ISO/IEC 27001:2022 · ISMS · READINESS

An ISMS you can put in front of a certification auditor.

Certification is issued by an accredited body. We get you ready for the audit it runs.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
The standard is the yardstick, not the sales pitch
Clauses 4 to 10 93 Annex A controls Statement of Applicability Stage 1 and Stage 2 Internal audit

Our promise

“A certificate is a date. The controls are evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework readiness assessment produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this readiness assessment
Readiness assessment Certification is issued by an accredited certification body, not by iDharma. We assess your readiness against the standard and prepare the evidence and gap list that body will ask you for.
The case file

ISO 27001, in three chapters

The Standard

ISO/IEC 27001 is the international standard for an information security management system, and the 2022 revision is now the only certifiable one. It sets mandatory requirements in clauses 4 to 10 and lists 93 Annex A controls you select from on your own assessment of risk.

The Gap

Most programmes can name the controls. Far fewer can produce the scope argument, the risk method, the Statement of Applicability and a finished internal audit cycle — which is the order a certification body actually reads them in, and where Stage 1 turns into a findings list.

The Review

We are not the body that certifies you, and that is exactly the point of us. iDharma tests the ISMS against every clause and all 93 controls, drafts the Statement of Applicability, and hands back the gap list that body will raise — at a point in the programme where you can still close it.

What is an ISMS?

A system you run, not a checklist you pass.

A governance system for information security that must be operated, measured and improved.

Who ends up needing it № 01
  • Nobody legally — and almost everybody commercially
  • SaaS and cloud providers, where it is now a buying gate
  • Processors handling customer data at scale
  • Regulated and public-sector suppliers
ISO 27001 · iDharma · Presented for review
What the standard asks for № 02
  • Seven mandatory clauses, 4 through 10
  • 93 Annex A controls in four themes
  • A Statement of Applicability addressing every one
  • An internal audit cycle finished before Stage 2
ISO 27001 · iDharma · Presented for review
Whose job is which

The ISMS is yours. The certificate is theirs.

You

The organisation being certified

The ISMS is yours, and clause 5 puts it on top management rather than on a security team. Scope, policy, risk decisions and the Statement of Applicability are all yours to own - and none of them can be delegated to a consultant, to an auditor, or to whoever happens to help you write them down.

The certification body

The people who issue the certificate

An accredited body runs Stage 1 and then Stage 2, and decides whether you are certified. It is independent of you and of us by design, it is the only party whose signature puts a certificate on your wall, and it is the one you should be preparing for rather than negotiating with on the day itself.

The line

A readiness review is not a certificate

We are neither of the above. iDharma assesses how ready you are against the standard and prepares the evidence and gap list the certification body will ask for - which is why nothing we find is ever commercially convenient for us. We have no certificate to sell you and no stake in whether you pass.

What the certificate says

“We’re certified — it’s on the wall.”

What the register says

If it reads 2013, it expired in October 2025.

Your customers can check that before you tell them.

  • Who it is for
  • SaaS & cloud providers
  • Data processors at scale
  • Regulated suppliers
  • Public-sector tenders
  • Teams already doing GDPR
Why this matters in 2026
A black lever-arch binder lying closed on a dark desk under a warm light, its page block thick with filed records and the steel ring hole catching the light: the evidence an auditor works through.
01 The transition closed on 31 October 2025. Every certificate issued against the 2013 version expired with it — and a buyer checking the register sees that first.
02

Annex A went from 114 controls in fourteen domains to 93 in four themes, and eleven of the controls in it were added outright.

03

Cloud services, threat intelligence, secure coding and data leakage prevention are all now named controls rather than implications of others.

04

Nobody is legally required to hold it, which is why the deadline arrives from procurement. A questionnaire is harder than most statutes.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

The pressure -

It is voluntary, and that rarely helps. No law requires the certificate anywhere much. A customer’s procurement questionnaire is the deadline that actually bites.

Certificate held -

Only 2022 is certifiable. The transition window closed on 31 October 2025 and every 2013 certificate expired with it, whatever date is printed on the document.

The SoA -

It is the first thing read. Every Annex A control addressed with a decision and a reason. A control simply left out is where a thin programme becomes visible fastest.

