ISO 27001 Certification, Made Straightforward
ISO/IEC 27001 is the international standard for information security management. We help you build the ISMS, implement the right controls, and get audit-ready, led by certified ISO 27001:2022 Lead Auditors.
What is ISO 27001?
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It sets out a risk-based framework for identifying, assessing and treating information security risks across people, process and technology.
Certification is issued by an independent, accredited certification body after a two-stage audit - Eye On Bits prepares your organisation for that audit; we do not issue the certificate ourselves, which is what keeps it credible to your customers and regulators.
What's included
Gap Assessment
Gap assessment against ISO/IEC 27001:2022 and Annex A controls.
Risk Treatment Plan
Risk assessment methodology and risk treatment plan.
ISMS Documentation
ISMS documentation - policies, procedures and the Statement of Applicability.
Staff Awareness & Audit
Staff awareness training and internal audit.
Certification Audit Support
Certification audit (Stage 1 and Stage 2) readiness support.
Surveillance Audit Support
Post-certification surveillance audit support and continual improvement.
Our approach - Plan, Do, Check, Act
The same continuous-improvement cycle behind every compliance programme we run.
Plan
Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.
Do
Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.
Check
Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.
Act
Run the audit, then keep improving through continual, corrective and preventive action.
Other compliance frameworks
ISO 27701
Privacy Information Management System, extending ISO 27001 for GDPR/DPDPA alignment.
Learn more →Questions we get asked first
How long does ISO 27001 certification take?
Typically 8–16 weeks depending on how much of the ISMS already exists and how quickly evidence can be gathered - a gap assessment gives an accurate timeline for your organisation.
Do you issue the ISO 27001 certificate?
No. We prepare your ISMS and support you through the audit; the certificate itself is issued by an independent, accredited certification body.
What happens after certification?
ISO 27001 certification is valid for three years, with annual surveillance audits by your certification body. We can continue supporting your ISMS through those cycles.
Ready to get audit-ready for ISO 27001?
Tell us where you're starting from and we'll come back with a scoped proposal within two working days.
