Who it applies to
▸Organizations that want a demonstrable, internationally recognized security baseline
▸Vendors for which certification is a condition of enterprise and public-sector contracts
▸Organizations that want to run security as a managed system
What it requires
The obligations, clearly explained.
01
A management system (ISMS)
A documented information security management system with a clearly defined scope and objectives.
02
Risk assessment
A repeatable process for identifying, evaluating, and treating risk.
03
Annex A controls
Selection and implementation of the controls relevant to the organization's risk, with documented justification.
04
Audit and review
Internal audit, management review, and a certification audit by an accredited body.
How Raptoric helps
We do the engineering work, not just the documentation.
Gap analysis
We establish your current posture against the standard and the 2022 control set.
ISMS implementation
We set up the management system, policies, and risk management process.
Control implementation
We implement and validate the technical controls, not only the documentation.
Certification readiness
We prepare the organization for the certification audit and provide support through the process.
We prepare the organization and validate the controls. The certificate is issued by an accredited certification body.
Services that deliver it
FAQ
Questions, answered
What is ISO 27001?
The international standard for an information security management system (ISMS). The certificate confirms that the organization manages information security as a continuous, documented process.
How long does the path to certification take?
It depends on the starting point. We run a gap analysis, establish or improve the ISMS, and guide the organization through the certification audit. Typically the process takes several months to a year.
Do you issue the certificate?
No. The certificate is issued by an accredited certification body. We prepare the organization and the evidence the auditor evaluates.
Is ISO 27001 sufficient on its own?
ISO 27001 provides the governance framework, but it does not replace validation against real attacks. We recommend that controls are regularly verified through penetration testing, which gives the management system a technical confirmation.
Further reading