Service · ISO 27001 (technical controls)
ISO 27001: we build the technical controls.
An ISO 27001 ISMS has a management-system half (policies, risk methodology, the Statement of Applicability) and a technical-controls half. We do the technical half - the Annex A technological controls, a security gap assessment, and the testing that proves they hold. The certificate is issued by an accredited body you retain; we are not a certification body and take no referral fee.
What we do
Which ISO 27001 Annex A controls do we implement?
The engineering half of an ISMS - the controls an auditor actually inspects on the technical side.
Technical gap analysis
Current-state assessment against the technological Annex A controls (ISO 27001:2022). Output: a remediation backlog ranked by risk and effort.
Technical risk input
Asset inventory and threat modeling on the systems side, feeding the risk register your ISMS needs. The formal risk methodology + Statement of Applicability sit with your GRC lead; we supply the technical reality.
Control implementation
MFA, SSO, encryption in transit and at rest, centralized logging and monitoring, change management, and a secure SDLC.
Vulnerability management & VAPT
Penetration testing plus continuous scanning (Vexta) - the technical vulnerability-management evidence an auditor expects to see operating.
Control documentation
Clear write-ups of the technical controls and how they map to Annex A, so your auditor and GRC lead can slot them into the ISMS.
Technical auditor support
We answer the security-control questions and help show the technical evidence during stage-1 and stage-2 fieldwork, alongside the certifier you retain.
What we own vs. what stays with you
How we scope it
How do we scope the ISO 27001 technical work?
Sized to your current security maturity after a short scoping call.
Assess
Technical gap analysis against the technological Annex A controls. You get a ranked control backlog.
Implement
We build and harden the technical controls - access, encryption, logging/monitoring, vulnerability management, secure SDLC.
Test
Penetration testing and scanning to confirm the controls hold and to produce technical evidence.
Support fieldwork
We stand alongside you on the technical questions while your chosen accredited body runs stage 1 and stage 2.
ISO 27001 FAQ
Do you do the audit, or issue the certificate?
What exactly do you do vs. not do?
What does it cost?
How does this relate to SOC 2?
ISO 27001 on your roadmap?
Let's scope the technical-controls work. The ISMS and the certificate stay with you and your accredited body - we make the technical side solid.

