ISO 27001 implementation: from gap analysis to certification

ISO 27001 implementation means building an Information Security Management System (ISMS) that meets ISO/IEC 27001:2022 and preparing it for an audit by an independent certification body. We run the whole process: gap analysis, documentation, security controls and internal audit. We have been certified ourselves and passed our DEKRA audit without a single major non-conformity.

Executive summary: ISO 27001 certification is increasingly a condition for entering a tender or signing a contract with a large client. A typical implementation, from gap analysis to certification audit, takes 4 to 9 months, depending on the size and maturity of the organisation. For a MedTech client, we closed 15 significant non-conformities before the external audit and cut preparation time by 3 months. The company achieved certification. We start every engagement with a gap analysis against the standard and Annex A.

Cerificate

We’ve been through this process ourselves, and we know the worst part is the picture in your head before you start.

Before we implemented ISO 27001 internally, we had the same concerns you probably do: how long will it take, how much paperwork, how will the team react. The reality turned out differently – we brought order to processes we should have had in place anyway, and we passed the DEKRA certification audit without a single major non-conformity. The methodology we apply with clients is exactly the path we walked ourselves, including the moments when we, too, felt like giving up.

Turn a compliance requirement into a competitive advantage

ISO 27001 is the world’s most widely recognised standard for information security management. Implementing it genuinely raises your security posture, and the certificate proves it to your clients and partners. As a company that has been through this process ourselves, we implement an Information Security Management System (ISMS) in your organisation and guide you step by step – from gap analysis, through documentation and security controls, all the way to the audit by an independent certification body.

Challenges

Common challenges in ISO 27001 implementation

For many companies, the road to certification looks much the same:

Externally imposed time pressure

ISO 27001 certification becomes a condition for signing a contract, entering a tender, or a requirement from a key client. The deadline is fixed, and the process has to be delivered fast and without mistakes.

Documentation that paralyses the team

The standard requires dozens of policies, procedures and records, from the Statement of Applicability to the risk register. Without experience, it is easy to get stuck producing documents that do not reflect how the company actually works, and that is exactly what the auditor checks.

No in-house expertise or capacity

Implementing an ISMS is several months of work and requires knowledge of both the standard and real-world audit practice. Day to day, your IT team has priorities other than writing security policies.

Risk of non-conformities during the certification audit

An underdeveloped information security management system leads to non-conformities during the audit. The certification body may then refuse to issue the certificate or make it conditional on closing those non-conformities within a set deadline.

Starting not from zero, but after a setback

Some companies come to us after a failed audit, a security incident or critical feedback from a client or investor. There is no time for a textbook implementation from scratch. The organisation has to raise its maturity quickly and show real improvement, not just another policy.

case study

See how it works in practice

Client:

A MedTech company preparing for ISO 27001 certification.

Challenge:

The company needed to quickly identify and close gaps in its information security management processes in order to meet the requirements of the standard and earn the trust of its most important clients.

Solution:

We ran a gap analysis against ISO 27001. We built the full ISMS documentation set from the ground up, including the risk register and the Statement of Applicability. We then carried out an internal audit and prepared a prioritised remediation plan.

Results:


15 significant non-conformities closed before the external audit. .
Preparation time for the certification audit reduced by 3 months.

External audit passed successfully and ISO 27001 certification achieved.

Your company can go through this process just as smoothly, without the chaos.

Do it yourself, use templates or implement with Tenesys?
CriterionIn-house implementationDocument templatesISO 27001 implementation with Tenesys
Who prepares the documentationyour team, alongside day-to-day workyour team, based on templatesour specialists, together with your team
Fit with company processesdepends on the team’s experiencelow, needs reworkdocuments built around real processes
Technical controlshandled by your IT teamoutside the scope of templatesimplemented as part of the project
Audit preparationno dress rehearsalno dress rehearsalinternal audit that simulates the certification body
Maintenance after certificationan extra task for the teamno supportoptional ISMS manager as part of CISO as a Service
Our service

End-to-end implementation of an Information Security Management System

We guide you through the entire process. We do not stop at advice: we implement the required policies, processes and technical controls.

We analyse external factors (legislation, regulatory requirements, client and partner expectations) and internal ones (structure, organisational culture, technology resources). We also define the needs of interested parties. As a result, the ISMS addresses the risks that actually apply to your company and protects you from penalties, reputational damage and the consequences of failing to meet contractual commitments.

We set clear boundaries for the ISMS: the locations, IT systems, applications and teams covered by certification. Auditors and clients then know exactly which processes your company is responsible for. Scope also works as a budget filter, because protection covers the systems your revenue depends on.

