{ "@context": "https://schema.org", "@graph": [ { "@type": "Service", "name": "ISO 27001 Risk Assessment & ISMS Readiness", "serviceType": "Penetration Testing", "provider": { "@type": "Organization", "name": "Affordable Pentesting", "url": "https://affordablepentesting.com" }, "areaServed": "US", "url": "https://affordablepentesting.com/compliance/iso-27001" }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://affordablepentesting.com/" }, { "@type": "ListItem", "position": 2, "name": "ISO 27001 Risk Assessment & ISMS Readiness", "item": "https://affordablepentesting.com/compliance/iso-27001" } ] } ] }
Gap analysis against Trust Services Criteria before your auditor finds the gaps. Audit-ready evidence packages delivered fast, priced for real budgets.
Our assessors hold the certifications your auditors and assessors recognize — OSCP, CEH, and CREST. No junior analysts running checklists.
You get a fixed price before we start. No hourly billing, no scope creep surprises, no invoice that looks nothing like the quote.
Most assessments are delivered in five to ten business days from kickoff. Built for real audit deadlines, not enterprise consulting timelines.
Reports are structured so your auditor, QSA, C3PAO, or certification body can evaluate evidence directly. No translation layer required.
ISO/IEC 27001 is the international standard for an Information Security Management System. Certification means an accredited certification body has examined your ISMS and confirmed it meets the standard. It is not a report on your controls the way SOC 2 is — it is a pass or fail certificate covering your management system as a whole.
That distinction shapes everything about how you prepare. Auditors are not only asking whether a control exists. They are asking whether your organization has a working system for identifying risk, deciding what to do about it, implementing that decision, and reviewing whether it worked. A strong control set with no management system behind it still fails.
ISO 27002 is the companion standard people frequently confuse with it. 27001 states the requirements you are certified against; 27002 is implementation guidance for the Annex A controls. You certify to 27001. You use 27002 to figure out how.
The mandatory requirements live in Clauses 4 through 10: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. These are non-negotiable and they are where most first-time nonconformities are raised.
Annex A contains 93 controls across four themes — organizational, people, physical, and technological. You are not required to implement all 93. You are required to consider each one, decide whether it applies, and document that decision in your Statement of Applicability. Excluding a control is allowed. Excluding it without a justification your auditor accepts is not.
The 2022 revision restructured Annex A from 114 controls into 93 and introduced eleven new ones, including threat intelligence, data masking, data leakage prevention, and web filtering. Organizations that transitioned from the 2013 version without revisiting their SoA routinely carry gaps against those new controls.
Clause 6.1.2 requires a defined, repeatable information security risk assessment process — not a one-time spreadsheet. You need documented risk criteria, a consistent method for identifying and analyzing risk, and results that can be reproduced. Your risk treatment plan and your Statement of Applicability both trace back to it.
This is the first artifact most certification body auditors ask for, and a weak one undermines everything downstream. If your SoA justifications do not map cleanly to identified risks, the auditor has found a systemic problem rather than an isolated gap.
Stage 1 is a documentation and readiness review. The auditor confirms your ISMS is defined, your mandatory documentation exists, and you are ready to be audited. Findings here are usually about completeness.
Stage 2 is the full certification audit. The auditor tests whether your controls actually operate, interviews your people, and samples evidence. Major nonconformities at Stage 2 must be closed before a certificate is issued. After certification, surveillance audits follow annually, with a full recertification at the three-year mark.
Our walkthrough of the ISO 27001 certification process covers what happens in each stage and how to prepare for the interviews.
From initial gap assessment to Stage 2, most organizations need six to eighteen months. The floor is set by something you cannot compress: auditors need to see your ISMS operating, which means internal audits, a management review, and a period of running records. Even a well-prepared organization rarely certifies in under six months.
Starting maturity is the main variable. A company with existing SOC 2 controls and documented processes moves considerably faster than one starting from a blank page. Our ISO 27001 certification timeline breaks the path into phases so you can plan against a real calendar.
Costs split into three buckets: implementation work to close gaps, tooling and control costs, and the certification body's audit fees. Consultancies commonly quote five and six figures for the implementation piece alone, and certification body fees scale with headcount and scope.
The bucket teams underestimate is internal time. Building an ISMS is organizational work, not a document you buy. Our ISO 27001 cost guide breaks down each line item, including what you can reasonably do in-house.
ISO 27001 certification is achievable without a six-figure consulting engagement. Get your ISO 27001 technical risk assessment quote and find out exactly what stands between you and certification.
Tell us your framework, environment size, and audit deadline. Takes two minutes. No account required, no sales call triggered.
We review your submission and send a fixed-price quote with scope, timeline, and what you’ll receive — usually within one business day.
Once you approve, we kick off immediately. Gap report, remediation roadmap, and evidence package delivered in 5 to 10 business days.
No sales calls. Same-day response.
From initial gap assessment to Stage 2 certification, most organizations need six to eighteen months depending on starting maturity and scope. Our assessment tells you where you actually are on that timeline so you can plan realistically rather than optimistically.
The standard does not mandate a penetration test by name. Annex A.8.8 (management of technical vulnerabilities) and A.8.29 (security testing in development and acceptance) create practical requirements for active security testing, and certification bodies treat pentest evidence as the strongest available demonstration that those controls operate effectively.
ISO 27001 contains the requirements you are audited and certified against. ISO 27002 is guidance on how to implement the Annex A controls. You cannot be certified to 27002 — it is a reference document, not a certifiable standard.
No. You must consider each one and document in your Statement of Applicability whether it applies, with justification. Exclusions are legitimate when your risk assessment supports them. Unjustified exclusions are a common source of nonconformities.
Substantially, yes. The control overlap is significant, particularly around access management, change management, and vendor risk. What SOC 2 does not give you is the management system layer — the risk assessment method, Statement of Applicability, internal audit programme, and management review that ISO requires.