do you work to?

ISO/IEC 27001:2022, with Annex A controls aligned to ISO/IEC 27002:2022.

IG-Smart holds ISO/IEC 27001 itself — is that relevant?

IG-Smart operates its own certified ISMS, so the team understands running one day to day. It is IG-Smart's own certification, separate from client outcomes.

Can you also be our internal auditor?

Yes, where independence allows. IG-Smart does not internally audit an ISMS it helped implement in the same cycle.

Next step

Need to show customers your information security is independently certifiable?

Not sure what applies?Find the Right Service