ISO/IEC 27001 has ceased to be an ornament on the chief executive's wall. It is often a condition of admission to a tender, an argument in due diligence, and the first question a corporate procurement department asks. Since November 2025 only the 2022 edition applies - the transition period has ended, certificates based on the 2013 version have expired, and every audit today follows the new structure of ninety-three Annex A controls. There is also the 2024 amendment, which requires climate change to be taken into account in the context of the organisation under clauses 4.1 and 4.2 - a small change in wording, a concrete one in the documentation. Implementing the standard is a project in which most depends on the first decisions: the scope of the system, the risk assessment methodology, and whether the documentation describes reality or wishful thinking. That is precisely where we begin.
IT companies and software houses whose corporate clients require the certificate
Organisations bidding in public tenders and sectoral procurement procedures
Local government and municipal companies building an ISMS for the National Interoperability Framework (KRI) and the Polish NCS Act
Organisations within the scope of NIS-2, for which the standard is the natural framework for compliance
Manufacturing, logistics and service companies processing counterparty data
The full cycle - from settling what the system covers, to support on the day of the certification audit and in the surveillance years that follow.
Gap analysis and scope - We establish where the organisation stands today against the requirements of the standard, and we agree the scope of the system together. Too broad a scope raises the cost of certification and maintenance; too narrow a one is dismissed by clients as lacking credibility - a decision that shapes the entire project.
Risk assessment - We select a methodology proportionate to the size of the organisation, identify assets and threats, estimate risk and prepare a treatment plan. The risk register is there to serve management, not the auditor - which is why we build it together with process owners.
Statement of Applicability and documentation - We work through all ninety-three Annex A controls, justifying every inclusion and every exclusion. In parallel we produce policies and procedures that describe how the organisation actually works.
Implementing the controls - We put in place the missing mechanisms across the four areas of the standard - organisational, people, physical and technological - including those introduced in the 2022 edition: threat intelligence, cloud security, configuration management, data masking and data leakage prevention.
Training and internal audit - We train staff, carry out the internal audit and run the corrective actions. Management goes through its first management review - the same one the certification body's auditor will ask about.
Certification and surveillance - We accompany you through the two-stage audit: the documentation review and the implementation audit. After certification we remain on hand for the annual surveillance audits and for recertification, so that the system stays alive rather than being revived a fortnight before the auditor arrives.
For an organisation of up to fifty people, with a single location and orderly IT, usually four to six months to certification readiness. On a larger scale, across several locations or with distributed infrastructure, it can run from eight to twelve months. The most common cause of delay is not the documentation but the implementation of real technical safeguards - access management, backups, monitoring. We build the schedule around whatever deadline matters to you, such as the date a tender submission falls due.
It is live only for organisations whose documentation is still based on the 2013 version - the transition period ended on 31 October 2025 and certificates issued against the old edition have expired. The 2022 edition restructured Annex A: instead of one hundred and fourteen controls across fourteen areas there are ninety-three across four groups, eleven of them entirely new. There is also the 2024 amendment, which introduces climate-related considerations into clauses 4.1 and 4.2. If the documentation has not been updated for several years, we begin by reviewing it.
No, and it cannot - that would be a conflict of interest the standard does not permit. The certificate is issued by an independent certification body accredited by the Polish Centre for Accreditation (PCA) or by its foreign equivalent, such as DNV, BSI or TUV. We prepare the organisation for that audit, help select the body and accompany you through the process. This separation of roles is in fact your safeguard: an adviser who audits their own work offers no assurance at all.
Quite the opposite - it is the most economical order in which to proceed. The KRI Regulation refers explicitly to the requirements of the standard, and the Polish NCS Act expects a risk management system for which ISO 27001 is the recognised model. In practice one system serves several compliance regimes at once, and the certificate becomes evidence of due diligence before the supervisory authority as well. We build the documentation so that compliance with each of these requirements can be demonstrated without duplicating work.
The certificate is valid for three years, but that is not a period of inactivity. In the first and second years the certification body conducts a surveillance audit, and in the third a full recertification. Between them the organisation must run internal audits, hold management reviews and update its risk assessment. We offer ongoing support through this cycle, because the most common reason for losing a certificate is not an incident but a simple failure to carry out the reviews.