First, The Diagnosis
ISO 27001 feels enormous. That's why most firms stall.
It's usually not a lack of will — it's not knowing where to start, fear of a huge cost, and a standard written in language that doesn't tell you what to actually do. Sound familiar?
"A big client / tender requires ISO 27001 and we're about to lose the deal."
"We don't know where we currently stand or how far off we are."
"We're worried it'll cost a fortune and take over the business for a year."
"We started, got lost in the documentation, and it stalled."
The fix isn't heroics — it's a clear starting point, a realistic plan, and someone who has read the standard so you don't have to.
Plainly
What it actually is — and what we honestly do.
ISO/IEC 27001 is the world's recognised standard for an information security management system (ISMS) — a documented, risk-based way of protecting your information, proven to work rather than just claimed. It's the credential enterprise and international clients trust.
Our honest role: we do the readiness and implementation — the gap analysis, the risk assessment, the ISMS, the policies and controls, and internal audit preparation. The certificate is then issued by an independent accredited certification body after their audit; that separation is exactly what makes it credible, and we won't pretend to issue it ourselves. We get you to that audit ready to pass.
Three Ways Forward
Start with where you stand. Go as far as you need.
You don't commit to the whole journey up front. Most begin by finding out how far off they really are — which is usually less scary than they feared.
Gap Analysis
The honest starting point.
- We measure you against ISO 27001
- A clear report of what's in place and what's missing
- A realistic roadmap, effort and cost estimate
- No obligation to go further with us
Readiness & Implementation
From gaps to certification-ready.
- Risk assessment & treatment plan
- The full ISMS — policies, controls, documentation
- Staff awareness & the evidence auditors expect
- Internal audit & management review, ready for the certification audit
Managed ISMS
Certification is a start, not an end.
- Ongoing ISMS operation & evidence upkeep
- Support through surveillance audits
- Continuous improvement & risk review
- Tied into your wider security posture
Our recommendation: start with the Gap Analysis — it's cheap, quick, and it replaces fear with a number and a plan. Most organisations then move into Readiness & Implementation once they see the path is manageable; the managed tier keeps the certificate alive year after year.
Where This Gets You
The tick-box that opens doors — backed by the real thing.
The destination is simple: when a client, partner or tender asks "are you ISO 27001?", you have a credible, evidenced answer — and the contracts that were closed to you open up. But you also get the thing the badge is supposed to represent: a real, working security management system that genuinely lowers your risk. Pairs naturally with POPIA compliance and penetration testing, which share much of the same evidence.
Common Questions
Straight answers.
Do you issue the ISO 27001 certificate?
No — and no consultant honestly can. The certificate is issued by an independent accredited certification body after their own audit; that independence is what makes it trustworthy. We do everything up to that point: gap analysis, the ISMS, the evidence, and getting you ready to pass the audit.
How long and how much does it take?
It depends on your size and starting point, which is exactly what the gap analysis tells you. Rather than quote a scary number blind, we measure where you stand first and give you a realistic timeline and cost — most SME implementations are far more manageable than feared.
We already did a POPIA audit — does that help?
Yes, a lot. POPIA and ISO 27001 share a great deal of the same security foundation and evidence. If you've done POPIA work with us, you're already part of the way there, and we won't make you redo it.
Is it worth it if no one's asked us for it yet?
Increasingly, yes — because by the time a big client demands it, you may be weeks from a deadline you can't meet. Getting ready ahead of the ask turns ISO 27001 from a blocker into a competitive advantage you can lead with.