~12 MO
To first certification
Gap assessment, ISMS buildout, then a two-stage audit. It's a management system you operate, not a document you submit — and that takes time a deal won't give you.
ISO 27001 is the internationally recognized proof of a working security program — the one European, UK, and global-enterprise buyers expect by name. But it certifies a management system, not a checklist, and that's roughly a 12-month build you can't fast-track. We get you certification-ready before the contract demands it.
Book an ISO 27001 Strategy Call →// WHY ISO 27001, WHY NOW
~12 MO
Gap assessment, ISMS buildout, then a two-stage audit. It's a management system you operate, not a document you submit — and that takes time a deal won't give you.
93 / 4
The 2022 revision restructured Annex A into 93 controls across Organizational, People, Physical, and Technological themes — 11 of them entirely new for cloud, threat intel, and secure development.
GLOBAL
Where SOC 2 anchors North American deals, ISO 27001 is what European, UK, and global-enterprise buyers require by name — often a hard gate on cross-border contracts.
// CONTROLS AREN'T THE SYSTEM
The most expensive misread in ISO 27001 is treating it as a control checklist. The standard certifies an Information Security Management System — the clauses 4–10 governance of risk assessment, internal audit, and management review — and Annex A is just the catalog the ISMS draws from. Build a binder of controls with no system underneath and you fail Stage 1, because the auditor reads your Statement of Applicability and ISMS documentation first.
// THE ISMS + ANNEX A
ISO 27001 certifies your ISMS — the management system that runs risk assessment, internal audit, and review. The 93 Annex A controls plug into it across four themes, and the Statement of Applicability declares which apply.
Context, leadership, planning, support, operation, evaluation, and improvement — the governance system an accredited body audits. The four Annex A themes below are the control catalog the ISMS selects from, declared in the Statement of Applicability the auditor reads first.
// A.5
Organizational
37 controls
// A.6
People
8 controls
// A.7
Physical
14 controls
// A.8
Technological
34 controls
Most failed Stage 1 audits trace back to a weak or stale Statement of Applicability.
// THE PATH
A first certification runs about 12 months, then a 3-year cycle. The amber stages are the accredited certification body's audits — Stage 1 reads your documents, Stage 2 tests the system in operation.
Gap
Gap Assessment
MO 0–2
Build
ISMS Buildout
MO 2–5
Stage 1
Documentation Audit
MO 5–6
Stage 2
Certification Audit
MO 6–7
Surveil
Surveillance Yr 1&2
MO 12, 24
Recert
Recertification
YEAR 3
Amber stages are the accredited certification body's audits — Stage 1 (documentation) and Stage 2 (operation). Certification runs a continuous 3-year cycle, not a one-time pass.
// IS THIS YOU?
// 01 // GLOBAL DEAL
A European, UK, or global-enterprise prospect's procurement asked for ISO 27001 specifically — and a SOC 2 report won't substitute. The deal waits until you're certified.
// 02 // SOC 2 ALREADY
You've done SOC 2 and you're going international. Your controls are a head start — but you still need the ISMS that ISO 27001 certifies on top of them.
// 03 // LAPSED CERT
The 2013 version lapsed on Oct 31, 2025. If you didn't transition, the certificate is invalid — and you now face a full recertification against 2022, not a quick transition audit.
// WHAT WE DO
// Phase 01 · Assess
We measure your current state against the standard, define the ISMS scope, and map the work — so the buildout targets real gaps, not guesswork.
// Phase 02 · Build
We stand up the management system the auditor certifies — risk treatment, the SoA, internal audit, and the controls — then run a mock audit before Stage 1.
// Phase 03 · Sustain
We carry you through Stage 2 and keep the ISMS live between audits, so surveillance and recertification are maintenance — not a restart.
// THE BUILD TAKES MONTHS
// FREQUENTLY ASKED
It's not a checklist. ISO 27001 certifies an Information Security Management System (ISMS) — the governance system in clauses 4–10: context, leadership, planning, support, operation, evaluation, and improvement. Annex A is a catalog of 93 reference controls the ISMS selects from; the controls serve the system, not the reverse.
This is the most expensive misunderstanding teams bring in. Treat it as a control checklist and you build a binder with no management system underneath, then fail Stage 1 — the auditor reads the Statement of Applicability and ISMS documentation first and finds no functioning system of risk assessment, internal audit, and review. The controls are the easy part; the ISMS is what gets certified.
The 2022 revision restructured Annex A from 114 controls across 14 domains into 93 across four themes — Organizational (37), People (8), Physical (14), Technological (34). Eleven controls are entirely new, covering cloud services, threat intelligence, data masking, DLP, secure development, and more. The clauses 4–10 changed only modestly.
On the old version: the transition deadline of October 31, 2025 has passed. Any 2013 certificate is now invalid regardless of its printed expiration. If your 2013 cert lapsed without transitioning, you can't do a shorter transition audit anymore — you need a full recertification against 2022, meaning a complete Stage 1 and Stage 2.
A first-time certification typically runs about 12 months — faster with a mature program, longer from scratch. The path: gap assessment, ISMS buildout (risk assessment and treatment, policies, the SoA, internal audit, management review), then the two-stage certification audit.
Stage 1 is a documentation and readiness review — the auditor reads your ISMS docs and SoA to confirm the system is designed and ready; most Stage 1 failures trace to a weak or stale SoA. Stage 2 tests whether the ISMS and its controls are actually operating. Certification is then valid three years, with annual surveillance audits and a full recertification at year three.
It depends who you sell to. SOC 2 dominates North American enterprise procurement; ISO 27001 is the internationally recognized certification expected in Europe, the UK, the Middle East, Asia, and global enterprise and government supply chains. Many companies eventually need both because different buyers ask for different proof.
The good news is heavy overlap — ISO 27001's Annex A controls cover most of what a SOC 2 Security examination tests, so an existing SOC 2 program is a strong head start on the control side. What SOC 2 doesn't give you is the ISMS: the certified management system ISO 27001 requires on top of the controls. If your roadmap includes global customers, ISO 27001 usually isn't optional for long.
// THE NEXT MOVE
Book a 30-minute ISO 27001 strategy call with a WatchUr6 advisor. Bring the buyer or market driving this, whether you already hold SOC 2 or a lapsed 2013 cert, and your target timeline. You'll walk away with a right-sized ISMS scope, an honest read on your gaps, and a realistic path to a 2022 certification — whether you hire us or not.
Book an ISO 27001 Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED