Your current state against ISO/IEC 27001:2022 and all 93 controls — with a realistic roadmap.
from €4,900
excl. VAT · 2–3 days
Most companies underestimate not the effort for technology, but for evidence, documentation, and management processes. In two to three days we assess your current state against ISO/IEC 27001:2022 and all 93 Annex A controls, and translate the result into a roadmap with numbers: what is missing, in what order, with how much internal and external effort, and by when.
Since 31 October 2025, certificates under ISO 27001:2013 are invalid — the transition period has expired. Those who missed it no longer need a delta audit but a full recertification with Stage 1 and Stage 2. At the same time, NIS2 makes a structured ISMS framework a de-facto necessity for tens of thousands of companies. Demand at certification bodies is rising accordingly — schedule early.
Existing policies, procedures, risk overviews, audit reports, management reviews.
Context of the organisation and interested parties · Leadership, security policy, roles · Planning, risk methodology, security objectives · Resources, competence, awareness, documented information · Operations · Performance evaluation, internal audit, management review · Improvement and nonconformity handling.
Assessment across the four theme areas — organisational, people, physical, and technological controls. Per control: maturity level, existing evidence, gap, and effort.
Definition of a defensible scope — this is where later effort is determined — plus creation of the draft SoA and calculation of the certification roadmap.
Report within ten working days, then a presentation of findings.
| Ergebnis | Form |
|---|---|
| Gap report with maturity profile per clause and per control, including evidence status | PDF, 30–50 pages |
| Statement of Applicability (draft) — all 93 controls with applicability and justification | Excel, directly reusable |
| Certification roadmap — phases, milestones, internal and external effort, budget range, realistic target date | PDF + Excel |
| Scope recommendation — with reasoning on why a narrow initial scope is often the faster path | in report |
| Guidance on selecting a certification body — what to look for, typical audit cost range | in report |
| Your control catalogue as a fillable register — importable to Jira | CSV / Jira import |
| Duration | 2 days (standard) or 3 days including scope workshop and draft SoA |
| Participants | CISO or project lead plus selected input from IT, HR, procurement, facilities |
| Format | remote or on-site |
| Price | from €4,900 excl. VAT · 3-day variant from €6,900 excl. VAT |
We typically respond within one working day.