Built to Scale|Maatwerksoftware · AI · Automatisering
Current – ISO/IEC 27001:2022

ISO/IEC 27001
Information Security Management System
ISMS Certification

ISO/IEC 27001 is the internationally recognized standard for information security. Certification builds trust with enterprise customers, unlocks tenders, and provides solid evidence for NIS2 and GDPR. THE BARK guides you from scope to certificate.

Why act now

More and more enterprise customers, tenders, and supply chains require an ISO 27001 certificate as a prerequisite. Those who start the build early secure contracts that would otherwise go to the competition.

Standard

ISO/IEC 27001:2022

93

Annex A controls

4 themes

Control themes

3 years

Certificate valid

annual

Surveillance audits

iso-27001

Who benefits from ISO 27001?

ISO 27001 is not a legal obligation but a strategic advantage. Certification is especially relevant for companies that must demonstrate trust and stay competitive in the market.

Companies seeking market advantage

  • SaaS & IT providers
  • Cloud & hosting providers
  • Software & app development
  • Managed service providers
  • Data centers
  • Consultancies & agencies
🏭

Companies needing evidence

  • Suppliers in supply chains
  • Data processors (GDPR)
  • Handlers of sensitive data
  • NIS2-affected entities
  • Public-sector vendors
  • Finance & healthcare sector

Note on applicability: ISO 27001 is a voluntary standard – there is no legal obligation to certify. In practice, however, it is increasingly required contractually: by enterprise customers, in public tenders, and as recognized evidence in the context of NIS2 and GDPR. Companies of any size can become certified.

What does ISO 27001 specifically require?

The standard defines a continuous management process (PDCA) as well as binding controls. These six building blocks form the foundation of an audit-ready ISMS.

ISMS scope & context

Definition of scope, internal and external issues, and relevant interested parties. The ISMS must be clearly delimited and tailored to the organization.

Risk assessment & treatment

Systematic identification, analysis, and evaluation of information security risks. A documented treatment decision is made for each risk.

Statement of Applicability (SoA)

The central applicability statement: which of the 93 Annex A controls are relevant, which are implemented – and which are excluded with justification.

Annex A controls implementation

Implementation of the selected measures across four themes: organizational, people, physical, and technological.

Internal audit

Regular internal audits verify that the ISMS is effective and conforms to the standard. Nonconformities are documented and corrected.

Management review & improvement

Top management regularly reviews the ISMS. Findings feed into continual improvement – the core of the PDCA cycle.

The path to certification

A typical ISO 27001 certification journey – from kickoff to certificate.

1
Kickoff

Project start & scope

Definition of scope, assembly of the team, and assignment of responsibilities. The foundation of the ISMS is laid.

2
Analysis phase

Gap analysis & risk register

Comparison of the current state against ISO/IEC 27001:2022 and creation of a complete risk register with treatment plan.

3
Implementation phase

Controls & documentation

Creation of policies, implementation of Annex A controls, and build-up of the audit-ready ISMS documentation including the SoA.

Where we step in
4
Certification

Stage 1 & 2 audit

An external certification body reviews the documentation (Stage 1) and effectiveness (Stage 2). On success: a certificate valid for 3 years.

How we support you with ISO 27001

From the gap analysis to passing the certification audit – we guide you through the entire ISMS build in three clearly structured phases.

Phase 1

Analysis

We define the scope, compare your current state against ISO/IEC 27001:2022, and create a solid risk register.

  • Define scope & context
  • Gap analysis against 27001:2022
  • Build risk register
  • Derive treatment plan
2–4 weeks · report included
Phase 2

Implementation

We create policies, implement the Annex A controls, and build the complete, audit-ready ISMS documentation.

  • Create policies & procedures
  • Implement Annex A controls
  • Statement of Applicability (SoA)
  • Build documentation
  • Roll out the ISMS across the organization
8–16 weeks · complete documentation
Phase 3

Support

We prepare you for the audit, support you during certification, and keep the ISMS effective over the long term.

  • Conduct internal audits
  • Support certification
  • Prepare surveillance audits
  • Continual improvement
Ongoing · annual surveillance

Frequently Asked Questions about ISO 27001

Ready for your ISO 27001 certificate?

Let us determine scope and maturity together – and plan the fastest path to the certificate. Free initial consultation, concrete assessment.

Schedule free initial consultation

We will get back to you within 24 hours.

© 2025 THE BARK — Vedat EGE · Oberhausen · the-bark.de