Security & Compliance

ISO 27001 implementation

The information-security certification European RFPs treat as table stakes.

Typical duration
12–16 weeks
Scope
Fixed and written before you sign
Team
Principal plus 1–2 specialists

Who it is for

Anyone selling into the EU or to enterprise.

Everything below is in the scope document, written and priced before anything starts. If something you need is not on this list, say so and it goes in the quote — or we tell you it does not belong in this engagement.

  • Scope definition — the decision that most affects cost and nobody thinks about
  • Risk assessment and treatment plan, plus the full policy set
  • Control implementation with evidence collection designed in from the start
  • Internal audit and management review run before the certification body arrives
  • Support through Stage 1 and Stage 2 audits

How every Security & Compliance engagement runs →

Next step

Thirty minutes on whether this is the right engagement.

If a different service on this list fits better, or if you do not need us at all, that is what the call will conclude.