International and enterprise doors
ISO 27001 is the certification global enterprises and overseas markets recognize. When a customer contract or tender names it, nothing lighter substitutes.
ISO/IEC 27001 readiness
ISO 27001 is a management system, not a checklist: risk process, policies, internal audit, and a certification body's two-stage audit at the end. We build the system and walk you to the audit ready.
Scope, timing, and fees are documented before work begins.
ISO 27001 is the certification global enterprises and overseas markets recognize. When a customer contract or tender names it, nothing lighter substitutes.
The standard demands a working management system: risk methodology, Statement of Applicability, internal audits, management reviews. Buying a policy template pack does not survive a Stage 2 audit.
Certification brings annual surveillance audits and a three-year recertification cycle. The program must keep operating after the party, which is why our retainer usually carries it.
Best fit: organizations of 25 to 200 people with a contractual or market driver naming ISO 27001, and leadership prepared to operate a management system, not just file one.
Not the right fit: companies with no external driver for ISO specifically; NIST and CIS alignment delivers most of the security value in a fraction of the time and cost, and we will say so on the call.
ISO/IEC 27001 certifies an information security management system (ISMS): the governance machine that decides risk, applies the Annex A controls that fit, and proves the loop runs. Certification is issued by an accredited certification body after a Stage 1 audit (documentation) and a Stage 2 audit (operation), then maintained through annual surveillance audits.
Readiness is the whole climb before the auditors arrive: scoping the ISMS, building the risk assessment methodology, producing the Statement of Applicability, writing policies people follow, standing up vulnerability management with real evidence, running the internal audit and management review the standard requires, and coordinating the independent penetration test that commonly supports the evidence.
We are deliberately not a certification body, and that is a feature: the firm that builds your system should not be the firm that judges it. We prepare you, help you choose the certification body, and stand behind you through both stages.
Every engagement includes
Example SoA extract
Illustrative structure only. Your findings, owners, evidence, and priorities are based on your environment.
See what your scope includesISMS boundary, gap assessment against Annex A and the management clauses, and a readiness plan sequenced backward from your target audit window. Price fixed in writing.
The system goes live: risk process running, policies adopted, controls operating, evidence accumulating, internal audit and management review completed. Usually steered through our retainer.
Stage 1, fixes, Stage 2, certificate. We prepare the package, sit with your team, and stay for the annual surveillance cycle if you want us to.
How pricing works
Your quote is built from your headcount, your systems, and how far you are from the bar. It is fixed in writing at the free 30-minute call, before any work starts, and it never changes after you approve it.
Separately scoped, always disclosed
The certification body's audit fees and the independent penetration test are third-party engagements quoted by those firms. Tooling, remediation labor and travel are their own line items when they apply. We take commissions from nobody.
No. Certification is issued by an accredited certification body after Stage 1 and Stage 2 audits. We build the ISMS, run the readiness, and prepare you for those audits. The builder and the judge should be different firms, and with us they always are.
Plan 6 to 12 months or more: the system has to demonstrably operate before Stage 2, and calendar time is part of the evidence. The biggest lever is starting the management-system clock early.
Sometimes, and we will say so. If no customer, contract or market names ISO specifically, NIST and CIS alignment buys most of the security value far faster and cheaper. ISO earns its cost when a named demand exists.
Annual surveillance audits and a three-year recertification cycle. The ISMS has to keep running: reviews, internal audits, risk updates, evidence. Most clients carry it on the fractional CISO retainer, which exists for exactly this.
We cover your organization, your deadline, and who is asking for what. You leave knowing the likely scope, the timeline, and your next step, with the price fixed in writing before any work starts.
Prefer phone or email?
(754) 216-9664 info@hardenwell.com
Do not include PHI or sensitive records in booking notes. See our Privacy Policy.