Skip to main content
Compliance Readiness

ISO 27001
Readiness

ISO 27001 is the certification enterprise buyers outside North America ask for, and it certifies a management system rather than a moment in time. We run the readiness engagement so your ISMS is real, documented, and ready for a registrar rather than assembled the week before Stage 1.

Certification Audit Surveillance Audit Readiness Assessment
readiness log ISO 27001 assessing
09:14:02scopeISO 27001:2022confirmed
09:14:17assessOrganizational Controls (A.5)walked
09:15:18assessPeople Controls (A.6)walked
09:16:19assessPhysical Controls (A.7)walked
09:18:40gapmarked complete, no evidence attachedblocker
09:19:05gapcontrol has no named owneropen
09:22:31evidencefiled against control · expiry trackedaccepted
09:24:12handoffrequirement → control → evidencemapped
your team assesses evidence vetted tracked in Talon
4
control areas walked
3
assessment paths
14
frameworks on one programme
0
methodology slides
Fit

Who this is for

Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.

Companies selling into Europe, the UK, or APAC where ISO 27001 is the default ask

Teams who already hold SOC 2 and want to reuse that work rather than start again

First-time certifiers who would rather build an ISMS that runs than a binder that satisfies

Organisations with a Stage 1 date already booked

Scope of work

What the engagement does

Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.

  • Define the ISMS scope and the boundary the certificate will name
  • Run the risk assessment and build the risk treatment plan the standard requires
  • Produce the Statement of Applicability with a defensible justification for every Annex A control included or excluded
  • Assess the Annex A controls in scope and record where you stand
  • Stand up the mandatory clauses - internal audit, management review, corrective action - so they exist before the registrar looks for them
  • Prepare for Stage 1 and Stage 2 and coordinate with your chosen registrar

What you walk away with

An ISMS that operates rather than a document set that describes one: a scope statement, a risk register with treatment decisions, a Statement of Applicability that holds up under questioning, and the clause 9 and 10 machinery running. Where SOC 2 evidence already exists, it is mapped across rather than recreated.

Sequence

How it runs

Four phases. You always know which one you are in and what is outstanding.

01

Scoping call

We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.

no charge
02

Assessment

We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.

Lorikeet assessor
03

Remediate and evidence

We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.

joint
04

Hand off to your assessor

You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.

with your assessor
Coverage

What the assessment covers

The control areas we walk for ISO 27001. Each breaks down into individual controls carrying status, owner and evidence in Talon.

01 Organizational Controls (A.5)
02 People Controls (A.6)
03 Physical Controls (A.7)
04 Technological Controls (A.8)
Who performs the assessment

Certification is issued by an accredited registrar, not by us. We prepare the ISMS, run the internal audit, and work with the registrar you select through Stage 1 and Stage 2.

Where it lives

It runs in Talon, not in a spreadsheet

Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.

  • Control-by-control status, kept current by the people doing the work
  • Evidence filed against the control it satisfies, with expiry dates tracked
  • The auditor request list, so nothing is chased over email
  • A readiness view that shows what an assessor would see
Already running a compliance platform?

Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.

Our partners
Questions

Asked on almost every ISO 27001 call

ISO 27001 certifies a management system against an international standard; SOC 2 is an AICPA attestation report on controls. ISO is the more common ask outside North America. The control overlap is substantial, which is why doing them in parallel costs far less than doing them separately.

It records which Annex A controls apply to your ISMS and why the rest do not. Registrars read it closely - an SoA that excludes controls without a defensible reason is one of the more common Stage 1 findings.

Yes. Clause 9.2 requires it, and clause 9.3 requires a management review. Both must have happened before Stage 2. We run the internal audit as part of readiness so it is genuine rather than retrospective.

Most of it. Access control, change management, incident response, supplier management and logging map closely. We map your existing controls to Annex A first, so the work is the gap rather than the whole standard.

Alongside

Rarely run alone

Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.

Next

ISO 27001 readiness, on your timeline

A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!