What is ISO 27001?+
The international standard for an information security management system (ISMS). The certificate confirms that the organization manages information security as a continuous, documented process.
How long does the path to certification take?+
It depends on the starting point. We run a gap analysis, establish or improve the ISMS, and guide the organization through the certification audit. Typically the process takes several months to a year.
Do you issue the certificate?+
No. The certificate is issued by an accredited certification body. We prepare the organization and the evidence the auditor evaluates.
Is ISO 27001 sufficient on its own?+
ISO 27001 provides the governance framework, but it does not replace validation against real attacks. We recommend that controls are regularly verified through penetration testing, which gives the management system a technical confirmation.