ISO 27001 & 22301 Certification Support
Budget: $30 – $250 USD
Our small-size IT company is preparing for formal certification against ISO/IEC 27001 (information security management) and ISO 22301 (business continuity). We already have a handful of security and continuity policies, but they are patchy and don’t yet form a coherent management system. The immediate priority is building out the full document set so an accredited auditor can walk in, trace every clause to living evidence, and issue the two certificates with minimal findings.
What I need you to drive:
• Expand our existing artefacts into a complete, audit-ready ISMS and BCMS: scope statement, risk methodology, SoA, mandatory and supporting procedures, policy suite, business impact analysis, continuity strategies, test plans, records and forms.
• Align everything with the latest ISO/IEC 27001:2022 and ISO 22301:2019 clause structures and terminology.
• Provide version-controlled templates (Word / Excel or similar) that my team can maintain after hand-over.
• Walk me through each draft so the rationale, ownership and evidence requirements are crystal-clear.
Nice-to-haves that you may also cover if time allows are a brief gap validation against Annex A controls and tips on our first internal audit, but documentation is the core deliverable.
Acceptance criteria
1. All required documents delivered and cross-referenced to the standard’s clauses.
2. Language and formatting consistent with professional certification expectations.
3. My team can demonstrate, via a short rehearsal session with you, where each piece of evidence will reside.
If you’re an ISO lead implementer or auditor who has taken tech companies over the finish line before, I’m ready to get started right away.
What I need you to drive:
• Expand our existing artefacts into a complete, audit-ready ISMS and BCMS: scope statement, risk methodology, SoA, mandatory and supporting procedures, policy suite, business impact analysis, continuity strategies, test plans, records and forms.
• Align everything with the latest ISO/IEC 27001:2022 and ISO 22301:2019 clause structures and terminology.
• Provide version-controlled templates (Word / Excel or similar) that my team can maintain after hand-over.
• Walk me through each draft so the rationale, ownership and evidence requirements are crystal-clear.
Nice-to-haves that you may also cover if time allows are a brief gap validation against Annex A controls and tips on our first internal audit, but documentation is the core deliverable.
Acceptance criteria
1. All required documents delivered and cross-referenced to the standard’s clauses.
2. Language and formatting consistent with professional certification expectations.
3. My team can demonstrate, via a short rehearsal session with you, where each piece of evidence will reside.
If you’re an ISO lead implementer or auditor who has taken tech companies over the finish line before, I’m ready to get started right away.
Related categories:
Project Management
Training
Health & Medicine
Audit
Compliance
Risk Management
Documentation
Change Management