Service
An information security management system that earns certification and still makes sense to the people who have to run it.
Most organisations do not fail ISO 27001. They pass it, and then discover they own a management system nobody uses. The policies were written for the auditor, the risk assessment happened once, and the controls sit in a document library the business has already routed around.
That outcome costs you twice. Once for the project itself, and again every year, when the surveillance audit triggers a scramble to reconstruct evidence that should have accumulated on its own.
An implementation is done properly when the management system produces its evidence as a by-product of how the organisation already works. That is the standard I hold the work to.
Five phases. Each one ends with something you can act on, so you always know where you stand and what it will take to finish.
This is for organisations that need certification for a concrete reason: a customer demands it, a tender requires it, or NIS2 makes it the cleanest route to demonstrating conformity. It works best when someone inside the organisation owns the outcome and management is willing to make decisions rather than approve documents.
If what you want is a certificate as quickly as possible with as little change as possible, I am the wrong consultant. That work exists and other people do it well. I take on implementations where the intention is to keep the system running after the auditor has left.
For an SME with a contained scope, four to eight months from kick-off to the certification audit is realistic. The limiting factor is rarely my availability. It is how quickly your organisation can make decisions and produce evidence.
Certification only matters when someone outside your organisation asks to see the certificate. If your driver is a regulatory obligation or a customer questionnaire, demonstrable conformity with a credible evidence trail is sometimes enough. Decide this deliberately at the start, because it changes both the budget and the timeline.
In Belgium, yes. ISO 27001 is one of the routes the Centre for Cybersecurity Belgium recognises, provided the scope of your management system covers the regulated services and your Statement of Applicability demonstrates measures equivalent to the applicable CyberFundamentals level.
More on NIS2 obligations for Belgian SMEs
Both. I design the system, write what needs writing and run the audit cycle. Your people supply the reality: how the processes actually run, what the technology actually does, where the exceptions live. A management system written entirely by a consultant is precisely the management system nobody uses.
No. ISO/IEC 27001:2022 is the only current edition, and certificates issued against the 2013 version expired on 31 October 2025. If you never transitioned, you are not certified today, and the route back is a transition project rather than a fresh implementation.
Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.
Request an intro call