Uncovered critical IT vulnerabilities in a major tech acquisition, securing deal value.
Get Certified: ISO/IEC 27001
A complete ISO/IEC 27001 implementation programme, from current state to a fully certified ISMS. Built for organisations that want real security, not a paper tiger.
Built for organizations that want real security, not a paper tiger.
The path to certification
- Gap Analysis & Strategy
- Implementation & Culture
- Audit Readiness
See the full process in detail
ISO/IEC 27001 Certification
A complete implementation programme, from current state to a fully certified ISMS. Built for organisations that want real security, not a paper tiger.
ISO/IEC 27001 is the world's most established framework for information security management systems. For organisations that need structure, maturity, documented governance and regulatory compliance, the standard is a strategic foundation, not only for technical security, but for the organisation's entire risk management and corporate control.
Berigo delivers complete ISO 27001 programmes, taking your organisation all the way from current state to certification. We produce all required documents, establish processes, facilitate risk assessments, implement controls, build competence, conduct internal audits and prepare the organisation for the external audit.
We can lead the entire process ourselves, or work closely with your organisation to ensure knowledge transfer. The goal is always the same: genuine improvement in information security, not a paper tiger.
Our approach is built on 30 years of experience spanning technical work, leadership, incident response, compliance, auditing and security director roles, combined with a PhD in cybersecurity leadership.
Why ISO 27001?
ISO 27001 gives your organisation a management system that creates lasting value:
Documented governance and control
The structure of the standard ensures that security is no longer ad hoc, but planned, measured and improved.
Real risk reduction
Risk management, systematic controls and maturity work lead to better decisions and less exposure.
Concrete demands from customers and suppliers
More and more organisations require certification in tenders, framework agreements and supply chains.
Support for EU requirements
ISO 27001 is directly relevant to NIS2, the AI Act, GDPR, DORA and the CRA.
Stronger preparedness
Controls, processes and exercises give the organisation the ability to handle incidents.
Reputation and trust
Certification is documented proof of quality and maturity.
How we work: a complete programme from A to Z
1. Pre-analysis and maturity assessment
- interviews
- document review
- technical assessment
- process mapping
- maturity model
- risk picture
This provides a clear starting point.
2. Gap analysis against ISO 27001
We assess the organisation against all requirements (clauses 4 to 10 and Annex A) and deliver:
- findings
- gaps
- impact
- prioritised actions
- project plan
3. Establishing the ISMS
We establish the structure of the management system:
- roles and responsibilities
- process ownership
- document management
- reporting
- committees and meeting structure
4. Producing all governing documents
We write or quality-assure everything the organisation needs, including policies, procedures, workflows and practice documents.
Mandatory documents
- ISMS scope
- ISMS policy
- Statement of Applicability (SoA)
- risk assessment
- risk methodology
- internal audit
- management review
Supporting procedures (selection)
- access management
- change management
- asset management
- logging and monitoring
- incident management
- emergency preparedness
- backup
- supplier management
- data classification
- DevSecOps / development lifecycle
Policies
- information security policy
- cloud policy
- encryption policy
- IA / AI governance policy
- supplier policy
- security-related HR policies
Everything is adapted to the organisation's culture, language and maturity.
5. Risk assessments
We conduct complete risk assessments based on ISO 27005, FAIR, NIST or the organisation's own methodology. The delivery includes:
- identification of assets
- analysis of threats and vulnerabilities
- assessment of likelihood and impact
- risk acceptance
- risk treatment
- prioritised action list
6. Control structure (Annex A)
We describe which of the 93 controls apply, how they should be implemented and how they are documented.
7. Implementation
We help the organisation to:
- establish processes
- carry out technical measures
- implement routines
- establish metrics
- anchor the work with senior management
- ensure proper reporting
- establish a control environment across the organisation
8. Training and competence
We provide targeted training for:
- management
- the board
- process owners
- HR
- IT/operations
- project teams
- the entire organisation (awareness)
Knowledge transfer is an integral part of the work.
9. Internal audit
We prepare the audit programme and conduct or lead the internal audit:
- interviews
- control testing
- findings
- audit report
10. Management review
We facilitate the entire process and prepare the report required by ISO 27001.
11. Preparing for the external audit
- audit simulation (mock audit)
- quality assurance
- document control
- clarification of roles
- training in audit dialogue
12. Support during the audit itself
We are at your side during Stage 1 and Stage 2 to ensure confidence, quality and professional responses.
After certification
We assist with:
- continual improvement
- annual audits
- document updates
- ISMS operations
- competence development
Flexible delivery model
1. Full delivery
We lead the entire project, produce all documents, drive implementation and deliver the organisation ready for certification. Ideal for organisations that need pace, capacity and quality.
2. Co-management
We lead, manage and quality-assure, while the organisation builds internally. Delivers strong knowledge transfer and strong internal ownership.
3. Guided model
The organisation does most of the work itself. Berigo provides methodology, templates, audit support and quality assurance. Ideal for organisations with strong internal resources, or for a longer timeline.
Tailored to your pace and goals
Fast track (3 to 6 months)
For organisations with time-critical requirements or a solid existing structure.
Standard track (6 to 12 months)
The most common model: a good balance of quality, progress and learning.
Extended track (12 to 24 months)
For organisations seeking cultural anchoring, maturity and lasting competence growth.
Real security value, not a paper tiger
We build a system that:
- works in practice
- improves the security level
- provides better governance
- gives management control
- supports the organisation's strategy
- withstands audits and regulatory scrutiny
- is understandable and usable
- is tailored, not generic
We are uncompromising on one point: ISO 27001 must deliver actual value and real improvement.
Knowledge transfer at the centre
We do not want your organisation to become dependent on us. That is why we:
- train key personnel
- coach process owners
- hand over all templates
- build maturity and understanding
- ensure the organisation owns its ISMS
The result is a solution that lives on long after certification.
What your organisation gains
- A certifiable and robust ISMS
- Documentation that withstands audits and regulatory scrutiny
- Reduced risk and increased control
- Anchoring across the entire organisation
- A stronger culture and greater competence
- Better governance from management
- Support for NIS2, GDPR, the AI Act, DORA and more
- A confident external audit
- Increased credibility in the market
- Efficient supplier management
- In short: a more robust, professional and predictable organisation
Get in touch
We offer a no-obligation introductory conversation to map:
- maturity
- ambitions
- possible models
- desired pace
- requirements from customers and regulators
- internal capacity
We then put together a programme fully tailored to your organisation.
Related services
CISO as a Service
Executive-level security expertise without building an in-house department. Berigo provides senior security leadership on par with group CISOs: flexible, scalable and cost-effective.
Incident Response and Preparedness
Preparedness is decided before the incident happens. Berigo helps boards and executive teams with response plans, exercises and procedures that meet NIS2 notification requirements.
Related news on this topic
Proven Executive Outcomes
Guided a Nordic critical infrastructure provider from limited visibility to board-approved NIS2 compliance in 6 months.
Is your Board ready for NIS2?
Download the 2026 Executive Checklist for Cyber Liability.
Your address is used to send you the guide, and handled as described in our privacy statement. privacy statement.