Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
ISO 27001 · Implementation

ISO 27001 implementation

Most companies reach for ISO 27001 because a European or global buyer asked for it. This is a plain-language guide to what the standard actually is, the steps to get certified, a realistic timeline, and what it costs.

Book a discovery call

We are a Toronto prep partner: we get you ready and coordinate the certification body, so you walk into the audit prepared.

What ISO 27001 actually is

Key takeaway: ISO 27001 certifies that you run an information security management system, an ISMS. An accredited registrar, also called a certification body, audits you against the standard and issues the certificate if you pass.

ISO 27001 is an international standard for running an information security management system, usually shortened to ISMS. An ISMS is not a document or a tool. It is the ongoing set of policies, processes, and controls you use to keep information secure, plus the habit of measuring and improving them. The standard describes what that system has to include, and an accredited registrar, also called a certification body, audits you against it and issues the certificate if you pass.

The word certificate matters. Unlike SOC 2, which produces an attestation report signed by a CPA firm, ISO 27001 produces a certificate granted by a registrar. Both prove you take security seriously, but they come from different worlds. If you want the full comparison, read our guides on SOC 2 and ISO 27001 for startups and SOC 2 versus ISO 27001. The short version: SOC 2 is the North American default, ISO 27001 is what the rest of the world tends to ask for, and the controls underneath them overlap a great deal.

How ISO 27001 implementation works, step by step

Key takeaway: Certification is a defined sequence. You build the management system, prove to yourself that it works, and then the registrar checks it in two stages.

Here is the whole path, stage by stage, with a short note on what each stage produces.

Stage 01

Scope the ISMS

Decide what the management system covers. Scope drives everything after it, including cost, so getting this right early keeps the project honest.

  • Which products are in and out
  • Which teams are in and out
  • Which locations are in and out
  • Which systems are in and out
Stage 02

Risk assessment and risk treatment plan

Identify the risks to the information in scope, and judge how likely and how damaging each one is. That set of decisions becomes your risk treatment plan, which is the backbone of an ISO 27001 program.

  • Reduce the risk
  • Accept the risk
  • Transfer the risk
  • Avoid the risk
Stage 03

Statement of Applicability (SoA)

Work through the Annex A controls and record your choices. The SoA is the document a registrar reads first, because it maps your risks to the controls you have chosen to put in place.

  • Which Annex A controls apply to you
  • Which ones do not, and why
  • How each risk maps to the controls you have chosen
Stage 04

Implement the controls

Put the Annex A control themes into practice across organizational, people, physical, and technological areas. This is where readiness turns into real, working security rather than paperwork.

  • Access control
  • Change management
  • Logging and monitoring
  • Supplier and vendor management
  • Secure development
  • Incident response
Stage 05

Internal audit and management review

Before the registrar shows up, you audit yourself. Both are required by the standard, not optional extras.

  • An internal audit that checks the ISMS is actually operating
  • A management review that puts the results in front of leadership
  • A record so decisions and improvements are captured
Stage 06

Stage 1 audit (documentation)

The registrar reviews your documentation to confirm you are ready. Think of it as a readiness check that surfaces gaps before the real thing.

  • Your ISMS documentation
  • Your defined scope
  • Your Statement of Applicability
  • Your risk work
Stage 07

Stage 2 audit (certification)

The registrar tests whether your controls are working in practice. Pass it and the certificate is issued.

  • Evidence gathered that controls operate
  • Interviews with your team
  • The certificate issued on a pass
  • Yearly surveillance audits after that to keep it valid

Stage 1 and Stage 2 audits compared

What to compareStage 1 auditStage 2 audit
FocusDocumentation and readinessControls working in practice
What the registrar doesReviews your ISMS documentation, scope, SoA, and risk workGathers evidence and interviews your team
PurposeConfirms you are ready and surfaces gaps before the real thingTests whether the controls actually operate
OutcomeA readiness check, no certificate yetPass and the certificate is issued, then yearly surveillance audits

How long it takes

Key takeaway: ISO 27001 certification commonly takes several months from start to certificate, including the Stage 1 and Stage 2 audits. Your scope, the gaps the analysis finds, and the certification body's schedule set the pace.

ISO 27001 certification commonly takes several months from start to certificate, including the Stage 1 and Stage 2 audits. What drives it is the gaps the analysis finds, the size of your scope and the certification body's schedule. Older or more complex environments, or a wide scope, push it out.

In terms of effort, ISO 27001 is comparable to a first SOC 2, but it leans more heavily on documentation. SOC 2 is largely about showing evidence against a set of trust criteria. ISO 27001 asks you to stand up a formal ISMS, produce a risk treatment plan, write the Statement of Applicability, and run an internal audit before the registrar ever arrives. None of that is hard on its own, but it is more process, so building it with someone who has done it before saves weeks.

What it costs

Key takeaway: Two costs sit side by side and stay separate. The registrar charges its own audit fees, which we do not quote. Readiness is our part, priced as a fixed scope. Optional compliance tooling is a smaller third line.

There are two clearly separate costs, and it helps to keep them apart in your head. The first is the registrar, or certification body, which runs the Stage 1 and Stage 2 audits and the yearly surveillance audits after that. Registrar fees are usually priced in USD and scale with the size and complexity of your scope, so a small, focused scope costs meaningfully less than a broad one. We do not quote the registrar; they are independent from us by design.

The second cost is readiness, which is our part. We price it as a fixed scope so you know the number before you start, rather than an open hourly meter. On top of those two, some teams add compliance tooling to automate evidence collection, which is a smaller, optional line item. For a broader way to think about compliance budgets, our guide to SOC 2 cost uses the same logic that applies here.

