§ CAPABILITY

ISO 27001 Readiness and ISMS Implementation

The management system European procurement asks for. Scope, risk assessment, the Statement of Applicability, and the operating evidence a certification body will want to see running.

Who
Founder holds the engineering leadership seat; the delivery team executes underneath it.

What you're seeing

A European enterprise buyer asked for ISO 27001 and you have SOC 2.
Usually means The frameworks are not interchangeable in procurement even where the controls overlap. The second certification is much cheaper than the first, but it is a separate audit against a separate standard.
The risk register was written in one sitting, last year.
Usually means Risk assessment is being treated as a document rather than as a repeatable process. The standard is a management system — the spine of it is the process running, not the artefact existing.
Nobody can say what is in scope.
Usually means The scope statement is vague or absent, which means the cost is unbounded and the certificate may not cover what a buyer is buying. This is the most expensive mistake available here and it is made at the very start.
Internal audit and management review are on the plan for the month before certification.
Usually means They are being treated as deliverables to produce rather than cycles to have run. A certification body asks to see the system operating, and a single retrospective cycle is visible as one.

Scope is the expensive decision

Everything downstream is priced by it, and it is decided at the beginning when the least is known.

Too wide, and the assessment covers systems no customer asked about — the internal tooling, the marketing stack, the office. Every one of those brings controls, evidence and audit time, at full cost, for no commercial return.

Too narrow, and procurement reads the certificate, notices that the scope statement does not include the product they are buying, and treats it as absent. That is the worse error, because it is discovered after the money is spent.

The scope statement names systems, locations and people, and it is written to be read by a buyer rather than only by an assessor. Getting it right is worth the slow conversation it requires.

A management system, not a folder

The standard is about a process that runs. This is the part that consistently surprises teams arriving from a SOC 2 background.

The risk assessment is the spine. Not the register — the method: how risks are identified, how they are evaluated, who owns each one, what treatment was decided and when it will be reviewed. An assessor reads the register and immediately asks how it was produced. A register written in one sitting last year answers that question badly, and it is a question with a very recognisable wrong answer.

The Statement of Applicability is where this becomes concrete. Every Annex A control, a decision on applicability, a justification, and a pointer to what actually implements it. Filling it honestly is the exercise that reveals which controls exist and which are aspirations.

It has to have been running

Internal audit and management review are cycles, not deliverables.

Booking both for the month before the Stage 2 assessment produces documents that look correct and read as retrospective, because they are. More importantly it wastes their actual function: an internal audit is where you find your own nonconformities, at no cost and with no deadline. Finding them in the certification audit instead means finding them in front of an assessor, with a corrective action plan and a date.

This is why the timeline is six to twelve months rather than weeks. The documentation is not the constraint.

Where it sits

This is a capability under SOC 2 Readiness, which carries the compliance work as a whole — the page is named for the framework most buyers ask for first, and the underlying control environment serves both.

It is built on the same evidence pipeline as Compliance Automation, which is what makes the second framework cheap rather than a repeat of the first, and it depends on Vendor Risk Management for the supplier controls in Annex A, which are the ones most often left until an assessor asks.

How the work runs

  1. Set the scope

    Which systems, which locations, which people. Scope decided carelessly is the most expensive mistake available here — too wide and the cost multiplies, too narrow and buyers reject the certificate.

  2. Run the risk assessment

    A repeatable method, applied, with owners and treatment decisions recorded. This is the spine of the standard and the part most often written retrospectively.

  3. Produce the Statement of Applicability

    Every Annex A control with an applicability decision and a justification, mapped to what actually implements it.

  4. Operate before certifying

    Internal audit and management review performed, not merely documented. A certification body asks to see the system running.

What arrives

  • A defined ISMS scope with the reasoning recorded
  • A risk register with owners and treatment decisions
  • A Statement of Applicability mapped to real implementations
  • Internal audit and management review records from actual cycles

What it costs your team

Roughly a day a month from leadership once running, more during scoping and internal audit.

How we decide

  • Scope is settled first, deliberately, in writing

    Costs It is a slow conversation involving people outside engineering, at the point where everyone wants to start on controls.

    Everything downstream is priced by scope. Too wide and the assessment covers systems no customer cares about, at full cost. Too narrow and procurement rejects the certificate as not covering the product they are buying — which is the same outcome as not having one, after paying for it. Neither error is cheap to correct once an audit is booked.

  • The risk assessment is a method that runs, not a document that exists

    Costs It commits leadership to a recurring cycle rather than a one-off exercise.

    The standard is about a management system. An assessor reads the register and then asks how it was produced, who owns each item, what was decided and when it was reviewed. A register written retrospectively answers the first question and none of the others, and the gap is obvious to anyone who has read a few.

  • Internal audit and management review happen before certification, for real

    Costs It extends the timeline by months that produce no external artefact.

    These two cycles are what distinguish an operating management system from a set of documents describing one. They are also where the system's own defects surface, which is the point — finding them in your own internal audit is free, and finding them in the Stage 2 assessment is a nonconformity with a deadline attached.

Frequently Asked Questions

An international standard for an information security management system: a documented, operating process for identifying risk and applying controls, assessed by an accredited certification body. The certificate covers the management system rather than a product, and it is issued on a three-year cycle with surveillance audits in between.
ISO 27001 for European and international procurement, SOC 2 for North American. The underlying controls overlap substantially, so whichever comes second is considerably cheaper. Which comes first is decided by which deals are waiting, not by which standard is stronger.
Usually six to twelve months, and the constraint is not documentation. The standard requires evidence that the system has been operating — risk assessments performed, internal audits conducted, management reviews held. Documents can be produced in weeks; operating history cannot be compressed.
A document listing every Annex A control with a decision on whether it applies, a justification for that decision, and a reference to what implements it. It is the artefact an assessor works from, and it is where a management system that exists only on paper becomes visible — because each entry has to point at something real.
Not necessarily, but the roles have to be named and someone has to be accountable. Where that is a part-time or fractional arrangement, the documentation should say so plainly rather than implying a department that does not exist. Assessors are unimpressed by org charts and interested in whether the named person can describe what they do.

Sources

Page reviewed