ISO 27001 / ISO 9001 Preparation — certification readiness, done before
ISO certification is a process with a clear structure. We've run it many times across different organisations and know where things slow down, where auditors focus, and how to keep the programme moving. We work alongside your team to implement controls, build documentation, and prepare everything needed for the certification audit.
A certification programme that actually moves
ISMS design
Scope, boundaries, and a Statement of Applicability that hold up under audit.
Risk register & treatment
A living risk register with a treatment plan your team can actually maintain.
Policies that get used
Information security policy and procedures written to match how you actually work.
Business continuity
BIA, recovery plans, and testing that satisfy the standard and survive a real incident.
Internal audit
A full internal ISMS audit and management review before the certification body arrives.
Audit-day support
Certification audit preparation and support, plus a corrective-action plan for anything raised.
Typical scope
- Gap analysis and assessment of existing ISMS documents
- ISMS scope definition and process boundaries
- Statement of Applicability
- Information Security Policy and internal procedures
- Information security risk register and risk treatment plan
- ISMS monitoring, measurement and control plan
- Business continuity management (BIA, recovery plans, testing)
- Employee training materials preparation and delivery
- Internal ISMS audit and audit report
- Management review and review protocol
- Non-conformity and corrective action plan
- Certification audit preparation and support
Frameworks & methodologies
Redziet to savā perimetrā
Tell us where you are today. A CYBORA engineer — not a salesperson — will come back with what actually applies to your situation.
- Reply within one business day
- Scoped to your regulatory frameworks
- No obligation, no sales pitch
Take control of your perimeter
Register for a pilot demonstration of the CYBORA GRC and HybridSOC platform. One team, accountable for your full cyber security lifecycle.