Honest note: we do not publish a single sticker price for ISO 27001, because it depends almost entirely on your scope. Anyone quoting a firm number before they understand your scope is guessing.

If you already have SOC 2 (or want both)

Key takeaway: ISO 27001 and SOC 2 share a large amount of underlying work, so if you have done one, you are not starting the other from zero.

ISO 27001 and SOC 2 share a large amount of underlying work. Access control, change management, risk assessment, vendor management, and logging and monitoring show up in both. If you have done one, you are not starting the other from zero. The evidence, policies, and control implementations you built the first time carry over, so the second framework is mostly about reframing what you have and filling the gaps that are genuinely specific to it.

The work that shows up in both:

  • Access control
  • Change management
  • Risk assessment
  • Vendor management
  • Logging and monitoring

That is why teams who expect to need both often plan for it up front and build the evidence once. We walk through exactly how the two line up in our guide on SOC 2 and ISO 27001 for startups.

How traztech helps

Key takeaway: TrazTech is a prep partner, not the registrar. We build the ISMS and coordinate the certification body, but only an accredited registrar issues the certificate.

Be direct about the stakes, because ISO is stricter than SOC 2. Stage 2 findings are graded: a minor comes with a corrective action window, a major nonconformity withholds the certificate until you remediate and the body verifies the fix, at audit days you pay for. You can sit Stage 2 and leave without a certificate.

The majors are predictable, which is the useful part. Those are absences, and absences are what readiness is for.

We are a prep partner, not the registrar. What we do not do is issue the certificate, because keeping readiness and certification separate is how ISO 27001 is meant to work. What we do:

  • Build the ISMS with you
  • Run the risk assessment and risk treatment plan
  • Draft the Statement of Applicability
  • Implement the Annex A controls
  • Run your internal audit and management review
  • Coordinate the certification body through Stage 1 and Stage 2

What makes us different is that we are unusually technical about it. Our principal is a published security researcher with five published CVEs, including CVE-2024-45163 (CVSS 9.1), the kill-switch for the Mirai botnet, so the controls we build hold up when a buyer or an auditor starts poking at them. We quote fixed scope, and because we are Canadian, we handle the PIPEDA and Quebec Law 25 overlap so you do not build the same evidence twice.

Get ISO 27001 ready with a partner who has done it

Tell us your scope, your deadline, and which buyer is asking. We will map the path, quote a fixed scope, and coordinate the registrar so certification is a formality, not a scramble.

Start your ISO 27001 prep

Frequently asked questions

Do we need ISO 27001 or SOC 2?

It usually comes down to who is asking. North American buyers tend to ask for a SOC 2 report, while European and global buyers tend to ask for an ISO 27001 certificate. If your customers are naming ISO 27001 in security questionnaires or contracts, that is your answer. Many companies eventually do both, because the underlying controls overlap heavily and evidence you build for one carries into the other.

How long does ISO 27001 take?

ISO 27001 certification commonly takes several months, including the Stage 1 and Stage 2 audits. What drives it is the gaps the analysis finds, the size of your scope and the certification body's schedule. The effort is comparable to a first SOC 2, but ISO 27001 is more documentation-heavy because you have to stand up a formal ISMS, a risk treatment plan, and an internal audit.

How much does ISO 27001 certification cost?

There are two separate costs. The registrar, or certification body, charges its own fee for the Stage 1 and Stage 2 audits and the yearly surveillance audits after that. Those fees are usually priced in USD and scale with the size and complexity of your scope. Separately, readiness work is a fixed-scope fee that we quote up front. Optional compliance tooling is a third, smaller line item. We do not publish a single number because it depends entirely on your scope.

Can you fail an ISO 27001 audit?

Yes, more directly than a SOC 2. Stage 2 findings are graded. A minor nonconformity comes with a corrective action window and does not block certification. A major nonconformity means the certificate is not issued until you remediate and the certification body verifies the fix, at additional audit days you pay for. You can sit Stage 2 and leave without a certificate. The usual causes are an undefined ISMS scope, a Statement of Applicability with unjustified exclusions, an internal audit that never ran, and a management review with no record behind it. More on what goes wrong.

Do you issue the certificate?

No. The ISO 27001 certificate is issued by an accredited registrar, also called a certification body, and only they can grant it. We are your prep partner. We build the ISMS, close the gaps, run the internal audit, and coordinate the registrar so the Stage 1 and Stage 2 audits go smoothly. Keeping readiness and certification separate is how the standard is meant to work.

Is ISO 27001 harder than SOC 2?

It is not harder so much as more formal. SOC 2 is a set of trust criteria you show evidence against. ISO 27001 asks you to run an actual management system: define scope, assess risk, write a risk treatment plan, produce a Statement of Applicability, and audit yourself before the registrar audits you. The technical controls overlap a lot, but the paperwork and process discipline are heavier.

Walk every ISO 27001 control yourself

traztech Workspace has all 93 Annex A controls and 25 ISMS clauses (4-10) of ISO 27001 written in plain English, with what the standard asks for, what to do about it, and somewhere to attach the proof. You answer them, it scores you, and nothing is locked behind an upgrade.

No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote A documented readiness position the audit firm can scope and price against Nothing. The audit firm prices your readiness, not your tooling

Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.

Comparing providers? A consultant cannot issue you a certificate, and much of this market is marketed as though they can: how the Toronto ISO 27001 market actually works.

Track record

Who is actually doing the work

We would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.

The platform stayed in production throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.