Skip to main content
ServicesComplianceAboutContact
Free assessment

Professional cybersecurity services. Protecting your business from modern threats.

ServicesPenetration TestingSOC as a ServiceVulnerability ManagementCloud SecuritySecurity Training
ComplianceISO 27001 ReadinessGDPR ComplianceNIS2 Directive
CompanyAbout UsContactLet's talkBlog
© 2026 IT Baseline OOD (EIK: 202950882). All rights reserved.
Privacy PolicyTerms of ServiceCookies
COMPLIANCE — ISO/IEC 27001:2022

A clear path toISO 27001.

Gap analysis, ISMS design, and audit preparation, so you walk into certification ready. One partner, from the first assessment to the Stage 2 audit.

Start with a gap analysisTalk to an ISO expert ↗
ISO 27001
The information security standard
Gap → Audit
End-to-end, one partner
Annex A
93 controls, 4 themes
ISMS
Built around how you work

The roadmap

GAP → CERTIFICATION
01Gap analysisWe measure your current controls against ISO 27001 and map exactly what is missing before any documents are written.
02ISMS designScope, risk assessment, Statement of Applicability, and the policy set that forms your management system.
03ImplementationWe roll out the controls, procedures, and awareness training that turn the ISMS from paper into daily practice.
04Internal auditAn independent readiness check and management review confirm the system works before the certification body arrives.
05Certification auditStage 1 reviews your documentation, Stage 2 verifies implementation on site. You walk in prepared.

Annex A domains

ISO/IEC 27001:2022 · 93 CONTROLS
A.5
Organizational

37 controls for policies, roles, supplier relationships, and how information security is governed across the business.

A.6
People

8 controls for screening, awareness, responsibilities, and the human side of keeping information secure.

A.7
Physical

14 controls for secure areas, equipment, and protecting the environment where information physically lives.

A.8
Technological

34 controls for access, cryptography, logging, and the technical safeguards on your systems and data.

Questions, answered.

How long does preparation take?+

Typically 6 to 12 months, depending on organization size, current maturity, and available resources.

What is the difference between ISO 27001 and SOC 2?+

ISO 27001 is an international standard for an ISMS; SOC 2 is an American framework for service organizations. ISO is more widely recognized in Europe and globally.

Do we need a dedicated security team?+

Not necessarily. Many organizations use our vCISO services as a cost-effective alternative to a full-time security team.

What do the Stage 1 and Stage 2 audits involve?+

Stage 1 is a documentation review of the ISMS. Stage 2 is an on-site audit that verifies implementation. The two stages are usually 2 to 4 weeks apart.

Certification opens doors. Lack of it closes them.
START WITH A GAP ANALYSIS TO SEE HOW CLOSE YOU ALREADY ARE
Start with a gap analysis →