Oman United Kingdom Norway Support portal
Talk to an expert
AboutContact

ISO/IEC 27001

From gap assessment to a certification-ready management system: defensible scope, a risk method your team can run, and evidence collected as work happens.

Start ISO 27001
Frameworks
ISO · NIST · NIS2 · GDPR · PDPL
Output
Audit-ready evidence
Reporting
Arabic and English

Why organisations get stuck

Compliance programmes stall when documents are written for auditors rather than for the people who have to follow them. Our ISO/IEC 27001 programme produces a management system your own teams can operate after we leave.

What the programme covers

Each area below is a defined part of the engagement, with an owner, an output and a date.

Scope

A defensible boundary statement agreed before any control work begins.

Risk

Risk expressed in terms of safety, availability and financial impact.

Policies

Documents staff can follow, approved through your own governance route.

Controls

Annex A or framework controls mapped to what you already run.

Internal audit

Independent testing against the standard ahead of the certification body.

Management review

Board-ready inputs, decisions and records the auditor will ask for.

The management system cycle

PLANScope, risk, controlsDOPolicies, training, operationCHECKInternal audit, metricsACTCorrective action, reviewEVIDENCEcollected aswork happens
Evidence collected as work happens, not before the audit.

How the work runs

The same sequence on every engagement, so you know what happens next.

STEP 01

Assess

A gap assessment against the standard, showing what already passes as well as what does not.

STEP 02

Design

Scope, risk method, policy framework and control set agreed with your management team.

STEP 03

Implement

Documents written with the people who will follow them, and controls embedded in existing processes.

STEP 04

Audit

Internal audit and management review run properly, producing the records the certification body expects.

STEP 05

Sustain

Ongoing operation of the management system, or handover to your team with training.

What you get out of it

A system your team can run

Documents and processes written to be operated after we leave.

Audit-ready evidence

Evidence collected as work happens rather than assembled the week before the audit.

Bilingual delivery

Policies, training and reporting available in Arabic and English.

Standards and references: ISO/IEC 27001:2022 · ISO/IEC 27002:2022 · ISO/IEC 42001:2023 · NIST CSF 2.0 · Oman PDPL · Cyber Essentials

Before you enquire

How long does certification readiness take?
It depends on your starting point, which is what the gap assessment establishes. You get an indicative timeline with the assessment, not before it.
Can policies and reports be produced in Arabic?
Yes. Documentation, awareness material and audit evidence are available in Arabic and English, which matters where a regulator will read them.
Do you also perform the certification audit?
No, and no consultancy should. Certification is awarded by an accredited certification body. We prepare you for it and support you through it.

Start ISO 27001

One scoping call with the consultant who would run the work. No obligation, no charge.

Start ISO 27001
Talk to an expert