Skip to main content
M516 Cyber Solutions

Assurance & Certification

ISO 27001 certification without the theatre

Felix · 1 August 2026 · 1 min read

Certification is straightforward when the management system reflects how the business actually runs. Here is how to avoid a paper ISMS.

ISO/IEC 27001:2022 rewards organisations that build a management system around real operations. It punishes those who write an ISMS for the auditor and then run the business a different way.

Scope decides everything

A narrow, honest scope certifies faster and survives surveillance audits. An overreaching scope creates findings in areas the business never intended to control.

Get the risk assessment right

Assets, threats, owners, treatment decisions and residual risk acceptance — recorded, dated and approved. The Statement of Applicability should follow from that assessment, not from a template.

Annex A in 2022 terms

The 93 controls are grouped into organisational, people, physical and technological themes. New additions such as threat intelligence, cloud service security, secure coding and data leakage prevention reflect how organisations now operate.

Evidence over intent

Auditors test operation, not authorship. Internal audit, management review, corrective actions, competence records and metrics need a visible history. Three weeks of logs before Stage 2 is a familiar and avoidable finding.

Extending the certificate

ISO/IEC 27701 adds privacy information management for GDPR alignment. ISO/IEC 42001 adds AI management. Both sit on the same clauses 4 to 10 spine, so the incremental effort is far smaller than a standalone programme.

Build the system you actually use, and certification becomes a by-product.

  • ISO 27001
  • ISO 27701
  • certification

← All insights

Want this thinking applied to your supplier ecosystem?

A short, no-obligation discovery call to understand your risk profile and where to start.