ISO/IEC 27001
It is the international standard that shows up most often in tenders, contracts and vendor questionnaires, and the only one on this list that certifies how a company manages risk rather than a technology. DM11 runs the work from scope to audit, with a senior specialist leading and your team learning to operate what remains.
DM11 prepares your company and runs the implementation. The audit and the certificate come from an accredited certification body that you contract. That separation is not our choice: whoever prepares cannot certify, and it works that way in any serious scheme.
Who runs the implementation
ISO/IEC 27001 Lead Auditor certified by BSI
ISO/IEC 27002 Foundation
17 years of governance, risk and compliance
Experience with bank and Big Four audits
WHAT IT ACTUALLY IS
ISO/IEC 27001 sets the requirements for an information security management system. It lists no tool and demands no vendor: it demands that the company know its risks, decide what to do about each one, carry out what it decided and prove that over time. This is why it fits a thirty-person fintech and a three-thousand-person manufacturer alike, and why the certificate travels across industries.
Unlike TISAX and TPN, here there is a real certificate, issued by an accredited body. It is valid for three years, with surveillance audits in between. Missing a surveillance audit costs you the certificate, so the standard rewards routine rather than a concentrated push.
The 2022 revision reorganised Annex A from 114 controls to 93, grouped into four themes instead of fourteen sections. Anyone certified under the 2013 version has already had to migrate. A proposal still talking about 114 controls is out of date.
The standard lets you define what is included: one site, one product, the whole company. Too broad and you multiply evidence, time and cost; too narrow and your customer asks why their area was left out. That conversation is the first thing we have, before any project starts.
The 93 controls are a reference, not a block obligation. The Statement of Applicability is where the company records what applies, what does not and why. A well-written exclusion carries more weight in an audit than a control implemented with no purpose.
WHEN THE DEMAND ARRIVES
In seventeen years almost every project started down one of these three roads. Recognising yours sets the scope and the timeline with the right frame.
A clause asks for the certification, or the customer's security questionnaire came back rejected. Here the deadline is theirs, not yours, and the conversation starts with what can be shown next week while the programme runs.
Tenders and RFPs list 27001 as a qualifying requirement. Without it the proposal is not even read. The scope here has to cover exactly what the tender names and nothing beyond it, so you do not pay for certification nobody asked for.
A funding round, entry into a regulated market, or an incident that gave everyone a fright. On this road the deadline is yours, and it is the cheapest scenario: the work can be done in the right order instead of the urgent one.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern repeats. Where a client agrees, we give named references in a conversation.
Technology, software as a service
A large customer made renewal conditional on an ISO 27001 certificate, with a twelve-month deadline. The company had good technical practice and no management system: the security decisions lived in two people's heads and in no document at all.
We started with scope, limited to the platform that customer used rather than the whole company. In the first two months we raised technical hygiene in parallel: MFA on every critical access and a backup policy, things that improve the posture before any paperwork. Risk analysis, the Statement of Applicability and evidence collection followed.
Certified within the contract deadline. What the board did not expect was the side effect: months later the same evidence set answered the security questionnaires of two other customers, with no new project.
Manufacturing, three sites
The company was going to certify all three plants at once, because it looked simpler and more impressive. Only one of them handled the customer information behind the requirement; the other two ran production on their own designs.
We stopped the project before it started and wrote down, with the board, what the customer was actually asking for. The scope settled on one plant and the corporate processes behind it. The other two joined the management programme without joining the certificate.
Certification took far less effort. The other two plants were folded in at the following year's surveillance audit, at their own pace, and the cost spread across two financial years instead of landing in one.
Financial services
The company had bought a pack of ready-made policies from a vendor and believed it was one step from certification. The policies were good and described nothing the company actually did. In the first rehearsal interview, nobody in operations recognised the process on paper.
We rewrote the policies from what the company actually did, keeping what already worked and fixing what could not survive a question. Then we rehearsed the audit with interviews, including the people who run the process and not only those who signed it.
The rehearsal found what the audit would find, with time to fix it. At the certification audit the gap between the written process and the practised one had already closed, which is exactly what the auditor tests.
HOW WE RUN IT
Most certification projects spend months producing documents before anything changes in the environment. Ours accelerates technical hygiene alongside the governance, so the company is safer from the second month rather than only at the twelfth. Led by an external specialist, with one focal point from your team. Each requirement is assessed on a binary scale: met, not met, partially met or not applicable, with no subjective score nobody can defend in an audit.
We define and approve the scope and boundaries of the management system (clause 4), engage top management and set up the security committee (clause 5). In parallel we map and catalogue the critical information assets and put the basic technical hygiene in place.
Scope and boundaries of the management system approved
Security committee formed, with management engaged
Inventory of critical information assets
Information security policy approved
MilestoneScope approved, policy signed off and MFA live on 100% of critical access.
We define the risk methodology and run the gap analysis against clauses 6 and 7, with identification and assessment workshops alongside the business areas. Out of that come the risk treatment plan and the first version of the Statement of Applicability.
Risk management methodology defined and approved
Gap analysis against clauses 6 and 7
Risk treatment plan
Initial Statement of Applicability
MilestoneStatement of Applicability signed and risk matrix approved by the board.
We document and apply the operational security planning (clause 8) and formalise the complementary policies. This is where the advanced controls land: business continuity, disaster recovery and the technical testing that produces evidence a control actually works.
Operational planning documented and in use
Complementary organisational policies published
Business continuity and disaster recovery plans
Vulnerability scanning and preventive testing
MilestonePolicies published, a continuity simulation run and the first scan completed.
We run the internal audit (clause 9) with a consultant independent of whoever implemented, conduct the management review and handle the findings (clause 10). We consolidate the evidence repository and stay with you through both stages of the external audit.
Internal audit run by an independent consultant
Management review, with findings addressed
Central repository of technical evidence
Support through stage 1 and stage 2 of the external audit
MilestoneCertification audit completed and the certificate issued by the accredited body.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline becomes a promise, and this is a promise that depends more on you than on us. Our clients have certified at nine, at twelve and at eighteen months. What separated them is below, and the first conversation is already enough to estimate honestly.
One site and one product move far faster than the whole company. It is the variable with the largest effect on the timeline, and the only one you can settle at the very start.
A company with an asset inventory, tested backups and access control already in order effectively begins at phase two. A company without them spends the first two months building the base.
This is the variable that surprises people most. A committee that meets and decides takes months off; a committee that exists on paper stretches the project without anyone being able to point at where. The standard demands management participation for exactly this reason.
THE ROLES ARE KEPT APART
The separation shows up twice on this journey, and both times it protects you. At the external audit, the certificate comes from an accredited body you contract, never from DM11. At the internal audit required by clause 9, whoever runs it must be independent of whoever implemented: where DM11 did the implementation, the internal audit is run by a consultant who took no part in it.
DM11 prepares, implements and supports. It does not audit to certify and issues no certificate
You contract the certification body, and the choice is yours
The clause 9 internal audit is carried out by someone who did not implement
We help you compare accredited bodies, with no interest of our own in the answer
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
No, and nobody who implements is allowed to. The certificate is issued by an accredited certification body that you contract. DM11 prepares the company, implements the management system alongside your team and supports you through both stages of the external audit. That separation is a rule of the accreditation scheme rather than a choice of ours, and it is what gives the certificate its worth.
With the contract clause or the questionnaire in hand, we set the right scope, what you already have that counts toward it, and a timeline estimate that holds.
Comparisons on this subject
See all 13 comparisons