attackless
← Services
Certification readiness

ISO 27001, built as a management system — not a one-off project

We help you design, document, and run an information security management system (ISMS) that satisfies ISO/IEC 27001: scope and risk assessment, a Statement of Applicability, policies your team actually follows, and the internal audit evidence a certification body will expect to see.

The framework

ISO 27001 runs on a cycle, not a checklist

The standard is built around Plan–Do–Check–Act: a continuous loop of setting objectives, implementing controls, checking they work, and acting on what you learn. An ISMS that stops after the first pass through isn't really an ISMS — it's a snapshot. We set up the cycle so it keeps running after we're gone.

01 PLAN 02 DO 03 CHECK 04 ACT ISMS 27001
  • 01Plan

    Define the ISMS scope, run the risk assessment, and draft the Statement of Applicability — the document that maps every Annex A control to your actual environment and justifies what you include or exclude.

  • 02Do

    Turn the plan into policies, procedures, and technical controls people can follow day to day: access management, incident response, supplier security, backups, and the rest of the SoA brought to life.

  • 03Check

    Run the internal audit, review control effectiveness, and gather the evidence a certification body will ask for — before they ask for it, not while they're in the room.

  • 04Act

    Close gaps, update the risk treatment plan, and feed findings from the audit and management review back into the next planning cycle. The loop keeps the ISMS current instead of frozen at certification day.

Where you stand

Readiness is a checklist, not a score

We won't hand you a percentage that claims to predict an audit outcome — no one can promise that, and anyone who does is guessing. What we do track, honestly, is which milestones are actually in place. Here's what "ready for a certification audit" looks like in practice.

  • 1

    ISMS scope defined

    The boundaries of what's covered — systems, locations, teams, third parties — are written down and agreed with leadership.

  • 2

    Risk assessment complete

    Assets, threats, and vulnerabilities are identified and scored against a documented methodology, not a gut feeling.

  • 3

    Statement of Applicability drafted

    Every Annex A control has a stated status — applied, planned, or excluded — with a reason a third party can follow.

  • 4

    Policies in place

    The mandatory ISMS policies exist, are approved, and are actually distributed to the people expected to follow them.

  • 5

    Internal audit done

    Someone independent of the process being audited has checked it, and findings are logged with owners and dates.

How we work

Engagements typically start with a scoping workshop and a gap assessment against Annex A, then move through risk assessment, policy drafting, and control implementation alongside your team. We prepare the evidence pack — scope statement, risk register, SoA, policy set, and internal audit report — that a certification body will review.

An honest note on certification: attackless prepares your ISMS for certification — we do not issue certificates. Certification against ISO/IEC 27001 is performed by an independent, accredited certification body following its own audit process. Our job is to make sure you walk into that audit with a management system that holds up.