Sentrix

Services · Compliance

ISO/IEC 27001 certification support

From gap analysis to the certification body's audits, Sentrix structures your ISO 27001 journey and keeps the verification independent of the preparation.

Why this matters

A gap analysis alone doesn't get you certified. ISO 27001 rewards organizations that treat it as a living management system, not a documentation sprint before an audit deadline.

A deadline is already ticking

A strategic client, a tender or an international partner requires ISO 27001, with a firm deadline attached.

DIY stalls without an owner

Internal efforts often run out of steam for lack of time, method or a clear project owner.

Your MSP shouldn't grade its own work

An IT provider offering to "handle ISO 27001" blurs the line between implementation and independent verification.

The 2022 restructure changes the target

Annex A now has 93 controls across four themes; starting on an outdated version means redoing work later.

What sets this apart

We build the controls into how you operate, and keep the audit independent. We implement the missing controls with your IT, HR, legal and operations teams, then run the formal internal audit ourselves, the independent external perspective self-audit can't offer, before you ever face the certification body.

  • Access and identity controls implemented with your IT, HR and legal teams.
  • Supplier and third-party risk processes for anyone touching your data.
  • Logging and monitoring formalized into a reviewable cadence.
  • A formal internal audit run before the certification body's Stage 1 and Stage 2 audits.

Sample gap findings

Illustrative examples; they do not describe a specific client.

  • High: multi-factor authentication is not enforced for privileged accounts. Action: implement and evidence MFA before the Stage 2 audit.
  • High: supplier relationships with access to company data are not formally risk-assessed. Action: build a supplier risk assessment process with documented evidence.
  • Medium: logging is enabled across systems but not reviewed on a defined cadence. Action: formalize log review and retention to close the traceability gap.
  • Low: business continuity procedures are documented but have never been tested. Action: run and document a continuity test ahead of the internal audit.

What is ISO 27001 certification?

ISO/IEC 27001 is an international standard that specifies the requirements for an Information Security Management System (ISMS). Its purpose: to preserve the confidentiality, integrity and availability of your data, through controls spanning people, processes and technology.

Getting certified is not about writing documents to check boxes. It means building a living management system that combines three dimensions: organizational governance, technical cybersecurity and regulatory compliance. Certification is issued by an accredited third-party certification body (BSI, DNV, Bureau Veritas, SGS or Intertek, for example), following an independent audit, never by the firm that prepared you.

According to the text of ISO/IEC 27001:2022, the current version, Annex A was restructured and now has 93 controls grouped into four themes (organizational, people, physical, technological). The certificate runs on a three-year cycle with annual surveillance audits. The guide to clauses 4 to 10 details what the standard expects and the evidence the auditor will ask for; the ISO 27001 framework page summarizes the standard.

Preparing without certifying: our independence commitment

The rule is simple, and it protects the value of your certification: whoever supports you must not be the one who certifies you. We structure your process, build your ISMS and prepare you for the audits, but the certification body remains an accredited third party, chosen by you. We can present you several options, with no commercial ties to any of them. That is what guarantees a certificate that actually holds up with your clients and partners.

Who this support is for

  • SMEs and technology services companies that need to demonstrate their information security maturity to access new markets.
  • SaaS vendors, cloud providers and integrators receiving a growing number of client security questionnaires who want to answer them with a recognized framework rather than case by case.
  • Organizations that have lost, or risk losing, a tender for lack of certification, and want to structure the process once and for all.
  • Growing companies that need to demonstrate their cyber maturity to investors, a potential acquirer or a foreign parent company.
  • Organizations already compliant with other frameworks (SOC 2, GDPR or Law 25, NIST CSF) that want to capitalize on the work already done to reach ISO 27001 without starting from zero.

Is this the right time for you?

If you recognize your situation in any of the following, this support is designed for you.

  • A strategic client, a tender or an international partner requires ISO 27001, with a firm deadline.
  • You have read the standard, downloaded templates and started drafting policies, and you are realizing the gap between theory and implementation is bigger than expected.
  • You already attempted an internal effort that ran out of steam for lack of time, method or a clear project owner.
  • Your IT provider or MSP is offering to "handle ISO 27001," and you want to keep the verification independent from the implementation.
  • You are already compliant with GDPR, Law 25 or another framework, and want to know what actually remains to be done for ISO 27001, without redoing all the work.
  • You want a realistic estimate of the effort, cost and timeline before committing, not a "six months" promise pulled from a brochure.
  • You are starting on the 2022 version of the standard and want to account, from day one, for the new controls and the restructured Annex A.

What you get

Gap analysis

A full comparison between your current posture and ISO 27001:2022 requirements, with an action plan prioritized by risk level and a realistic estimate of the road ahead.

Defined certification scope

The delineation of the entities, services and sites covered: a strategic choice that directly affects cost, timeline and the certification's value with your clients.

Documented, right-sized ISMS

An Information Security Management System sized for your organization, structured around your operational reality, not a 500-page ISMS that ends up in a drawer.

Statement of Applicability (SoA)

The document justifying the inclusion or exclusion of each Annex A control, with the associated risk assessment and treatment plan.

Policies and procedures

The mandatory policies, procedures and records drafted, reviewed with your teams and adapted to your reality, with one guiding principle: every document must be usable, not just compliant.

Internal audit and management review

The formal internal audit required by the standard, conducted with an independent external perspective, plus the documented management review: two prerequisites for certification, run upfront to maximize your chances on the first pass.

Auditor-ready evidence file

An organized file, ready to present on the day, so you are not searching for documents in front of the certification auditor.

