ISO/IEC 27001 is the international standard for an information security management system, and the 2022 revision is now the only certifiable one. It sets mandatory requirements in clauses 4 to 10 and lists 93 Annex A controls you select from on your own assessment of risk.
An ISMS you can put in front of a certification auditor.
Certification is issued by an accredited body. We get you ready for the audit it runs.
Our promise
“A certificate is a date. The controls are evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework readiness assessment produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this readiness assessmentISO 27001, in three chapters
Most programmes can name the controls. Far fewer can produce the scope argument, the risk method, the Statement of Applicability and a finished internal audit cycle — which is the order a certification body actually reads them in, and where Stage 1 turns into a findings list.
We are not the body that certifies you, and that is exactly the point of us. iDharma tests the ISMS against every clause and all 93 controls, drafts the Statement of Applicability, and hands back the gap list that body will raise — at a point in the programme where you can still close it.
A system you run, not a checklist you pass.
A governance system for information security that must be operated, measured and improved.
- Nobody legally — and almost everybody commercially
- SaaS and cloud providers, where it is now a buying gate
- Processors handling customer data at scale
- Regulated and public-sector suppliers
- Seven mandatory clauses, 4 through 10
- 93 Annex A controls in four themes
- A Statement of Applicability addressing every one
- An internal audit cycle finished before Stage 2
The ISMS is yours. The certificate is theirs.
The organisation being certified
The ISMS is yours, and clause 5 puts it on top management rather than on a security team. Scope, policy, risk decisions and the Statement of Applicability are all yours to own - and none of them can be delegated to a consultant, to an auditor, or to whoever happens to help you write them down.
The people who issue the certificate
An accredited body runs Stage 1 and then Stage 2, and decides whether you are certified. It is independent of you and of us by design, it is the only party whose signature puts a certificate on your wall, and it is the one you should be preparing for rather than negotiating with on the day itself.
A readiness review is not a certificate
We are neither of the above. iDharma assesses how ready you are against the standard and prepares the evidence and gap list the certification body will ask for - which is why nothing we find is ever commercially convenient for us. We have no certificate to sell you and no stake in whether you pass.
“We’re certified — it’s on the wall.”
If it reads 2013, it expired in October 2025.
Your customers can check that before you tell them.
- Who it is for
- SaaS & cloud providers
- Data processors at scale
- Regulated suppliers
- Public-sector tenders
- Teams already doing GDPR
Annex A went from 114 controls in fourteen domains to 93 in four themes, and eleven of the controls in it were added outright.
Cloud services, threat intelligence, secure coding and data leakage prevention are all now named controls rather than implications of others.
Nobody is legally required to hold it, which is why the deadline arrives from procurement. A questionnaire is harder than most statutes.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your readiness check
Four moments, and only one issues anything.
Each of these is set by the certification body rather than by you - so they cannot be added up, and they cannot be run in parallel.
-
Document
Before you bookScope, policy, risk method and the Statement of Applicability exist on paper, and the records behind them exist too.
-
Review
Stage 1The auditor reads the ISMS. What comes back is a readiness verdict and a findings list - not a certificate, and not a pass.
-
Test
Stage 2Controls sampled, people interviewed, evidence followed. Major nonconformities close before anything is issued.
-
Sustain
Every year afterSurveillance audits in years one and two, then a full recertification in year three. The certificate is not a finish line.
Teams book Stage 2 and forget that clause 9.2 wants a completed internal audit cycle behind them, with findings closed. Arriving without one is the most common avoidable failure there is - and it is the one an auditor spots in the first hour.
What the standard asks, what we ship
12 requirements, and the artefact that evidences each one. Paired, so every claim on this page can be checked against the requirement beside it.
- Context and ISMS scope Clause 4
- A scope statement with its boundary argued rather than asserted, the interested parties named, and the exclusions written down before an auditor asks about them.
- Leadership and policy Clause 5
- An information security policy that maps to how you actually operate, with roles and authorities assigned to people who can exercise them.
- Risk assessment and treatment Clause 6.1
- A repeatable method, a populated risk register, and a treatment plan carrying owners, dates and residual risk accepted by someone empowered to accept it.
- Statement of Applicability Clause 6.1.3 - all 93
- Every Annex A control addressed with an included-or-excluded decision, its justification, and the risk that drove it. Mandatory, and read first.
- Objectives and planning Clause 6.2
- Security objectives that are measurable, resourced and owned, with the plan to reach them rather than the intention to.
- Support and competence Clause 7
- Competence evidenced rather than asserted, awareness that reaches the whole workforce, and documented information under version control.
- Operation Clause 8
- Operational planning and control, risk reassessed at planned intervals and on material change, and outsourced processes governed rather than assumed.
- Monitoring and measurement Clause 9.1
- What is measured, how, how often, who reviews it and what happens when it moves - the clause asks for all five and most programmes can answer two.
- Internal audit Clause 9.2
- An audit programme with real independence, a full cycle completed before Stage 2, and findings tracked to closure rather than to a spreadsheet.
- Management review Clause 9.3
- A review that produces decisions and resource commitments, minuted as such - not a standing agenda item that notes the ISMS still exists.
- Improvement Clause 10
- Nonconformities recorded, root cause addressed rather than the symptom, corrective actions verified as effective, and a trend an auditor can follow.
