Services/Capability

ISO 27001 Assessment

ISO 27001 readiness and certification preparation.

Delivered through
The right vCISO engagement
Engagement levels
Advisory · Managed · Embedded
What you get

Deliverables

Full ISO 27001 readiness engagement: scope definition, Statement of Applicability development, gap analysis, risk register creation, policy authoring, internal audit support, and certification body liaison. Built for companies targeting first-time certification, not surveillance audits.

  • ISMS scope definition and Statement of Applicability
  • Gap analysis against Annex A controls
  • Risk register and treatment plan
  • Policy authoring across all Annex A domains
  • Internal audit program setup and first-round audit
  • Certification body selection and liaison support
Fit

Who this is for

International-facing SaaS companies, companies with European or UK customers, and organizations where SOC 2 alone is not enough.

Related capabilities

Not ready to talk? Score your SOC 2 readiness.

Twenty questions, a scored PDF in your inbox, a realistic timeline to audit. Free.

Start the scorecard

Ready when you are

Your next move starts with a 30 minute call.

If vCISO.com is not a fit, we will say so and point you toward someone who is. If we are, we will identify the right ownership level and scope the engagement on the call.