The calendar

Four moments, and only one issues anything.

Each of these is set by the certification body rather than by you - so they cannot be added up, and they cannot be run in parallel.

  1. Document

    Before you book

    Scope, policy, risk method and the Statement of Applicability exist on paper, and the records behind them exist too.

  2. Review

    Stage 1

    The auditor reads the ISMS. What comes back is a readiness verdict and a findings list - not a certificate, and not a pass.

  3. Test

    Stage 2

    Controls sampled, people interviewed, evidence followed. Major nonconformities close before anything is issued.

  4. Sustain

    Every year after

    Surveillance audits in years one and two, then a full recertification in year three. The certificate is not a finish line.

The trap

Teams book Stage 2 and forget that clause 9.2 wants a completed internal audit cycle behind them, with findings closed. Arriving without one is the most common avoidable failure there is - and it is the one an auditor spots in the first hour.

Requirement & coverage

What the standard asks, what we ship

12 requirements, and the artefact that evidences each one. Paired, so every claim on this page can be checked against the requirement beside it.

Context and ISMS scope Clause 4
A scope statement with its boundary argued rather than asserted, the interested parties named, and the exclusions written down before an auditor asks about them.
Leadership and policy Clause 5
An information security policy that maps to how you actually operate, with roles and authorities assigned to people who can exercise them.
Risk assessment and treatment Clause 6.1
A repeatable method, a populated risk register, and a treatment plan carrying owners, dates and residual risk accepted by someone empowered to accept it.
Statement of Applicability Clause 6.1.3 - all 93
Every Annex A control addressed with an included-or-excluded decision, its justification, and the risk that drove it. Mandatory, and read first.
Objectives and planning Clause 6.2
Security objectives that are measurable, resourced and owned, with the plan to reach them rather than the intention to.
Support and competence Clause 7
Competence evidenced rather than asserted, awareness that reaches the whole workforce, and documented information under version control.
Operation Clause 8
Operational planning and control, risk reassessed at planned intervals and on material change, and outsourced processes governed rather than assumed.
Monitoring and measurement Clause 9.1
What is measured, how, how often, who reviews it and what happens when it moves - the clause asks for all five and most programmes can answer two.
Internal audit Clause 9.2
An audit programme with real independence, a full cycle completed before Stage 2, and findings tracked to closure rather than to a spreadsheet.
Management review Clause 9.3
A review that produces decisions and resource commitments, minuted as such - not a standing agenda item that notes the ISMS still exists.
Improvement Clause 10
Nonconformities recorded, root cause addressed rather than the symptom, corrective actions verified as effective, and a trend an auditor can follow.
Annex A control selection Four themes, 93 controls
Organisational, people, physical and technological controls selected from the risk assessment - with the thin themes named before a certification body names them.
The engagement

Your ISMS, independently tested

From one product line to the whole estate.

  1. Scope

    What the ISMS covers, and where its boundary will actually hold.

  2. Test

    Clauses 4 to 10 and all 93 controls, against what you really run.

  3. Report and hand over

    You see the draft first. Then the gap list, the SoA and the plan - dated.

Request a readiness review
An auditor in a light grey trouser suit over a white T-shirt, with long dark hair, standing against a warm pale wall and pointing into the open space alongside.
The gap list, before the certification body writes it.
Struck in your favour

Why teams choose iDharma to get ISO 27001 ready

No certificate to sell

We are not a certification body and cannot become yours, so nothing we find is convenient for us.

Written to the clause

Every finding names the clause or the control it comes from, so your auditor can check it against the standard.

All 93, decided

The Statement of Applicability is drafted with every control addressed, not the forty that were easy to justify.

Ready for Stage 1

The output is the gap list and evidence pack a certification body asks for, in the order it asks for them.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

ISO 27001 readiness report

The full review: where the ISMS stands against clauses 4 to 10 and against all 93 Annex A controls, written clause by clause with each gap ranked by what it will cost you at Stage 2 rather than by how easy it is to close. Where a scope or exclusion call is genuinely arguable, it says so instead of picking the convenient reading.

Drafted

Statement of Applicability

All 93 controls addressed with an included-or-excluded decision, the justification behind each, and the risk that drove it - the document an auditor opens first.

