ISO 27001 implementation

An information security management system that earns certification and still makes sense to the people who have to run it.

← Back to home

Why most ISO 27001 projects disappoint

Most organisations do not fail ISO 27001. They pass it, and then discover they own a management system nobody uses. The policies were written for the auditor, the risk assessment happened once, and the controls sit in a document library the business has already routed around.

That outcome costs you twice. Once for the project itself, and again every year, when the surveillance audit triggers a scramble to reconstruct evidence that should have accumulated on its own.

An implementation is done properly when the management system produces its evidence as a by-product of how the organisation already works. That is the standard I hold the work to.

How I run an implementation

Five phases. Each one ends with something you can act on, so you always know where you stand and what it will take to finish.

  1. Scope and context We decide what the management system covers and, just as importantly, what it does not. Scope drives everything downstream: an oversized scope inflates the audit, the documentation and the yearly maintenance. This phase delivers the scope statement, the interested parties and the boundaries you will defend in front of an auditor.
  2. Gap analysis I measure your current situation against the requirements of ISO/IEC 27001:2022 and its Annex A controls, and record what already exists. Most SMEs are further along than they assume. The gap is usually in governance and evidence, not in technology.
  3. Risk assessment and treatment A risk assessment your management team can actually discuss: scenarios in business language, a method that survives being repeated next year, and treatment decisions that carry an owner and a date. The Statement of Applicability follows from this, not the other way around.
  4. Documentation and implementation Policies and procedures written for the people who have to follow them, in Dutch or English. I keep the set as small as the standard allows. Every document you create is a document you have to maintain, review and prove you follow.
  5. Internal audit, management review and certification support Before a certification body arrives, the system has to have completed a full cycle: internal audit, corrective actions, management review. I run that cycle, assemble the evidence and support you through the certification audit itself.

What you end up with

Who this is for

This is for organisations that need certification for a concrete reason: a customer demands it, a tender requires it, or NIS2 makes it the cleanest route to demonstrating conformity. It works best when someone inside the organisation owns the outcome and management is willing to make decisions rather than approve documents.

If what you want is a certificate as quickly as possible with as little change as possible, I am the wrong consultant. That work exists and other people do it well. I take on implementations where the intention is to keep the system running after the auditor has left.

Questions I get

How long does an implementation take?

For an SME with a contained scope, four to eight months from kick-off to the certification audit is realistic. The limiting factor is rarely my availability. It is how quickly your organisation can make decisions and produce evidence.

Do we need to be certified, or is conformity enough?

Certification only matters when someone outside your organisation asks to see the certificate. If your driver is a regulatory obligation or a customer questionnaire, demonstrable conformity with a credible evidence trail is sometimes enough. Decide this deliberately at the start, because it changes both the budget and the timeline.

Can ISO 27001 cover our NIS2 obligations?

In Belgium, yes. ISO 27001 is one of the routes the Centre for Cybersecurity Belgium recognises, provided the scope of your management system covers the regulated services and your Statement of Applicability demonstrates measures equivalent to the applicable CyberFundamentals level.

More on NIS2 obligations for Belgian SMEs

Who does the work, you or us?

Both. I design the system, write what needs writing and run the audit cycle. Your people supply the reality: how the processes actually run, what the technology actually does, where the exceptions live. A management system written entirely by a consultant is precisely the management system nobody uses.

We are still certified against the 2013 version. Does that count?

No. ISO/IEC 27001:2022 is the only current edition, and certificates issued against the 2013 version expired on 31 October 2025. If you never transitioned, you are not certified today, and the route back is a transition project rather than a fresh implementation.

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call