ISO 27001, from gap analysis to audit.
CloudSoul maps your business against everything the standard expects, ranks the gaps worst first, and holds the evidence the certification body asks to see.
What ISO 27001 asks of you.
ISO 27001 certifies a way of working, not a product. These are the pieces it expects to find.
-
A management system you actually run
Security has to be a routine you keep, not a folder you filed.
-
A scope you can defend
You decide what is covered, and you say so plainly.
-
A risk assessment that drives what you do
Your own risks decide what gets done first.
-
Written policies and the records behind them
Every policy needs the records that show it is real.
-
Internal checks before anyone external looks
You test yourself first and fix what you find.
-
An independent audit at the end
An accredited certification body reviews the work and issues the certificate.
What working with us looks like.
Four steps. Each one feeds the next.
Model your business
You tell us what you do and what you run. Everything else is built from that.
See what is missing
We check your business against everything the standard expects. Back comes a ranked list, worst first, each item with the fix beside it.
Do the work
Start with the compliance work: write the policy, run the training, name the owner. Where a gap needs tooling instead, our Security Operations pillar covers it, switched on when your list calls for it.
Hold the evidence
Every step leaves a dated record in one place. The certification body does the audit, and finds that record already in order.
Questions buyers ask us.
How long does certification take?
It depends on your scope, your size and what you already hold. A company with policies and named owners in place moves quickly. Starting from nothing takes longer. We tell you which of those you are before you commit.
Do you issue the certificate?
An accredited certification body issues it, after an independent audit. CloudSoul gets you ready and holds every piece of evidence they ask to see.
We already have NIS2 work under way. Does it count?
Yes. The two overlap heavily, so most of the work counts twice. Map a control once and it lands against both frameworks.
What do we have to do ourselves?
The compliance work stays with you: policies, training, named owners. We supply the templates and the order to do them in, so nobody starts from a blank page.
Do we need to install anything?
Nothing to host and nothing to configure. You connect what you already run, and it works from there.
What happens after we are certified?
The certification body comes back for surveillance audits. Your evidence keeps building in the background, so there is nothing to reconstruct. As you hire, expand or add suppliers, what you hold still describes the company you are.