Workbook

Risk method and register

A repeatable assessment method, the register populated against your real estate, and a treatment plan carrying owners, dates and formally accepted residual risk.

Repository

ISMS policy and procedure set

The documented information clause 7.5 requires, written to your operations rather than adopted generically - which is a difference an auditor notices immediately.

Programme

Internal audit programme

A programme with genuine independence, a full cycle you can run before Stage 2, and a findings register that tracks to closure rather than to a spreadsheet.

Agenda

Management review pack

The inputs clause 9.3 expects, assembled into a review that produces decisions and resource commitments rather than minutes recording that one happened.

Gap list

Stage 1 readiness pack

The gap list and evidence bundle an accredited body asks for, ordered the way it asks - so the documentation review finds a prepared ISMS rather than a surprise.

Format & fee

Real numbers, upfront.

Scope
Set by the standard, not by us
Output
A gap list, not a certificate
Re-review
Before each surveillance audit - $10,500 against your known baseline

The standard fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
ISO 27001 · Readiness review $12,500 flat
  • Gap analysis, clauses and all 93 controls
  • Statement of Applicability, drafted
  • 24 ISMS policy and procedure documents
  • Internal audit and Stage 1 packs
Show your hand

Four things Stage 1 will ask you to produce

An ISMS is not graded on intent. Each of these is either in your hand on the day the auditor arrives, or it is not.

The scope,
defensible

A boundary you can argue for, with the exclusions written down and justified. Get this one wrong and every later conversation is about the wrong system entirely.

The SoA,
complete

All 93 controls addressed with a decision and a reason. A Statement of Applicability that simply omits a control is the place where a thin programme becomes visible.

The audit,
already run

A full internal audit cycle finished, with its findings closed rather than merely logged. Arriving at Stage 2 without one is the most common avoidable failure there is.

The evidence,
dated

Records generated as the controls ran, not assembled the week before. An auditor is testing operating history, and history cannot be written retrospectively.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Versions, controls, the SoA, the audit, cost. Answered straight.

Request this review
Is the 2013 version still valid?

No. The transition closed on 31 October 2025 and every certificate issued against ISO/IEC 27001:2013 expired with it. A customer checking the register will see that before you tell them.

What changed in the 2022 revision?

Annex A went from 114 controls in 14 domains to 93 in four themes, eleven were added - threat intelligence, cloud services, data leakage prevention and secure coding among them - and every control gained five attributes. The clauses are substantively unchanged.

Do we have to implement all 93 controls?

No - you have to consider all 93 and record a decision on each. Controls are selected from your risk assessment and exclusions are legitimate where justified. What is not legitimate is a Statement of Applicability that does not address a control at all.

Do we need an internal audit before certification?

Yes, and a complete one. Clause 9.2 requires an internal audit programme, and certification auditors look specifically for evidence the ISMS has audited itself and acted on what it found. Arriving at Stage 2 without one is the most common avoidable failure.

What does an iDharma readiness review cost, and what comes with it?

A flat fee, stated in full on this page, with nothing charged until you approve the scope. It covers the gap analysis, the drafted Statement of Applicability and the policy set the review writes against. The certificate itself is issued by an accredited body, not by us.

Get started

Request your readiness review

Tell us what the ISMS covers and we come back with a scoping call within one day.

What we need from you

Nothing you do not already have. Most of this comes out of your existing security paperwork in an afternoon, and we tell you exactly which extracts before you commit.

  1. What the ISMS scope covers, and what it excludes
  2. Whatever asset inventory and risk register exist
  3. Your Statement of Applicability, if there is one
  4. The last internal audit and management review
  5. Your target Stage 1 date, if a customer set one

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a readiness review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022
  • IAF transition requirements and accredited bodies
Published
October 2022
2013 expired
31 October 2025

What it means

  • General information about what the standard requires — not legal advice, and not a certification decision.
  • Where a scope or exclusion question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • Nothing here quotes the standard. ISO text is copyright, so every clause and control is described in our own words. The 2022 structure, the four themes and their counts, the eleven new controls and the transition date were checked; the clause-level detail below that is written from the standard as practised, not line-checked against it.
  • iDharma cannot certify you. Only an accredited body can, and nothing here predicts what it will decide.

Something on this page out of date?

Tell us