Your client asked for ISO 27001. Here is what that actually takes.
Gap assessment, risk treatment, policies people follow, and the evidence trail an auditor asks for, from the first workshop to the certification audit, and the year after it.
Engineering offices in Egypt, delivering on site across Egypt and Saudi Arabia, and supporting clients remotely across the Gulf, Africa, Europe and the United States.
Most people call. It is faster, and you speak to an engineer, not a form.
What a gap assessment looks at
Where certification projects go wrong
We are often brought in after a first attempt has stalled. It is nearly always one of these four, and none of them are about the standard being hard.
The scope is drawn too wide
Someone scopes the whole company on the first attempt. The workload triples, the timeline slips, and the certificate that the client actually asked for was only ever needed for one service line.
Policies nobody follows
A folder of documents bought or copied, describing a company that does not exist. Auditors test practice against policy, so a good policy nobody follows is worse than a modest one everybody does.
Evidence that does not exist
The control is real, but nothing records it happening. Access reviews done verbally, backups tested without a written result, incidents handled but never logged. On audit day it did not happen.
A consultant who leaves at the certificate
The certificate arrives, the consultant leaves, and nobody inside the business knows how to keep it. The first surveillance audit is then a crisis rather than a formality.
The programme, phase by phase
Timelines depend on your size and starting point, so we scope them with you rather than quoting a number here. What does not change is the order.
Scope and gap assessment
The cheapest decision in the whole programme, and the one most often rushed.
- Agree what the certificate is for, a client demand, a tender, or genuine risk
- Draw the scope to that need: entities, sites, systems, people
- Assess the current state against the standard, control by control
- Produce a ranked gap list with effort and owner against each item
- Identify what already exists and can be reused rather than rewritten
- Give you a realistic timeline before you commit budget
You get the gap report whether or not you continue with us.
Risk assessment and treatment
The risk register is the spine of the standard. Everything else hangs off it.
- An asset register that reflects what you actually run
- A risk methodology you can repeat without us in the room
- Risks owned by named people, not by “IT”
- Treatment decisions recorded, including the risks you accept
- A Statement of Applicability that matches your real controls
- Review cadence agreed and diarised
We write it with your people, so they can defend it in the audit interview.
Controls and documentation
Policies short enough to be read, and matched to how the business actually works.
- Policy set written to your operations, not a generic template pack
- Technical controls implemented and verified, not just documented
- Access control, joiners and leavers, and privileged account handling
- Supplier and third-party security requirements
- Business continuity and incident response, with named roles
- Awareness training that staff can complete without resenting it
Technical hardening runs alongside. See Cyber Security.
Evidence and internal audit
This is the phase that decides whether the external audit is calm or painful.
- Each control mapped to the record that proves it operating
- Evidence collected on a schedule, in one place, not hunted for in week one
- Internal audit run properly, with findings raised and closed
- Management review held and minuted
- Corrective actions tracked to completion
- A dry run of the questions the auditor will ask your staff
We would rather find a non-conformity ourselves than have the auditor find it.
Certification audit, and the year after
The certificate is a milestone, not the finish line. Surveillance audits come annually.
- Support through Stage 1 and Stage 2 with the certification body
- Findings answered with evidence, not argument
- Handover so your team can run the system without us
- An annual calendar: reviews, internal audit, management review, training
- Support for client security questionnaires as they arrive
- Ongoing help sized to what you need, not a permanent retainer by default
Day-to-day operation can sit inside Managed IT if you would rather not run it.
Environments held to somebody else’s standard
Real Stark programmes. Client identifiers are withheld under confidentiality. Sector and scope only.
ISO 27001, TISAX, PCI DSS and SOC
We have taken multiple client environments through ISO/IEC 27001, PCI DSS, SOC and TISAX, from the first gap analysis to the certification audit itself.
National data centre
Built and operated under strict security and confidentiality requirements, with access control and segmentation designed into the programme rather than retrofitted.
National e-payment platform
Web application firewall and network access control in front of a national payment service, monitored around the clock, the kind of environment where evidence is not optional.
Client security questionnaires
We help you answer supplier security assessments without overstating what is in place, which is the fastest way to lose a deal twice.
References can be provided directly, on request, with the client’s agreement.
Three things we will tell you not to do
The questions we get asked most
How long does ISO 27001 take?
It depends on your size, your scope and how much already exists, which is exactly why we will not quote a number before the gap assessment. What we will do is give you a realistic timeline and an effort estimate at the end of that assessment, before you commit any budget.
Is Stark Technology itself certified?
We are an implementation and consulting partner: we prepare and support client environments through certification, and we have taken multiple clients through ISO/IEC 27001, PCI DSS, SOC and TISAX. We do not claim to hold the certificate on your behalf, and no consultant can.
Do you also do the technical work, or only the paperwork?
Both, and that is the point of using us rather than a documentation-only consultancy. The same team implements the firewall rules, the identity controls, the patching and the backups that the standard requires, so the evidence is real rather than aspirational.
Can you help with TISAX, PCI DSS or a customer’s own questionnaire?
Yes. The management system underneath is largely the same; what changes is the control set and the evidence format. Enterprise security questionnaires are handled the same way. Accurately, without overstating.
What happens after we are certified?
Surveillance audits come round annually, so we hand over a calendar: risk reviews, internal audit, management review and training, with owners and dates. You can run it yourself, or we can carry it as part of a managed agreement. Either way you are not dependent on us to keep it.
Tell us which standard you have been asked for.
Ten minutes on the phone is usually enough to tell you how big the job really is, what you already have that counts, and whether you need the certificate at all.
Sunday to Thursday, 9am to 6pm · Egypt, and remote worldwide
Our other IT services
Every service below is delivered by the same team, under the same agreement.