- Annex A control selection Four themes, 93 controls
- Organisational, people, physical and technological controls selected from the risk assessment - with the thin themes named before a certification body names them.
Your ISMS, independently tested
From one product line to the whole estate.
-
Scope
What the ISMS covers, and where its boundary will actually hold.
-
Test
Clauses 4 to 10 and all 93 controls, against what you really run.
-
Report and hand over
You see the draft first. Then the gap list, the SoA and the plan - dated.
Why teams choose iDharma to get ISO 27001 ready
No certificate to sell
We are not a certification body and cannot become yours, so nothing we find is convenient for us.
Written to the clause
Every finding names the clause or the control it comes from, so your auditor can check it against the standard.
All 93, decided
The Statement of Applicability is drafted with every control addressed, not the forty that were easy to justify.
Ready for Stage 1
The output is the gap list and evidence pack a certification body asks for, in the order it asks for them.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
ISO 27001 readiness report
The full review: where the ISMS stands against clauses 4 to 10 and against all 93 Annex A controls, written clause by clause with each gap ranked by what it will cost you at Stage 2 rather than by how easy it is to close. Where a scope or exclusion call is genuinely arguable, it says so instead of picking the convenient reading.
Statement of Applicability
All 93 controls addressed with an included-or-excluded decision, the justification behind each, and the risk that drove it - the document an auditor opens first.
Risk method and register
A repeatable assessment method, the register populated against your real estate, and a treatment plan carrying owners, dates and formally accepted residual risk.
ISMS policy and procedure set
The documented information clause 7.5 requires, written to your operations rather than adopted generically - which is a difference an auditor notices immediately.
Internal audit programme
A programme with genuine independence, a full cycle you can run before Stage 2, and a findings register that tracks to closure rather than to a spreadsheet.
Management review pack
The inputs clause 9.3 expects, assembled into a review that produces decisions and resource commitments rather than minutes recording that one happened.
Stage 1 readiness pack
The gap list and evidence bundle an accredited body asks for, ordered the way it asks - so the documentation review finds a prepared ISMS rather than a surprise.
Real numbers, upfront.
- Scope
- Set by the standard, not by us
- Output
- A gap list, not a certificate
- Re-review
- Before each surveillance audit - $10,500 against your known baseline
The standard fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- Gap analysis, clauses and all 93 controls
- Statement of Applicability, drafted
- 24 ISMS policy and procedure documents
- Internal audit and Stage 1 packs
Four things Stage 1 will ask you to produce
An ISMS is not graded on intent. Each of these is either in your hand on the day the auditor arrives, or it is not.
The scope,
defensible
A boundary you can argue for, with the exclusions written down and justified. Get this one wrong and every later conversation is about the wrong system entirely.
The SoA,
complete
All 93 controls addressed with a decision and a reason. A Statement of Applicability that simply omits a control is the place where a thin programme becomes visible.
The audit,
already run
A full internal audit cycle finished, with its findings closed rather than merely logged. Arriving at Stage 2 without one is the most common avoidable failure there is.
The evidence,
dated
Records generated as the controls ran, not assembled the week before. An auditor is testing operating history, and history cannot be written retrospectively.
Four cards, and the date on each one is part of the card.
Plain answers
Versions, controls, the SoA, the audit, cost. Answered straight.
Request this reviewIs the 2013 version still valid?
No. The transition closed on 31 October 2025 and every certificate issued against ISO/IEC 27001:2013 expired with it. A customer checking the register will see that before you tell them.
What changed in the 2022 revision?
Annex A went from 114 controls in 14 domains to 93 in four themes, eleven were added - threat intelligence, cloud services, data leakage prevention and secure coding among them - and every control gained five attributes. The clauses are substantively unchanged.
Do we have to implement all 93 controls?
No - you have to consider all 93 and record a decision on each. Controls are selected from your risk assessment and exclusions are legitimate where justified. What is not legitimate is a Statement of Applicability that does not address a control at all.
Do we need an internal audit before certification?
Yes, and a complete one. Clause 9.2 requires an internal audit programme, and certification auditors look specifically for evidence the ISMS has audited itself and acted on what it found. Arriving at Stage 2 without one is the most common avoidable failure.
What does an iDharma readiness review cost, and what comes with it?
A flat fee, stated in full on this page, with nothing charged until you approve the scope. It covers the gap analysis, the drafted Statement of Applicability and the policy set the review writes against. The certificate itself is issued by an accredited body, not by us.
Request your readiness review
Tell us what the ISMS covers and we come back with a scoping call within one day.
What we need from you
Nothing you do not already have. Most of this comes out of your existing security paperwork in an afternoon, and we tell you exactly which extracts before you commit.
- What the ISMS scope covers, and what it excludes
- Whatever asset inventory and risk register exist
- Your Statement of Applicability, if there is one
- The last internal audit and management review
- Your target Stage 1 date, if a customer set one
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022
- IAF transition requirements and accredited bodies
- Published
- October 2022
- 2013 expired
- 31 October 2025
What it means
- General information about what the standard requires — not legal advice, and not a certification decision.
- Where a scope or exclusion question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- Nothing here quotes the standard. ISO text is copyright, so every clause and control is described in our own words. The 2022 structure, the four themes and their counts, the eleven new controls and the transition date were checked; the clause-level detail below that is written from the standard as practised, not line-checked against it.
- iDharma cannot certify you. Only an accredited body can, and nothing here predicts what it will decide.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.