ISO 27001
Readiness
ISO 27001 is the certification enterprise buyers outside North America ask for, and it certifies a management system rather than a moment in time. We run the readiness engagement so your ISMS is real, documented, and ready for a registrar rather than assembled the week before Stage 1.
Who this is for
Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.
Companies selling into Europe, the UK, or APAC where ISO 27001 is the default ask
Teams who already hold SOC 2 and want to reuse that work rather than start again
First-time certifiers who would rather build an ISMS that runs than a binder that satisfies
Organisations with a Stage 1 date already booked
What the engagement does
Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.
- Define the ISMS scope and the boundary the certificate will name
- Run the risk assessment and build the risk treatment plan the standard requires
- Produce the Statement of Applicability with a defensible justification for every Annex A control included or excluded
- Assess the Annex A controls in scope and record where you stand
- Stand up the mandatory clauses - internal audit, management review, corrective action - so they exist before the registrar looks for them
- Prepare for Stage 1 and Stage 2 and coordinate with your chosen registrar
What you walk away with
An ISMS that operates rather than a document set that describes one: a scope statement, a risk register with treatment decisions, a Statement of Applicability that holds up under questioning, and the clause 9 and 10 machinery running. Where SOC 2 evidence already exists, it is mapped across rather than recreated.
How it runs
Four phases. You always know which one you are in and what is outstanding.
Scoping call
We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.
Assessment
We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.
Remediate and evidence
We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.
Hand off to your assessor
You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.
What the assessment covers
The control areas we walk for ISO 27001. Each breaks down into individual controls carrying status, owner and evidence in Talon.
Certification is issued by an accredited registrar, not by us. We prepare the ISMS, run the internal audit, and work with the registrar you select through Stage 1 and Stage 2.
It runs in Talon, not in a spreadsheet
Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.
- Control-by-control status, kept current by the people doing the work
- Evidence filed against the control it satisfies, with expiry dates tracked
- The auditor request list, so nothing is chased over email
- A readiness view that shows what an assessor would see
Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.
Our partnersAsked on almost every ISO 27001 call
ISO 27001 certifies a management system against an international standard; SOC 2 is an AICPA attestation report on controls. ISO is the more common ask outside North America. The control overlap is substantial, which is why doing them in parallel costs far less than doing them separately.
It records which Annex A controls apply to your ISMS and why the rest do not. Registrars read it closely - an SoA that excludes controls without a defensible reason is one of the more common Stage 1 findings.
Yes. Clause 9.2 requires it, and clause 9.3 requires a management review. Both must have happened before Stage 2. We run the internal audit as part of readiness so it is genuine rather than retrospective.
Most of it. Access control, change management, incident response, supplier management and logging map closely. We map your existing controls to Annex A first, so the work is the gap rather than the whole standard.
Rarely run alone
Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.
ISO 27001 readiness, on your timeline
A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.