ISO/IEC 27001:2022 Readiness and ISMS Support

Build an ISO/IEC 27001:2022 ISMS that can be independently audited

Kooch supports the design, documentation and operation of an ISO/IEC 27001:2022 Information Security Management System (ISMS). Readiness depends on your scope, implementation, evidence and management decisions. Certification is assessed and issued only by an independent certification body.

Abstract
Nature

Need stronger information-security evidence for customers or certification?

Enterprise clients, international partners, and formal tenders often require ISO 27001 certification as a baseline for information security.
Without it, you risk being disqualified from major contracts and struggle to prove your commitment to protecting sensitive data. The process can seem complex and time-consuming, acting as a major blocker to your growth.

This service is designed for:

  • Organizations that need ISO 27001 certification to win new customers or meet contractual requirements.
  • Multinationals in sectors like finance, GxP, and cloud services seeking to formalize their security posture.
  • Tech and SaaS companies in competitive markets where an ISO 27001 certificate is a recognized competitive advantage.
  • Looking for a clear, expert-guided plan to improve their data protection framework.

A Structured Path to ISO/IEC 27001:2022 Readiness

This pre-certification service supports ISMS scope, risk assessment and treatment, the Statement of Applicability, policies, selected controls, evidence, internal audit and management review. Your organization implements and owns the ISMS; an independent certification body evaluates conformity. Read about security controls.

How It Works

Our Structured Path to Audit Readiness
1
Step 1: Scoping & ISMS Framework Design

We begin with a scoping call to set the boundaries for your ISMS. Our experts then work with you to design the framework, select the relevant Annex A controls, and define your core ISMS processes.

2
Step 2: Policy Development & Risk Assessment

We co-create approximately 15 core information security policies tailored to your business. Concurrently, we conduct a formal risk assessment, including risk identification, evaluation, and treatment planning.

3
Step 3: Evidence Collection

We guide your team in gathering the necessary operational proof required by auditors. This includes collecting logs, system configurations, employee training records, and other critical evidence.

4
Step 4: Mock Audit & Gap Remediation

To ensure there are no surprises, we run a readiness check that simulates a real audit to identify any final gaps. We then help you address the findings before the formal audit process begins.

5
Step 5: Handover of the Stage 1 Evidence Pack

We organize the agreed documentation and evidence for handover to your chosen independent certification body. The pack supports review but does not guarantee any audit or certification outcome.

What You Get (Deliverables)

A Complete, Audit-Ready ISMS Toolkit

Frequently Asked Questions

What is a Stage 1 audit?

A Stage 1 audit is the first part of the certification process. The auditor primarily reviews your ISMS documentation—such as policies, procedures, and the risk assessment—to ensure it meets the standard's requirements before proceeding to the Stage 2 (implementation) audit.

How long does this readiness process take?

The timeline is typically 2–6 months from start to finish. The final duration is highly dependent on client input and the timely availability of your team for collaboration and evidence gathering.

Does this package guarantee we will get ISO 27001 certified?

No. Kooch provides readiness consulting and does not certify organizations or guarantee an audit result. An independent, appropriately accredited certification body conducts the certification audits and decides whether certification is granted. The outcome also depends on your implementation, evidence and continuing management of the ISMS.

We're already KVKK and GDPR compliant. Do we still need ISO 27001?

They solve different problems. KVKK and GDPR are legal obligations governing how you handle personal data. ISO 27001 is a voluntary certification covering how you manage information security as a whole, including data that isn't personal. Being KVKK or GDPR compliant does not make you ISO 27001 ready, and holding ISO 27001 does not make you KVKK compliant. Clients who need both usually run them as separate but complementary projects — the risk assessment and policy work overlaps, which we account for when scoping.

Pricing

Transparent Pricing for a Clear ROI

Our readiness service is a fixed-fee project tailored to your organization's specific needs.
ISO 27001 Readiness & Documentation
$10,000 – $20,000
(One-Time Project Fee)

ISO/IEC 27001:2022 readiness support covering the agreed ISMS scope, documentation, evidence and internal review activities.
Co-creation of approximately 15 core information security policies tailored to your business.
A comprehensive risk assessment, including risk identification, evaluation, and a treatment plan.
A mock audit to identify and address gaps, with a final compiled evidence pack ready for handover to your auditors.