Post-certification maintenance plan

A clear cadence (annual internal audit, management review, tracking standard updates) to keep your certification through surveillance audits and renewal.

Our approach, step by step

A rigorous, transparent approach that turns a complex project into a managed, controlled process.

  1. Gap analysis. We map your current posture against ISO 27001:2022 requirements and the Annex A controls. We identify what is already in place and documentable, what is missing, and what needs realignment. Deliverable: a prioritized gap report and a clear recommendation on the achievable timeline.
  2. Scope and ISMS. We define with you the certification scope (which entities, which services, which sites) and structure the ISMS around your operational reality. This framing determines the cost, timeline and value of the certification.
  3. Controls and documentation. We implement the missing controls with your IT, HR, legal and operations teams, and draft the required policies, procedures and records. The ISO 27002:2022 and NIST CSF frameworks are used as support to translate the requirements into concrete practices.
  4. Internal audit and management review. We conduct the formal internal audit with an independent external perspective, a credibility that self-audit cannot offer, and prepare the management review. Both are mandatory prerequisites for certification.
  5. Certification audit support. We support you through the Stage 1 audit (documentation review) and the Stage 2 audit (implementation audit) conducted by the accredited certification body of your choice: translating the auditor's questions, structuring the answers, and managing any nonconformities and corrective action plans.
  6. Post-certification maintenance. An ISO 27001 certification has to be maintained. We remain available for the maintenance cadence (annual internal audit, management review, tracking standard updates), without locking you into a recurring contract: if your team can take over after the first cycle, that is a good outcome.

Why aim for ISO 27001 certification

Beyond the certificate, a well-run ISO 27001 process transforms your organization for the long term.

  • Commercial credibility: respond to tenders and client security questionnaires with an internationally recognized framework, instead of case by case.
  • Competitive advantage: stand out in sectors where certification has become a prerequisite, and reassure investors, acquirers and parent companies.
  • Tangible risk reduction: structure your security processes and reduce your exposure, both technically and on the regulatory side.
  • Better organization: clarify roles, responsibilities and processes, without unnecessary weight or bureaucracy.
  • Continuous improvement: build a lasting dynamic rather than a one-off effort that runs out of steam.

Getting the certificate is not enough. A truly successful certification is measured on several levels: certification with no major nonconformity at the initial audit, a sign of a well-scoped project; an ISMS that is easy to maintain over time and sustainable through annual surveillance audits; positive team engagement, with people who understand their role; processes that are structured without unnecessary bureaucracy; and a tangible reduction in risk. That is the lasting success we aim for, not just the formal issuance of the certificate.

Why trust Sentrix with your ISO 27001 journey

Independence preserved

We prepare; we do not certify. The choice of certification body remains yours, and we have no commercial ties to them, which protects the value of your certificate.

Multidisciplinary expertise

A team that covers governance, technical cybersecurity and regulatory compliance, backed by the ISO 27001:2022, ISO 27002:2022 and NIST CSF frameworks.

Operational support, not just standards knowledge

We act as project managers (a structured plan, clear milestones, follow-through) and adapt the requirements to the reality of your internal processes, without burying you in theory.

A maintainable ISMS

We build a structured, realistic and scalable system, able to stay compliant over time, rather than documentation that will not survive the first surveillance audit.

Where ISO 27001 fits

The reference point other frameworks get measured against. Work already done for SOC 2, GDPR, Law 25 or the NIST CSF can be reused: ISO 27001 doesn't mean starting from zero. For SMEs that find ISO 27001 out of reach for now, CAN/DGSI 104 certification is often a proportional first step. Once certified, Security Governance and Reporting keeps the internal audit and management review cadence running.

Let's talk about your ISO 27001 journey.

Whether you are under a firm client deadline, still weighing your options, or want to check your readiness, let's talk. A first conversation helps scope the perimeter and estimate an achievable effort and timeline. No commitment.

Contact us

Frequently asked questions

Do you issue the certification?
No, and that is deliberate. Certification is issued exclusively by an accredited third-party certification body, following an independent audit. We prepare and support you up to that audit, we run the internal audit and the management review, but we are never judge and jury. The choice of certification body remains yours, with no commercial ties on our side.
What changed between ISO 27001:2013 and ISO 27001:2022?
The 2022 version restructured Annex A, which now has 93 controls grouped into four themes (organizational, people, physical, technological), and introduced new controls. We start directly on the current version to avoid any rework: a project started on the outdated version has to be redone later.
We are already compliant with Law 25, GDPR or SOC 2. Does that speed up ISO 27001?
Yes. Some of the work already done (policies, controls, risk assessments) can be reused. The gap analysis pinpoints exactly what is transferable and what remains to be done, so you do not start from zero. The ISO 27002:2022 and NIST CSF frameworks are used as support to translate the remaining requirements into concrete practices.
Can we narrow the scope to certify faster?
Yes. Scope is a strategic lever: certifying a single product or service can reduce cost and timeline. But too narrow a scope can also limit the certificate's value with your clients. We define with you the entities, services and sites covered, with full knowledge of the trade-offs, as the second step of the process.
What happens if we fail the certification audit?
An audit surfaces nonconformities, which are addressed through corrective action plans within timelines agreed with the auditor. Our upfront preparation (formal internal audit, management review, auditor-ready evidence file) is specifically designed to avoid major gaps on the first pass, and we stay involved to manage any nonconformities that do come up.

Let's talk about your compliance program.

Last updated: 2026-09-17