Fortinetics Book a call →
Menu
05 — ISO 27001

ISO 27001:2022 — a working ISMS, not a binder.

For organizations with global operations or enterprise customers that specifically require ISO 27001. The management-system framework that pairs cleanly with SOC 2. It also carries into FedRAMP, but only the governance half: our overlap tool scores ISO 27001 against FedRAMP Moderate at about 40 percent, because the federal control architecture is new work either way.

You might be here because
  • A European or enterprise customer requires ISO 27001 specifically; SOC 2 will not substitute.
  • You need a management system your team can actually operate after we leave.
  • You are running SOC 2 and ISO in parallel and duplicating the same evidence twice.
  • A previous attempt produced documentation nobody uses and an auditor saw through it.

Global ISMS Certification

ISO 27001 certification requires an operational ISMS: risk assessment methodology, Statement of Applicability, Annex A control selection, internal audit program, management review cadence, and a continuous improvement loop. It is not a point-in-time checklist; it is a management system, and certification bodies can tell the difference immediately.

We design the ISMS, select Annex A controls based on your actual risk posture, produce the required documentation, train your team to operate it, support internal audits, and manage the Stage 1 and Stage 2 audits with an accredited certification body.

Where relevant we extend into ISO 27017 (cloud-specific controls) and ISO 27018 (personal data in cloud). Clients running multi-framework programs often find ISO 27001 provides the management-system backbone that SOC 2 artifacts plug into directly. FedRAMP inherits the governance layer from that backbone — the policy patterns, the risk methodology, the operational cadences — but the NIST 800-53 baseline, the SSP format, and the 3PAO pathway are separate work, and we scope them as such.

What we actually deliver
  • ISMS design: scope, risk methodology, risk register, and treatment plan
  • Statement of Applicability with justified Annex A control selection
  • Full documentation set and team training on operating the system
  • Internal audit program and management review cadence
  • Stage 1 and Stage 2 certification audit management
  • ISO 27017 / 27018 extensions and SOC 2 control mapping where in scope
We have done this before

All engagements are anonymized. We do not publish client names.

Next step

Start with a scoping conversation.

No obligation and no pitch deck. We will tell you what the engagement actually involves, what it depends on, and whether we are the right firm for it — including when we are not.

Other services