ISO 27001 readiness and internal audit
ISMS build, Annex A controls, internal audit, Stage 1 and 2. We build the ISMS, run the Clause 9.2 internal audit, assemble the evidence and do the testing that backs it, so that by the time the certification body arrives the work is already done and already documented.
What ISO 27001 actually asks for
ISO/IEC 27001:2022 asks for a management system, not a checklist. Clauses 4 to 10 cover scope, leadership, risk assessment and treatment, competence, internal audit, management review and continual improvement. Annex A lists 93 controls in four themes: organisational, people, physical and technological. You select controls by risk and justify the ones you leave out in a Statement of Applicability. Certification runs on a three-year cycle with surveillance audits in between.
Our part
The ISMS a certification body expects to find: scope definition, risk assessment and treatment plan, the Statement of Applicability, the policy set, and the records that show the system is running rather than written. Clause 9.2 requires an internal audit, and that is work we perform and document. Where an Annex A control under the technological theme needs technical proof, the penetration test supplies it.
Where the work needs a penetration test, it is the plan you already see on the pricing page: Startup at INR 74,999 for one scope, Growth at INR 1,79,999 for two. Growth is the plan that carries the SOC 2 and ISO 27001 control mapping in the report. The sample report shows the format an auditor will be handed.
What we hand over, and who signs it off
What we hand the certification body is an ISMS that is already running: scope, risk assessment and treatment, the Statement of Applicability, the policy set, and the Clause 9.2 internal audit with its records. The certificate itself is issued by that accredited body after its own Stage 1 and Stage 2 audits, and the ISO 27001 Lead Auditor qualification on our team is what lets us run your internal audit and walk you into theirs prepared.
Where a penetration test fits, and where it does not
Annex A 8.8 covers management of technical vulnerabilities and 8.29 covers security testing in development and acceptance. Those are the controls a pentest report evidences most directly. The majority of the 93 controls are governance and will never be settled by a test, which is why testing alone has never produced a certificate.
If you are still deciding which one first
ISO 27001 questions we are asked
Does ISO 27001 require a penetration test?
Not by name, but two Annex A controls are what a pentest report evidences most directly: 8.8 covers management of technical vulnerabilities and 8.29 covers security testing in development and acceptance. The majority of the 93 controls are governance and will never be settled by a test, which is why testing alone has never produced a certificate.
What are the Stage 1 and Stage 2 audits?
Stage 1 is a documentation review: the certification body reads your ISMS documentation, policies, risk assessment, Statement of Applicability and internal audit results to confirm the system exists and is ready to be tested. Stage 2 is the evidence audit, on site or remote, where they verify the controls are actually operating. Both are performed by the accredited certification body, not by us.
What is a Statement of Applicability?
The document where you record which of the 93 Annex A controls apply to you, and justify the ones you have left out. Controls are selected by risk rather than adopted wholesale, so the Statement of Applicability is where a certification body sees whether your risk assessment actually drove your control set or was written to match it afterwards.
Can Cybersecify certify us to ISO 27001?
No. The certificate is issued by an accredited certification body after its own Stage 1 and Stage 2 audits, and that body must be independent of whoever helped you prepare. The ISO 27001 Lead Auditor qualification on our team is competence to run your Clause 9.2 internal audit and walk you into theirs prepared; it is not accreditation to certify anyone.
What we have written about ISO 27001
Tell us what the deadline is
An auditor booked, a customer security review, an investor asking, or a renewal due. The date changes the scope and the order of the work, so it is the first thing we ask. Both co-founders are on the call.
Where these requirements come from
Everything this page says about the standards body or regulator's requirements is taken from their own published documentation, linked below and last checked on 2026-10-06. We quote the requirement rather than our reading of it wherever the difference matters.
- ISO/IEC 27001:2022, Information security management systems
- ISO/IEC 27002:2022, Information security controls
Checked 2026-10-06. iso.org returns 403 to automated requests, so the two ISO catalogue entries were confirmed as the correct canonical URLs rather than re-read on that date.
Our aim is to describe these requirements as accurately and as currently as we can, and to show you where to check us. We are reading someone else's documentation: a standards body or a regulator can revise it without an announcement, and our reading of it can be imprecise or go out of date.
How we source, draft and review what we publish, including where software sits in the drafting, is set out in our editorial policy. A page like this is only as good as the date on it, so we re-read the sources on a standing audit, date what we checked, and update the page when a source moves or when we can state something more precisely.
If something here no longer matches the source, tell us at errors@cybersecify.com. We will review it against the source and tell you what we decide; where it needs changing we change it and date the change.
This page is published for information. It is a best-effort account of someone else's published requirements, not a commitment about your engagement: what we deliver, and what it costs, is set out in the Statement of Work both parties sign, and our terms state that where website content and a signed agreement differ, the signed agreement governs.