Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

ISO 27001: A Pragmatic Path to Certification

ISO/IEC 27001 is the international standard for information security management systems (ISMS). mgm security partners sets up your ISMS, prepares it for certification, and guides you through the external audit—in a pragmatic, customized manner, with certified auditors who understand the technology, not just the standard.

Organizations are typically ready for certification within 6 to 12 months, depending on their starting point and the scope of the project. Starting early helps avoid time pressure right before the certification audit.

Our ISO 27001 Services

Offer

Five coordinated steps, from the initial assessment to passing the certification audit.

  • Compare the current status against ISO/IEC 27001:2022 and Annex A
  • Clearly Define the Scope and Interfaces
  • Quantify gaps and realistically estimate the effort required
  • Prioritized Roadmap with Milestones Leading Up to the Certification Audit
  • Establish a methodology for risk identification, assessment, and mitigation
  • Create and Justify a Statement of Applicability (SoA)
  • Risk Treatment Plan with Clear Responsibilities
  • Integration with Existing Enterprise Risk Management
  • Developing Guidelines, Policies, and Procedures
  • Define Roles, Responsibilities, and Reporting Lines
  • Streamlined, audit-ready documentation instead of mountains of paper
  • Integration into the existing management and tool landscape
  • Implement the technical controls in Appendix A in a concrete and effective manner
  • Evaluate access management, hardening, logging, cryptography, and backup
  • Implementing Vulnerability and Patch Management
  • Integration with penetration tests and existing security processes
  • Prepare for and Conduct Internal Audits and Management Reviews
  • Readiness Check and Preparation for the Certification Audit
  • Support during the audit with the certification body
  • Handling Nonconformities and Corrective Actions

The challenge

  • Setting up an ISMS ties up internal resources that are then lacking in day-to-day operations
  • Standard requirements are abstract and leave plenty of room for interpretation
  • Risk analysis, SoA, and the policy landscape seem overly complex
  • Transition from ISO 27001:2013 to 2022 with new and revised controls
  • Uncertainty as to whether the ISMS will pass the external certification audit

Our Added Value

  • Certified auditors will guide you, seeing things from the auditor's perspective
  • Experts who understand the technology, not just the standard
  • Pragmatic implementation tailored specifically to your company
  • An ISMS that is actually put into practice rather than just existing on paper
  • Reliable support all the way through the external certification audit

Your Path to ISO 27001 Certification

ISO 27001 is a cycle, not a project. We provide pragmatic, personalized support to guide you through the continuous improvement process.

ISO 27001: Quick Answers to Your Questions

No. We are certified auditors, but we deliberately do not conduct external certification audits. That is handled by an accredited certification body. This is precisely why we are fully on your side, with no conflict of interest: We set up your ISMS, conduct internal audits, and guide you through the external audit.

That depends on the starting point, scope, and internal resources. Typically, companies are ready for certification within 6 to 12 months. The gap analysis provides a reliable roadmap within just a few weeks.

Rarely. Most companies already have security measures and processes in place. In the gap analysis, we identify what is already up to ISO 27001 standards and what needs to be added. We build on what already exists rather than creating parallel structures.

ISO/IEC 27001:2022 reorganizes the controls in Annex A: instead of 114, there are now 93 controls across four subject areas, with eleven new controls, such as those related to threat intelligence, cloud security, and secure software development. The transition period from 2013 to 2022 ended on October 31, 2025. We provide support for initial certifications and the transition.

Yes. An effective ISO 27001 ISMS addresses many requirements of current regulations such as NIS2 and DORA, including risk management, reporting processes, and technical security measures. We integrate regulatory requirements into the workflows your teams already use.

Maximiliane Mayer

Let's talk about your ISO 27001 certification! Schedule your appointment!

DeepDive

What is ISO/IEC 27001?

ISO/IEC 27001 is the world’s leading standard for information security management systems. It describes how organizations systematically establish, operate, and continuously improve information security in a risk-based manner across all processes, people, and technology. The current version, ISO/IEC 27001:2022, contains 93 controls in Annex A, categorized into organizational, personnel-related, physical, and technological measures.

Certification is issued by an accredited certification body and is valid for three years, with annual surveillance audits. For many companies today, the certificate is a prerequisite for bidding on contracts, serves as proof of trustworthiness to customers, or is required to meet regulatory requirements such as NIS2 or DORA. For existing certificates under ISO/IEC 27001:2013, the transition period to the 2022 version ended on October 31, 2025.

93 Controls
Measures listed in Annex A of ISO/IEC 27001:2022, organized into 4 subject areas
3 years
Validity of the certificate, with annual surveillance audits
6–12 months
Typical time required to achieve certification readiness, depending on the initial situation
NIS2 & DORA
An ISO 27001 ISMS meets key requirements of current regulations