ASSESS
An honest starting position
A gap assessment across twenty-three requirement areas, scored zero to five against evidence you can actually produce. It tells you where you are before anyone commits to a date, and it is the same scale you re-score against later, so progress is comparable rather than asserted.
DEFINE
Context, scope and obligations
Internal and external issues, interested parties and their requirements, and a scope statement drafted as the sentence you want on a certificate and then worked backwards. Includes the climate change consideration added by ISO/IEC 27001:2022/Amd 1:2024, described honestly and proportionately.
PLAN
A programme that survives the day job
Mandate, sponsorship, roles and an effort model in person-days, with three routes — twelve months, six to seven months, and an accelerated path with the preconditions it genuinely requires and the point at which you should step back to a longer one.
DESIGN
A risk method you can repeat
Asset, threat and vulnerability structure, a fifty-four entry threat library, likelihood and impact criteria, five risk bands and four treatment options. The output feeds control selection directly, so the Statement of Applicability is derived from risk rather than reverse engineered.
IMPLEMENT
Every control, with an owner
Implementation guidance for all ninety-three Annex A control references across the four themes, each with what implementing it proportionately looks like, the decisions you have to make, the evidence it produces and the way it commonly fails.
DOCUMENT
Policies and procedures that are usable
Thirty policies with numbered, testable statements an audit finding can cite, and eighteen procedures written so a competent person who has never run one can follow it without asking a question. Supplied as designed PDFs and editable Word documents.
MEASURE
Evidence as a by-product of the work
An evidence model with five evidence types, a naming convention and retention, a lookup of what evidence each requirement needs, and twelve measures with sources, owners and frequencies. Designed so the records accumulate as you work rather than in a scramble beforehand.
AUDIT
Assurance that finds real things
An audit programme across the twenty-three requirement areas, auditor competence and independence, checklists by requirement area, working papers and sampling, the four finding categories, root cause analysis and corrective action tracked through to verified effectiveness.
CERTIFICATION READINESS
Prepared, not hopeful
What a certification body actually assesses and how the two stages differ, a readiness assessment on a zero-to-five scale, control-by-control preparation, how to run the assessment days, and how to respond to findings. Readiness scoring is a management tool for your own use, never a prediction of an outcome.