Certifying everything is expensive and certifying too little is worthless. The scope is argued out at the start.
Policies, statements of applicability and risk treatment written to be defended, not to fill a folder.
Internal audit, then Stage 1 and Stage 2 with the certification body, with us in the room.
Where you stand against the standard, and what the gap costs to close.
The management system, the documents and the controls that the scope demands.
Internal audit, then Stage 1 and Stage 2 with the certification body.
The scope, the risk treatment, the Statement of Applicability and the policies, with the evidence that shows they operate. We run the internal audit, prepare the management review, and answer the certification body’s findings with you. What you keep afterwards is a system that runs, not a folder that was assembled for one week in the year.
A gap analysis usually finds more in place than people expect.