ISO 27001 Implementation and Audit
ISMS design, risk management, Annex A controls and certification support.
Request an initial assessmentISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). Certification shows customers, partners and regulators that information is managed under a proven system.
MH Consulting has experience implementing and assessing ISMSs against ISO/IEC 27001:2022, from the initial assessment through to readiness for the certification audit.
What it covers
- Gap analysis against ISO/IEC 27001:2022
- Scope definition and ISMS design
- Risk methodology and assessment, risk treatment plan
- Statement of Applicability and Annex A controls
- Information security policies and procedures
- Staff training and awareness
- Internal audit and management review
- Support during the certification audit
Frequently asked questions
ISO 27001 Implementation and Audit
How long does ISO 27001 certification take?
It depends on the size of the scope and on how many controls you already have in place. After the gap analysis we give you a realistic phased plan up to the certification audit.
Do you issue the certificate?
No. The certificate is issued by an accredited certification body that is independent of the consultant. We prepare you and support you during the audit.
How does ISO 27001 relate to the GDPR and Law 124?
ISO 27001 covers information security as a whole, while the GDPR and Law 124 cover personal data. A working ISMS helps you meet the security requirements of those laws, but it does not replace their other obligations, such as legal basis or data subject rights.
Services
Other services
SOC 1, SOC 2 and SOC 3 Reports
Attestation, readiness and training ahead of the engagement.
Learn morePenetration Testing and Red Teaming
Testing of infrastructure, web, mobile and cloud, with technical and executive reports.
Learn moreIT Audit
Audits against COBIT, NIST and the requirements of local regulators.
Learn moreCybersecurity and Resilience
Risk assessment, security frameworks, business continuity and incident response.
Learn moreAI Compliance and Security
EU AI Act, ISO/IEC 42001, risk assessment and governance frameworks for AI systems.
Learn moreGovernance, Risk and Compliance (GRC)
Integrated GRC frameworks, risk assessments, compliance audits and GRC platforms.
Learn moreLet's talk about your next engagement.
Tell us about your engagement — we typically respond within one business day.
