All products

Compliance audit

ISO 27001 readiness

A Statement of Applicability is the first document a certification body asks for, and the one most small businesses have never written. This produces it: all 93 Annex A controls marked applicable or excluded, each with a reason that survives being questioned, and the applicable ones scored on the evidence you actually hold rather than on intent.

What you hold at the end. A Statement of Applicability in the portal, with a decision and a justification against all 93 controls.

Talk to us about this

Price

On enquiry

Timeframe

Three to four weeks

How it works

  1. Step 01

    We scope what your ISMS actually covers

    Which systems, which people, which premises. This decides more than anything else: a business with no office and no employees legitimately excludes a seventh of Annex A, and an exclusion you can justify is worth more than a control you cannot evidence.

  2. Step 02

    Every control gets a determination, not a tick

    Applicable or excluded, one at a time. The standard requires a justification for each exclusion, and that is the part auditors read first because it is where a scope gets quietly narrowed to whatever was easy.

  3. Step 03

    The applicable ones are scored on evidence

    What exists today, named. Nothing is marked met without something behind it, because the register refuses a met with no evidence attached, and a claim you cannot stand over is worse than an admission.

  4. Step 04

    It lands in the same register as everything else

    Your GDPR and AI Act obligations already live there. ISO controls join them rather than starting a second spreadsheet, with review dates that warn before they lapse and escalate when they do.

What is included

  • All 93 Annex A controls decided
  • A written justification for every exclusion
  • Annual review dates set and enforced

Questions

Does this certify us?
No, and be careful of anybody who says it does. Certification is issued by an accredited body after their own audit. This is the work that has to be done before calling one is worth the money, and it is the work most of the cost usually goes on.
We have no office and four people. Is most of it irrelevant?
A good part of it, and saying so in writing is the point. On our own ISMS 14 of the 93 are excluded: the physical controls that presuppose premises, and the people controls that presuppose employees. Each exclusion carries a reason, and the ones about employment lapse the day you hire somebody.
What happens after?
The register is kept current under the compliance retainer, at no extra monthly cost. A Statement of Applicability that is not reviewed is a document, and the point of holding it as data is that it cannot go stale quietly.

Talk to us

Tell us what the work looks like now. We will say whether ISO 27001 readiness is the right line for you, and what it would cost.

Send us the detail

Everything else we sell

All products →