WATCHUR6 // ISO 27001 // AUDIT READINESS

The credential global buyers
trust before they trust you.

ISO 27001 is the internationally recognized proof of a working security program — the one European, UK, and global-enterprise buyers expect by name. But it certifies a management system, not a checklist, and that's roughly a 12-month build you can't fast-track. We get you certification-ready before the contract demands it.

Book an ISO 27001 Strategy Call
ISO/IEC 27001:2022 CERTIFIED ISMS 93 ANNEX A CONTROLS VETERAN-LED

// WHY ISO 27001, WHY NOW

It's a system, not a sprint. And the clock starts at contract, not after.

~12 MO

To first certification

Gap assessment, ISMS buildout, then a two-stage audit. It's a management system you operate, not a document you submit — and that takes time a deal won't give you.

93 / 4

Controls across four themes

The 2022 revision restructured Annex A into 93 controls across Organizational, People, Physical, and Technological themes — 11 of them entirely new for cloud, threat intel, and secure development.

GLOBAL

The international standard

Where SOC 2 anchors North American deals, ISO 27001 is what European, UK, and global-enterprise buyers require by name — often a hard gate on cross-border contracts.

// CONTROLS AREN'T THE SYSTEM

We'll just implement the 93 Annex A controls.
The auditor certifies the ISMS — the controls just serve it.

The most expensive misread in ISO 27001 is treating it as a control checklist. The standard certifies an Information Security Management System — the clauses 4–10 governance of risk assessment, internal audit, and management review — and Annex A is just the catalog the ISMS draws from. Build a binder of controls with no system underneath and you fail Stage 1, because the auditor reads your Statement of Applicability and ISMS documentation first.

// THE ISMS + ANNEX A

93 controls. Four themes. One certified system.

ISO 27001 certifies your ISMS — the management system that runs risk assessment, internal audit, and review. The 93 Annex A controls plug into it across four themes, and the Statement of Applicability declares which apply.

The ISMS Clauses 4–10 · the thing that gets certified

Context, leadership, planning, support, operation, evaluation, and improvement — the governance system an accredited body audits. The four Annex A themes below are the control catalog the ISMS selects from, declared in the Statement of Applicability the auditor reads first.

// A.5

Organizational

37 controls

// A.6

People

8 controls

// A.7

Physical

14 controls

// A.8

Technological

34 controls

Most failed Stage 1 audits trace back to a weak or stale Statement of Applicability.

2022 Revision · 114/14 → 93/4 11 New Controls · CLOUD, THREAT INTEL, DLP SoA · READ FIRST IN EVERY AUDIT

// THE PATH

From gap to renewable certification.

A first certification runs about 12 months, then a 3-year cycle. The amber stages are the accredited certification body's audits — Stage 1 reads your documents, Stage 2 tests the system in operation.

Gap

Gap Assessment

MO 0–2

Build

ISMS Buildout

MO 2–5

Stage 1

Documentation Audit

MO 5–6

Stage 2

Certification Audit

MO 6–7

Surveil

Surveillance Yr 1&2

MO 12, 24

Recert

Recertification

YEAR 3

Amber stages are the accredited certification body's audits — Stage 1 (documentation) and Stage 2 (operation). Certification runs a continuous 3-year cycle, not a one-time pass.

// IS THIS YOU?

Three signs it's time to start.

// 01 // GLOBAL DEAL

A buyer wants ISO 27001 by name

A European, UK, or global-enterprise prospect's procurement asked for ISO 27001 specifically — and a SOC 2 report won't substitute. The deal waits until you're certified.

// 02 // SOC 2 ALREADY

You have SOC 2 and need the next credential

You've done SOC 2 and you're going international. Your controls are a head start — but you still need the ISMS that ISO 27001 certifies on top of them.

// 03 // LAPSED CERT

Your 2013 certificate expired

The 2013 version lapsed on Oct 31, 2025. If you didn't transition, the certificate is invalid — and you now face a full recertification against 2022, not a quick transition audit.

// WHAT WE DO

The system, the audit, and the years after.

