Independent assessment of your information security before the certification audit: gap analysis against ISO/IEC 27001, risk assessment, control review, PCI DSS readiness and OT security under ISA/IEC 62443.
Every clause and every Annex A control rated; a prioritised roadmap to certification with effort estimates.
Asset inventory, threat and vulnerability analysis, risk treatment plan and Statement of Applicability draft.
Scope definition, control review and remediation plan for merchants and service providers handling card data.
Zones and conduits, security levels and programme assessment for industrial control systems.
Policies, procedures and records checked for completeness and evidence — before an auditor asks.
Security awareness for staff and ISMS training for owners — see IMS Academy.
Readiness services are delivered by a separate team from the one that performs the certification audit. That separation is an accreditation requirement — and it is what makes the eventual certificate credible to your customers.
For an organisation of 50–200 people with basic IT controls in place. Larger scopes and multi-site ISMS take longer; we tell you the realistic timeline after the first review.
Tell us the scope — systems, sites, whether you target ISO/IEC 27001, PCI DSS or both.