Fast-track ISO 27001 certification - and stop losing global deals.
An ISMS that is actually operated, not a folder of templates. We run the risk treatment, carry the Annex A evidence, and take you through Stage 1 and Stage 2 with the certification body.
- A real ISMS - risk register, treatment plan, internal audit, management review - operated by us
- Statement of Applicability written from your risks, not copied from a sample
- Annex A evidence collected continuously and held fresh through surveillance audits















A management system, not a binder.
ISO 27001 certifies that you operate an information security management system - so auditors look for evidence it ran, not evidence it exists. That distinction is where most programs fail.
The ISMS is operated, not filed
Risk assessments get re-run, corrective actions get closed, internal audits actually happen, and management review produces decisions with dates on them.
A Statement of Applicability you can defend
Every Annex A control is included or excluded against a documented risk and justification. Exclusions are the first thing an auditor probes, so we write them to survive that.
Maps onto SOC 2 without doubling the work
The controls overlap heavily. Evidence collected once satisfies both programs, so adding the second framework costs a fraction of the first.
Certification body, handled
We help you select an accredited body, prepare the Stage 1 documentation review, and work the Stage 2 findings to closure - then keep you ready for surveillance.
What ISO 27001 actually requires.
The certifiable requirements are in clauses 4 through 10. Annex A is the control catalogue you select from - 93 controls in four themes under the 2022 revision.
Context & scope
clause 4Interested parties, ISMS boundaries, and what is deliberately outside them. Scope decides the cost of everything downstream.
Leadership & policy
clause 5Top-management commitment, the information security policy, and assigned roles with real authority.
Risk assessment & treatment
clause 6 - SoAA repeatable risk method, a populated risk register, treatment decisions, and the Statement of Applicability that falls out of them.
Annex A controls
93 controlsOrganizational (37), People (8), Physical (14), and Technological (34). You apply the ones your risk treatment calls for and justify what you exclude.
Performance & internal audit
clause 9Monitoring, measurement, a genuine internal audit programme, and management review with recorded outputs.
Certification cycle
3-year cycleStage 1 documentation review, Stage 2 certification audit, then annual surveillance audits and full recertification in year three.
We scope to ISO/IEC 27001:2022 and the restructured Annex A. ISO 27017 and ISO 27018 extensions can ride on the same ISMS when cloud or PII-processor commitments call for them.
From scoping call to certificate.
Two phases are gated - ISMS scoping and the certification audit. Getting scope wrong is the single most expensive mistake in an ISO programme, so we hold that line hard.
Scope the ISMS
We fix the boundary - which entities, systems, locations, and people are in. Too wide and you evidence things forever; too narrow and your customers reject the certificate.
Risk assessment and SoA
We run the risk assessment, agree treatment, and write the Statement of Applicability from the results - including the justification behind every excluded Annex A control.
Operate and evidence
Controls get implemented and then actually run. Internal audit, corrective actions, and management review generate the operating evidence Stage 2 asks to see.
Stage 1, Stage 2, certificate
The body reviews documentation, then audits operation. We work nonconformities to closure and keep you ready for the surveillance audit twelve months later.
ISO 27001 is $3,000 a year.
The security department is the rest.
Every other vendor in this category makes you book a demo to learn what ISO 27001 costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.
The people who already handed it over.
"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Real engagements. Real outcomes.
The same programme, run for teams who had no security function when they started.
A four-person team with payment data, no security function, and a Series A closing.
Read the case studyechowinHIPAA attestation held and SOC 2 underway, with the whole department owned by us.
Read the case studyThe Academy of Charter SchoolsA penetration test their IT team rode along on, plus a roadmap of what to harden.
Read the case studyISO 27001, honestly answered.
The questions that come up on every ISO 27001 scoping call, answered before you have to ask them.
- How long does ISO 27001 certification take?
- Three to six months is realistic for a company with reasonable engineering hygiene. The binding constraint is operating evidence - certification bodies want to see the ISMS having actually run, not just documented.
- Do you issue the certificate?
- No. Certificates come from an accredited certification body, and independence is the entire value of the certificate. We build and operate the ISMS, prepare you, and work the findings.
- Is the certification body's fee included?
- No. The $3,000/yr covers our work running the programme. The body bills separately for Stage 1, Stage 2, and each annual surveillance audit. We will give you the realistic range up front.
- We already have SOC 2. How much extra is ISO 27001?
- Less than the first one, materially. The control sets overlap heavily and evidence collected once maps to both. What ISO adds is the management-system machinery - risk method, internal audit, management review - which SOC 2 does not require in the same form.
- What changed in the 2022 revision?
- Annex A was restructured from 114 controls in 14 domains to 93 in four themes, with 11 new controls covering things like threat intelligence, cloud services, and secure coding. We scope to the current revision.
Certified, and still certified next year.
A 30-minute call. We will tell you what your ISMS scope should be, what Stage 2 will actually probe, and what the path to a certificate costs - whether or not you hire us.