// Phase 01 · Assess

Gap Assessment & Scoping

We measure your current state against the standard, define the ISMS scope, and map the work — so the buildout targets real gaps, not guesswork.

  • Gap assessment against clauses 4–10 and Annex A
  • ISMS scope definition and asset boundary
  • Prioritized roadmap to a certifiable system

// Phase 02 · Build

ISMS Buildout & Audit Readiness

We stand up the management system the auditor certifies — risk treatment, the SoA, internal audit, and the controls — then run a mock audit before Stage 1.

  • Risk assessment, treatment plan, and Statement of Applicability
  • Annex A control implementation across all four themes
  • Internal audit, management review, and Stage 1 readiness

// Phase 03 · Sustain

Certification & the 3-Year Cycle

We carry you through Stage 2 and keep the ISMS live between audits, so surveillance and recertification are maintenance — not a restart.

  • Certification body coordination and Stage 2 support
  • Annual surveillance audit readiness
  • Continual improvement and year-3 recertification

// THE BUILD TAKES MONTHS

You can't certify an ISMS the week a global deal asks for it.

Book an ISO 27001 Strategy Call

// FREQUENTLY ASKED

The ISO 27001 questions teams keep asking.

Is ISO 27001 a control checklist, or something else?

It's not a checklist. ISO 27001 certifies an Information Security Management System (ISMS) — the governance system in clauses 4–10: context, leadership, planning, support, operation, evaluation, and improvement. Annex A is a catalog of 93 reference controls the ISMS selects from; the controls serve the system, not the reverse.

This is the most expensive misunderstanding teams bring in. Treat it as a control checklist and you build a binder with no management system underneath, then fail Stage 1 — the auditor reads the Statement of Applicability and ISMS documentation first and finds no functioning system of risk assessment, internal audit, and review. The controls are the easy part; the ISMS is what gets certified.

What changed in 2022, and does the old version still count?

The 2022 revision restructured Annex A from 114 controls across 14 domains into 93 across four themes — Organizational (37), People (8), Physical (14), Technological (34). Eleven controls are entirely new, covering cloud services, threat intelligence, data masking, DLP, secure development, and more. The clauses 4–10 changed only modestly.

On the old version: the transition deadline of October 31, 2025 has passed. Any 2013 certificate is now invalid regardless of its printed expiration. If your 2013 cert lapsed without transitioning, you can't do a shorter transition audit anymore — you need a full recertification against 2022, meaning a complete Stage 1 and Stage 2.

How long does it take, and what are Stage 1 and Stage 2?

A first-time certification typically runs about 12 months — faster with a mature program, longer from scratch. The path: gap assessment, ISMS buildout (risk assessment and treatment, policies, the SoA, internal audit, management review), then the two-stage certification audit.

Stage 1 is a documentation and readiness review — the auditor reads your ISMS docs and SoA to confirm the system is designed and ready; most Stage 1 failures trace to a weak or stale SoA. Stage 2 tests whether the ISMS and its controls are actually operating. Certification is then valid three years, with annual surveillance audits and a full recertification at year three.

We already have SOC 2. Do we also need ISO 27001?

It depends who you sell to. SOC 2 dominates North American enterprise procurement; ISO 27001 is the internationally recognized certification expected in Europe, the UK, the Middle East, Asia, and global enterprise and government supply chains. Many companies eventually need both because different buyers ask for different proof.

The good news is heavy overlap — ISO 27001's Annex A controls cover most of what a SOC 2 Security examination tests, so an existing SOC 2 program is a strong head start on the control side. What SOC 2 doesn't give you is the ISMS: the certified management system ISO 27001 requires on top of the controls. If your roadmap includes global customers, ISO 27001 usually isn't optional for long.

// THE NEXT MOVE

Start the system before the contract needs the cert.

Book a 30-minute ISO 27001 strategy call with a WatchUr6 advisor. Bring the buyer or market driving this, whether you already hold SOC 2 or a lapsed 2013 cert, and your target timeline. You'll walk away with a right-sized ISMS scope, an honest read on your gaps, and a realistic path to a 2022 certification — whether you hire us or not.

Book an ISO 27001 Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED