Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. ISO/IEC 27001
  3. ISO/IEC 27001 implementation

ISO/IEC 27001

The certification your customer accepts without argument

It is the international standard that shows up most often in tenders, contracts and vendor questionnaires, and the only one on this list that certifies how a company manages risk rather than a technology. DM11 runs the work from scope to audit, with a senior specialist leading and your team learning to operate what remains.

Talk to a specialistSee the other standards

DM11 prepares your company and runs the implementation. The audit and the certificate come from an accredited certification body that you contract. That separation is not our choice: whoever prepares cannot certify, and it works that way in any serious scheme.

Who runs the implementation

  • ISO/IEC 27001 Lead Auditor certified by BSI

  • ISO/IEC 27002 Foundation

  • 17 years of governance, risk and compliance

  • Experience with bank and Big Four audits

WHAT IT ACTUALLY IS

It certifies how you manage risk, not what you bought

ISO/IEC 27001 sets the requirements for an information security management system. It lists no tool and demands no vendor: it demands that the company know its risks, decide what to do about each one, carry out what it decided and prove that over time. This is why it fits a thirty-person fintech and a three-thousand-person manufacturer alike, and why the certificate travels across industries.

A certificate does exist, and it lasts three years

Unlike TISAX and TPN, here there is a real certificate, issued by an accredited body. It is valid for three years, with surveillance audits in between. Missing a surveillance audit costs you the certificate, so the standard rewards routine rather than a concentrated push.

The current version is the 2022 one

The 2022 revision reorganised Annex A from 114 controls to 93, grouped into four themes instead of fourteen sections. Anyone certified under the 2013 version has already had to migrate. A proposal still talking about 114 controls is out of date.

Scope is your decision, and the most expensive one

The standard lets you define what is included: one site, one product, the whole company. Too broad and you multiply evidence, time and cost; too narrow and your customer asks why their area was left out. That conversation is the first thing we have, before any project starts.

Annex A is not a shopping list

The 93 controls are a reference, not a block obligation. The Statement of Applicability is where the company records what applies, what does not and why. A well-written exclusion carries more weight in an audit than a control implemented with no purpose.

WHEN THE DEMAND ARRIVES

Nobody goes looking for ISO 27001 on their own

In seventeen years almost every project started down one of these three roads. Recognising yours sets the scope and the timeline with the right frame.

A contract stalled

A clause asks for the certification, or the customer's security questionnaire came back rejected. Here the deadline is theirs, not yours, and the conversation starts with what can be shown next week while the programme runs.

A tender requires it

Tenders and RFPs list 27001 as a qualifying requirement. Without it the proposal is not even read. The scope here has to cover exactly what the tender names and nothing beyond it, so you do not pay for certification nobody asked for.

The company grew and got exposed

A funding round, entry into a regulated market, or an incident that gave everyone a fright. On this road the deadline is yours, and it is the cheapest scenario: the work can be done in the right order instead of the urgent one.

STORIES

Three situations we have already solved

We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern repeats. Where a client agrees, we give named references in a conversation.

Technology, software as a service

The contract that hinged on a certificate that did not exist

Situation

A large customer made renewal conditional on an ISO 27001 certificate, with a twelve-month deadline. The company had good technical practice and no management system: the security decisions lived in two people's heads and in no document at all.

What we did

We started with scope, limited to the platform that customer used rather than the whole company. In the first two months we raised technical hygiene in parallel: MFA on every critical access and a backup policy, things that improve the posture before any paperwork. Risk analysis, the Statement of Applicability and evidence collection followed.

Result

Certified within the contract deadline. What the board did not expect was the side effect: months later the same evidence set answered the security questionnaires of two other customers, with no new project.

Manufacturing, three sites

The scope that nearly cost double

Situation

The company was going to certify all three plants at once, because it looked simpler and more impressive. Only one of them handled the customer information behind the requirement; the other two ran production on their own designs.

What we did

We stopped the project before it started and wrote down, with the board, what the customer was actually asking for. The scope settled on one plant and the corporate processes behind it. The other two joined the management programme without joining the certificate.

Result

Certification took far less effort. The other two plants were folded in at the following year's surveillance audit, at their own pace, and the cost spread across two financial years instead of landing in one.

Financial services

They had the paperwork and not the practice

Situation

The company had bought a pack of ready-made policies from a vendor and believed it was one step from certification. The policies were good and described nothing the company actually did. In the first rehearsal interview, nobody in operations recognised the process on paper.

What we did

We rewrote the policies from what the company actually did, keeping what already worked and fixing what could not survive a question. Then we rehearsed the audit with interviews, including the people who run the process and not only those who signed it.

Result

The rehearsal found what the audit would find, with time to fix it. At the certification audit the gap between the written process and the practised one had already closed, which is exactly what the auditor tests.

HOW WE RUN IT

A hybrid method: security improves before the certificate arrives

Most certification projects spend months producing documents before anything changes in the environment. Ours accelerates technical hygiene alongside the governance, so the company is safer from the second month rather than only at the twelfth. Led by an external specialist, with one focal point from your team. Each requirement is assessed on a binary scale: met, not met, partially met or not applicable, with no subjective score nobody can defend in an audit.

  1. 01

    Management system foundation and technical hygiene

    We define and approve the scope and boundaries of the management system (clause 4), engage top management and set up the security committee (clause 5). In parallel we map and catalogue the critical information assets and put the basic technical hygiene in place.

    • Scope and boundaries of the management system approved

    • Security committee formed, with management engaged

    • Inventory of critical information assets

    • Information security policy approved

    MilestoneScope approved, policy signed off and MFA live on 100% of critical access.

  2. 02

    Risk assessment and organisational gap analysis

    We define the risk methodology and run the gap analysis against clauses 6 and 7, with identification and assessment workshops alongside the business areas. Out of that come the risk treatment plan and the first version of the Statement of Applicability.

    • Risk management methodology defined and approved

    • Gap analysis against clauses 6 and 7

    • Risk treatment plan

    • Initial Statement of Applicability

    MilestoneStatement of Applicability signed and risk matrix approved by the board.

  3. 03

    Operation and evidence collection

    We document and apply the operational security planning (clause 8) and formalise the complementary policies. This is where the advanced controls land: business continuity, disaster recovery and the technical testing that produces evidence a control actually works.

    • Operational planning documented and in use

    • Complementary organisational policies published

    • Business continuity and disaster recovery plans

    • Vulnerability scanning and preventive testing

    MilestonePolicies published, a continuity simulation run and the first scan completed.

  4. 04

    Sustainability, audit and certification

    We run the internal audit (clause 9) with a consultant independent of whoever implemented, conduct the management review and handle the findings (clause 10). We consolidate the evidence repository and stay with you through both stages of the external audit.

    • Internal audit run by an independent consultant

    • Management review, with findings addressed

    • Central repository of technical evidence

    • Support through stage 1 and stage 2 of the external audit

    MilestoneCertification audit completed and the certificate issued by the accredited body.

HOW LONG IT TAKES

Between nine and eighteen months, and three things decide where you land

We do not publish a standard timeline, because a published timeline becomes a promise, and this is a promise that depends more on you than on us. Our clients have certified at nine, at twelve and at eighteen months. What separated them is below, and the first conversation is already enough to estimate honestly.

The size of the scope

One site and one product move far faster than the whole company. It is the variable with the largest effect on the timeline, and the only one you can settle at the very start.

The starting point

A company with an asset inventory, tested backups and access control already in order effectively begins at phase two. A company without them spends the first two months building the base.

How committed leadership is

This is the variable that surprises people most. A committee that meets and decides takes months off; a committee that exists on paper stretches the project without anyone being able to point at where. The standard demands management participation for exactly this reason.

THE ROLES ARE KEPT APART

Whoever prepares does not certify, and whoever implements does not audit from inside

The separation shows up twice on this journey, and both times it protects you. At the external audit, the certificate comes from an accredited body you contract, never from DM11. At the internal audit required by clause 9, whoever runs it must be independent of whoever implemented: where DM11 did the implementation, the internal audit is run by a consultant who took no part in it.

  • DM11 prepares, implements and supports. It does not audit to certify and issues no certificate

  • You contract the certification body, and the choice is yours

  • The clause 9 internal audit is carried out by someone who did not implement

  • We help you compare accredited bodies, with no interest of our own in the answer

FREQUENTLY ASKED

What people ask before deciding

The questions that come up in almost every first meeting, answered straight.

No, and nobody who implements is allowed to. The certificate is issued by an accredited certification body that you contract. DM11 prepares the company, implements the management system alongside your team and supports you through both stages of the external audit. That separation is a rule of the accreditation scheme rather than a choice of ours, and it is what gives the certificate its worth.

Bring us what your customer asked for, and we will tell you the real size of the job

With the contract clause or the questionnaire in hand, we set the right scope, what you already have that counts toward it, and a timeline estimate that holds.

Talk to a specialistSee the other standards

Comparisons on this subject

  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • CIS Controls vs ISO 27001
See all 13 comparisons