Compliance · ISO 27001 compliance

Gap analysis and technical testing for ISO 27001 certification

Certification audits check that controls exist and that they work. We assess your ISMS against ISO 27001:2022, test the technical Annex A controls and leave you with an evidenced remediation plan.

Scope

What we cover

Gap analysis

Clause 4 to 10 and Annex A controls reviewed against your current policies, procedures and evidence.

Technical control testing

Vulnerability management, access control, cryptography, logging and secure development controls tested in practice.

Risk assessment support

Methodology, asset and risk register review, and treatment plan alignment.

Audit readiness

Statement of Applicability review and preparation for stage 1 and stage 2 audits.

How it works

From scoping call to closed findings

01

Assess

Document review and interviews with control owners across the organisation.

02

Test

Technical controls validated by penetration testing and configuration review.

03

Plan

Prioritised remediation roadmap with owners and effort estimates.

04

Prepare

Evidence pack and mock audit ahead of your certification body's visit.

Deliverables

What you receive

  • Gap analysis report by clause and Annex A control
  • Technical testing report
  • Remediation roadmap
  • Audit evidence pack
FAQ

Common questions about iso 27001 compliance

No. Certification is issued by an accredited certification body. We prepare you for that audit and provide the technical testing evidence it requires.

Book a scoping call

Scope your iso 27001 compliance engagement

A 30-minute call with a SecureBlock lead to align on objectives, assets and timeline. We follow up with a written scope and fixed-fee proposal within two business days.

Prefer email? sales@secureblock.io

No commitment. We reply within one business day.