ISO/IEC 27001 certification support
We get you to certification. We don’t sell it. Sentrix structures your ISO 27001 journey — from gap analysis to the certification body’s audits — while preserving the independence of the verification.
What is ISO 27001 certification?
ISO/IEC 27001 is an international standard that specifies the requirements for an Information Security Management System (ISMS). Its purpose: to preserve the confidentiality, integrity, and availability of your data, through controls spanning people, processes, and technology.
Getting certified is not about writing documents to check boxes. It means building a living management system that combines three dimensions: organizational governance, technical cybersecurity, and regulatory compliance. Certification is issued by an accredited third-party certification body (BSI, DNV, Bureau Veritas, SGS, Intertek, among others), following an independent audit — never by the firm that prepared you.
The current version, ISO/IEC 27001:2022, restructured Annex A, which now has 93 controls grouped into four themes (organizational, people, physical, technological).
93 controls
In Annex A of the 2022 version.
4 themes
Organizational, people, physical, technological.
A living ISMS
Not a stack of documents.
Third-party certification
By an accredited body, independent of the preparation work.
3-year cycle
With annual surveillance audits.
Preparing without certifying: our independence commitment
The rule is simple, and it protects the value of your certification: whoever supports you must not be the one who certifies you. We structure your process, build your ISMS, and prepare you for the audits — but the certification body remains an accredited third party, chosen by you. We can present you several options, with no commercial ties to any of them. That is what guarantees a certificate that actually holds up with your clients and partners.
Who this support is for
SMEs and technology services companies that need to demonstrate their information security maturity to access new markets.
SaaS vendors, cloud providers, and integrators receiving a growing number of client security questionnaires who want to answer them with a recognized framework rather than case by case.
Organizations that have lost — or risk losing — a tender for lack of certification, and want to structure the process once and for all.
Growing companies that need to demonstrate their cyber maturity to investors, a potential acquirer, or a foreign parent company.
Organizations already compliant with other frameworks (SOC 2, Law 25, NIST CSF) that want to capitalize on the work already done to reach ISO 27001 without starting from zero.
Is this the right time for you?
If you recognize your situation in any of the following, this support is designed for you.
- A strategic client, a tender, or an international partner requires ISO 27001 — with a firm deadline.
- You have read the standard, downloaded templates, and started drafting policies, and you are realizing the gap between theory and implementation is bigger than expected.
- You already attempted an internal effort that ran out of steam for lack of time, method, or a clear project owner.
- Your IT provider or MSP is offering to "handle ISO 27001," and you want to keep the verification independent from the implementation.
- You are already compliant with Law 25 or another framework, and want to know what actually remains to be done for ISO 27001 — without redoing all the work.
- You want a realistic estimate of the effort, cost, and timeline before committing — not a "six months" promise pulled from a brochure.
- You are starting on the 2022 version of the standard and want to account, from day one, for the new controls and the restructured Annex A.
What you get
Gap analysis
A full comparison between your current posture and ISO 27001:2022 requirements, with an action plan prioritized by risk level and a realistic estimate of the road ahead.
Defined certification scope
The delineation of the entities, services, and sites covered — a strategic choice that directly affects cost, timeline, and the certification’s value with your clients.
Documented, right-sized ISMS
An Information Security Management System sized for your organization, structured around your operational reality — not a 500-page ISMS that ends up in a drawer.
Statement of Applicability (SoA)
The document justifying the inclusion or exclusion of each of the 93 Annex A controls, with the associated risk assessment and treatment plan.
Policies and procedures
The mandatory policies, procedures, and records drafted, reviewed with your teams, and adapted to your reality — with one guiding principle: every document must be usable, not just compliant.
Internal audit and management review
The formal internal audit required by the standard, conducted with an independent external perspective, plus the documented management review — two prerequisites for certification, run upfront to maximize your chances on the first pass.
Auditor-ready evidence file
An organized file, ready to present on the day, so you are not searching for documents in front of the certification auditor.
Post-certification maintenance plan
A clear cadence (annual internal audit, management review, tracking standard updates) to keep your certification through surveillance audits and renewal.
Our approach, step by step
A rigorous, transparent approach that turns a complex project into a managed, controlled process.
1. Gap analysis
2. Scope and ISMS
3. Controls and documentation
4. Internal audit and management review
5. Certification audit support
6. Post-certification maintenance
Why aim for ISO 27001 certification
Beyond the certificate, a well-run ISO 27001 process transforms your organization for the long term.
- Commercial credibility — respond to tenders and client security questionnaires with an internationally recognized framework, instead of case by case.
- Competitive advantage — stand out in sectors where certification has become a prerequisite, and reassure investors, acquirers, and parent companies.
- Tangible risk reduction — structure your security processes and reduce your exposure, both technically and on the regulatory side.
- Better organization — clarify roles, responsibilities, and processes, without unnecessary weight or bureaucracy.
- Continuous improvement — build a lasting dynamic rather than a one-off effort that runs out of steam.
A successful certification is not just about the certificate
Getting the certificate is not enough. A truly successful certification is measured on several levels: certification with no major nonconformity at the initial audit, a sign of a well-scoped project; an ISMS that is easy to maintain over time and sustainable through annual surveillance audits; positive team engagement, with people who understand their role; processes that are structured without unnecessary bureaucracy; and a tangible reduction in risk. That is the lasting success we aim for — not just the formal issuance of the certificate.
Why trust Sentrix with your ISO 27001 journey
Independence preserved
We prepare — we do not certify. The choice of certification body remains yours, and we have no commercial ties to them — which protects the value of your certificate.
Multidisciplinary expertise
A team that covers governance, technical cybersecurity, and regulatory compliance, backed by the ISO 27001:2022, ISO 27002:2022, and NIST CSF frameworks.
Operational support, not just standards knowledge
We act as project managers — a structured plan, clear milestones, follow-through — and adapt the requirements to the reality of your internal processes, without burying you in theory.
A maintainable ISMS
We build a structured, realistic, and scalable system, able to stay compliant over time, rather than documentation that will not survive the first surveillance audit.
Frequently asked questions
Do you issue the certification?
How long does it take?
What changed between ISO 27001:2013 and ISO 27001:2022?
We are already compliant with Law 25 or SOC 2. Does that speed up ISO 27001?
Can we narrow the scope to certify faster?
What happens if we fail the certification audit?
Can our MSP lead our ISO 27001 certification?
Is this confidential?
Let’s talk about your ISO 27001 journey.
Whether you are under a firm client deadline, still weighing your options, or want to check your readiness — let’s talk. A first conversation helps scope the perimeter and estimate an achievable effort and timeline. No commitment.