# ISO 27001 certification

> You meet the auditor fully prepared, with a management system worth keeping.

ISO 27001 readiness is the clear path to certification — we build the documents and take the audits with you.

**Key points**

- Gap analysis and a scope that fits the business
- Policies and evidence that survive an auditor
- Stage 1 and Stage 2 taken with you

## Three things decide whether certification hurts

### Scope that fits the business

Certifying everything is expensive and certifying too little is worthless. The scope is argued out at the start.

### Documentation that survives an auditor

Policies, statements of applicability and risk treatment written to be defended, not to fill a folder.

### The audits themselves

Internal audit, then Stage 1 and Stage 2 with the certification body, with us in the room.

## What we produce, and what the auditor asks for

- **Scope statement** — What is certified and what is deliberately outside it, with the boundary defensible rather than convenient — this is the document that decides the cost of everything after it.
- **Risk assessment and treatment plan** — The risks the business actually carries, assessed on a method an auditor will accept, each one accepted, treated or transferred by somebody with the authority to decide.
- **Statement of Applicability** — All ninety-three Annex A controls, each applied or excluded with a reason that holds up when it is challenged rather than a tick in a column.
- **Policies people follow** — Short enough to be read and specific enough to settle an argument. A policy nobody follows is a finding, not a control.
- **Evidence of operation** — Records showing the controls ran — reviews held, access removed, backups tested. Stage 2 tests whether the system operates, not whether it exists.
- **Internal audit and management review** — Both are mandatory clauses and both are where unprepared organisations fail. We run the internal audit and prepare the review your leadership has to hold.
- **Stage 1 and Stage 2** — The certification body reads the system, then tests it. We are in the room for both, and we answer the findings with you rather than forwarding them.

## How it runs

1. **Assess** — Where you stand against the standard, and what the gap costs to close.
2. **Build** — The management system, the documents and the controls that the scope demands.
3. **Certify** — Internal audit, then Stage 1 and Stage 2 with the certification body.

## What you get

**A certifiable management system, and us in the room when it is audited** — The scope, the risk treatment, the Statement of Applicability and the policies, with the evidence that shows they operate. We run the internal audit, prepare the management review, and answer the certification body’s findings with you. What you keep afterwards is a system that runs, not a folder that was assembled for one week in the year.

---

Canonical: https://centio.bg/uslugi/iso-27001