Certification and compliance

Become certification-ready for ISO/IEC 27001, ISO/IEC 42001 and ISO 22301, and establish documented GDPR compliance with ISO/IEC 27701. Gap assessment, advisory support or full implementation.

Being certification-ready means the organisation genuinely runs on the standard rather than merely describing it. The requirements are understood and turned into processes that are used, roles that are filled, decisions taken by management, and documentation that shows what has been done. An auditor looks for evidence that the system works in practice. That is the work Berigo supports.

Berigo is an adviser and implementation partner. Certification itself is issued by an independent certification body chosen by the client, and we influence neither the auditor's judgement nor the outcome. What we do is make sure the organisation meets the audit with a management system that is real, documented and in operation.

Four routes in

We work across four areas: information security under ISO/IEC 27001:2022, artificial intelligence governance under ISO/IEC 42001:2023, business continuity under ISO 22301:2019, and privacy under the GDPR and ISO/IEC 27701:2025. Each can be taken on its own or combined into a single integrated management system.

Three delivery levels

Some organisations need a structured assessment of where they stand today. Some want to own the work themselves with expert support along the way. Some want us to lead and carry out the bulk of it. We therefore offer a gap assessment, advisory support and full implementation as three self-contained routes. You can begin with one and move on to another, and they can be combined across a programme.

Integrated management systems

The standards share a structure. Organisational context, interested parties, leadership commitment, policies, objectives, roles, risk management, document control, competence, supplier management, measurement, internal audit, management review, nonconformity handling and improvement recur in all four. Build them separately and you build the same thing four times.

An integrated management system establishes the shared parts once and layers the standard-specific parts on top. That gives more coherent governance and less duplicated effort. How large the gain turns out to be depends on the starting point, and we do not quantify it in advance.

The Nordics as home market, international delivery

Berigo works primarily with organisations in Norway, Sweden, Denmark, Finland and Iceland, and knows Nordic governance culture, supervisory practice and ways of working. With the Nordics as its home market, Berigo also supports organisations internationally, and management systems can be built across several legal entities, locations and jurisdictions. We deliver in Norwegian and English.

Assessmentwhere we standDesignwhat it should look likeBuilddocuments and processesOperationthe system in useAuditindependent reviewBerigo can deliver the whole route or parts of itThe client owns the management system throughout
Figure: the route to a certification-ready organisation. Berigo can deliver the whole route or parts of it, and you own the management system throughout.
ISO/IEC 27001ISO/IEC 42001ISO 22301ISO/IEC 27701Shared governance foundationcontext, interested parties, leadership, policies, objectives, roles, risk, document controlcompetence, supplier management, measurement, internal audit, management review, improvement
Figure: an integrated management system establishes the shared parts once, and layers the standard-specific parts on top.

Choose your delivery level

Three ways into the same goal. You can start with one and move on to another.

Gap assessment

A structured assessment of where you stand today.

The gap assessment is for organisations that want to know what is missing before committing to anything more. We assess current governance and practice against the requirements of the standard, and deliver a picture you can act on. The assessment stands on its own, and commits you to nothing further.

Scope and price are set after an initial clarification.

What it covers

  • Scope clarification, so the assessment addresses the right part of the organisation
  • Review of existing governance and governance documentation
  • Interviews with relevant roles, from leadership to those doing the work
  • Assessment against the requirements of the standard
  • Assessment of operational practice, meaning what is actually done
  • Identification of gaps and weaknesses
  • Maturity assessment
  • Prioritisation of measures by risk and effort
  • A recommended road map
  • An executive summary

What you are left with

  • A gap assessment report
  • A prioritised action plan
  • An overview of critical gaps
  • A recommended implementation sequence
  • A basis for deciding and planning the next phase

What you contribute

  • Access to the documentation and systems to be assessed
  • Time from the roles to be interviewed
  • A contact person who can clarify along the way
Get in touch

Advisory support

You own and run the work. We stand alongside as your expert support.

Advisory support is for organisations that want to own and run the implementation themselves, but need expert assistance along the way. You keep project management and ownership of the documents. Berigo acts as expert adviser, quality assurer and sounding board.

Scope and price are set after an initial clarification.

What it covers

  • Ongoing advice throughout implementation
  • Expert quality assurance of choices and solutions
  • Review of documents you have prepared
  • Support to project management without taking it over
  • Support for risk assessments and methodology
  • Support for control design
  • Support for documentation and structure
  • Support for building internal competence
  • Periodic status meetings at an agreed cadence
  • Support when nonconformities and obstacles appear
  • Certification readiness support

What you are left with

  • A management system you have built yourselves, with expert backing
  • Internal competence that stays in the organisation
  • Documentation you know from the inside, because you wrote it
  • Confidence that the choices will withstand an audit

What you contribute

  • Project management and progress
  • Resources to prepare documentation and implement measures
  • Decisions that require management authority
  • Ownership of the management system
Get in touch

Full implementation

We lead and carry out the bulk of the work, together with you.

Full implementation is for organisations that want Berigo to lead and carry out the bulk of the work. We take project management, build the management system and bring it to a certification-ready state. The client still owns the management system, and some things can only be done by the organisation itself.

Scope and price are set after an initial clarification.

What it covers

  • Project management and a detailed project plan
  • Establishment of the management system, with structure and processes
  • Document development, both governance and operational documents
  • Process development fitted to how you work
  • Risk assessments and control mapping
  • Implementation support for process owners, risk owners and control owners
  • Training and awareness
  • Internal audit, organised with the necessary independence
  • Preparation and running of the management review
  • Certification readiness, including a readiness assessment
  • Support during the certification audit
  • Follow-up of findings and nonconformities after the audit

What you are left with

  • An operational management system in day-to-day use
  • Documentation fitted to the organisation rather than taken from a generic template
  • A completed internal audit and management review
  • An organisation prepared for stage 1 and stage 2
  • A plan for continued operation and improvement

What you contribute

  • Leadership commitment, with genuine priority
  • Relevant resources and time from key roles
  • The necessary decisions, taken in time
  • Ownership of the management system, including after the project ends
  • Implementation of organisational and technical measures in your own organisation
  • Adherence to the processes once they are established
Get in touch

Proven Executive Outcomes

M&A

Uncovered critical IT vulnerabilities in a major tech acquisition, securing deal value.

NIS2

Guided a Nordic critical infrastructure provider from limited visibility to board-approved NIS2 compliance in 6 months.