We build an asset register: a list of the information, systems, devices and services the ISMS protects, each with a named owner. The register is the starting point for risk assessment and control selection, so the quality of the whole system depends on it.

We compare your organisation’s current state with the requirements of the standard and all 93 controls in Annex A of ISO/IEC 27001:2022. We pinpoint exactly what is missing and prioritise actions by risk.

We produce the complete required documentation set: the information security policy, the risk register, and procedures for incident management and business continuity. Documents are tailored to the scale and processes of your company rather than copied from a template. We prepare the Statement of Applicability (SoA), the document auditors ask about most often, with a justification for every decision.

A plan kept in a spreadsheet quickly loses its owner and its deadlines. That is why we move the plan, the risk register and the Annex A checklist into the task management system your team already uses. Progress is visible as it happens, not only in a final report.

We identify, assess and prioritise risks using the methodology the standard requires, building a risk register that genuinely supports business decisions.

We put the controls required by the standard into practice: access control, identity management, backups, monitoring and more. We draw on our DevOps and cybersecurity expertise to do it.

We run an internal audit that simulates what the certification body will do, close the non-conformities, and prepare both your team and your documentation for the external auditor.

The standard requires the ISMS to operate continuously: management reviews, internal audits, the PDCA cycle. Without that, keeping the certificate ends in a rushed rebuild of documentation just before the surveillance audit. That is why we offer to act as your ISMS manager as part of CISO as a Service. The ISMS manager keeps track of deadlines, reviews and updates.

If you are also subject to the NIS2 Directive or the DORA Regulation, we extend the programme to cover the additional requirements, such as supplier risk management and resilience testing. We deliver them within a single project instead of running two parallel implementations.

Methodology

Your route to ISO 27001 certification

We follow a six-stage methodology. It is the same route that got us our own ISO 27001 certificate.

1.

Diagnosis

We run a detailed gap analysis against the requirements of the standard and Annex A.

2.

Planning

We build an implementation roadmap with a schedule, the ISMS scope and a clear split of responsibilities. We spin up a ready-made project template in Jira, so from day one your team has tasks laid out rather than a blank page.

3.

Building the system

We develop the documentation and risk register, and implement the required technical and organisational controls.

4.

Putting it into practice

The system starts working in the company’s day-to-day operations, not just on paper. We collect evidence that it functions: records of reviews, tickets handled, training delivered. A lack of such evidence is one of the most common causes of non-conformities during an audit.

5.

Internal audit and corrections

We test the system in practice, then identify and close non-conformities before the external auditor arrives.

6.

External audit and certification

We support you throughout the audit by the independent certification body, which is the only party that can issue the certificate. The certification audit has two stages: a documentation review and an assessment of how the system works in practice. After certification, we help you maintain the ISMS through the annual surveillance audits.

RELATED SERVICES

Other services you may find useful

Risk Analysis and Security Audits
NIS2 and DORA Compliance
CISO as a Service
Identity and Access Management (IAM)
Q&A

Frequently asked questions

It depends on the size and maturity of the organisation. A typical process, from gap analysis to certification audit, takes 4 to 9 months. Most of that time usually goes into running the system in practice and collecting evidence for the auditor.

Not entirely. ISO 27001 is a strong foundation, but the NIS2 Directive and the DORA Regulation impose additional, detailed obligations, for example on supply chain security and resilience testing. We can extend the implementation to cover them.

No. The standard allows you to exclude controls that are not relevant to your organisation, but you must justify each exclusion in the Statement of Applicability (SoA). We help you make those decisions deliberately.

No. The certification audit is carried out by an independent, accredited certification body. We prepare your company so that the audit ends in a positive result, and we can recommend certification bodies we have worked with.

Yes. If you have already had a failed audit, a security incident or critical feedback from a client or investor, we start by assessing what you already have. We then close the most urgent gaps, without rebuilding the system from scratch.

Risk analysis and audits are targeted diagnostic exercises, such as a risk assessment or an internal audit. ISO 27001 implementation is a full programme from diagnosis to certification: building the management system, support during the certification body audit and help with maintaining the system.

The certificate is valid for 3 years. During that time the certification body carries out annual surveillance audits, followed by a recertification audit after three years. Keeping the certificate requires a working ISMS: management reviews, internal audits and an up-to-date risk register.

Annex A now contains 93 controls in four themes: organisational (37), people (8), physical (14) and technological (34). The 2013 version had 114 controls. The transition period for certificates issued against the 2013 version ended on 31 October 2025.