Compliance/02 - ISO 27001

Fast-track ISO 27001 certification - and stop losing global deals.

An ISMS that is actually operated, not a folder of templates. We run the risk treatment, carry the Annex A evidence, and take you through Stage 1 and Stage 2 with the certification body.

  • A real ISMS - risk register, treatment plan, internal audit, management review - operated by us
  • Statement of Applicability written from your risks, not copied from a sample
  • Annex A evidence collected continuously and held fresh through surveillance audits
Trusted by teams shipping in regulated markets
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess

A management system, not a binder.

ISO 27001 certifies that you operate an information security management system - so auditors look for evidence it ran, not evidence it exists. That distinction is where most programs fail.

The ISMS is operated, not filed

Risk assessments get re-run, corrective actions get closed, internal audits actually happen, and management review produces decisions with dates on them.

- clauses 4-10 - evidenced

A Statement of Applicability you can defend

Every Annex A control is included or excluded against a documented risk and justification. Exclusions are the first thing an auditor probes, so we write them to survive that.

- 93 controls - reasoned

Maps onto SOC 2 without doubling the work

The controls overlap heavily. Evidence collected once satisfies both programs, so adding the second framework costs a fraction of the first.

- shared evidence, mapped

Certification body, handled

We help you select an accredited body, prepare the Stage 1 documentation review, and work the Stage 2 findings to closure - then keep you ready for surveillance.

- stage 1 + stage 2 + surveillance

What ISO 27001 actually requires.

The certifiable requirements are in clauses 4 through 10. Annex A is the control catalogue you select from - 93 controls in four themes under the 2022 revision.

Context & scope

clause 4

Interested parties, ISMS boundaries, and what is deliberately outside them. Scope decides the cost of everything downstream.

Leadership & policy

clause 5

Top-management commitment, the information security policy, and assigned roles with real authority.

Risk assessment & treatment

clause 6 - SoA

A repeatable risk method, a populated risk register, treatment decisions, and the Statement of Applicability that falls out of them.

Annex A controls

93 controls

Organizational (37), People (8), Physical (14), and Technological (34). You apply the ones your risk treatment calls for and justify what you exclude.

Performance & internal audit

clause 9

Monitoring, measurement, a genuine internal audit programme, and management review with recorded outputs.

Certification cycle

3-year cycle

Stage 1 documentation review, Stage 2 certification audit, then annual surveillance audits and full recertification in year three.

We scope to ISO/IEC 27001:2022 and the restructured Annex A. ISO 27017 and ISO 27018 extensions can ride on the same ISMS when cloud or PII-processor commitments call for them.

From scoping call to certificate.

Two phases are gated - ISMS scoping and the certification audit. Getting scope wrong is the single most expensive mistake in an ISO programme, so we hold that line hard.

Phase 01 - gated

Scope the ISMS

We fix the boundary - which entities, systems, locations, and people are in. Too wide and you evidence things forever; too narrow and your customers reject the certificate.

Boundary locked - parties mapped
Phase 02

Risk assessment and SoA

We run the risk assessment, agree treatment, and write the Statement of Applicability from the results - including the justification behind every excluded Annex A control.

Risk register - SoA signed
Phase 03

Operate and evidence

Controls get implemented and then actually run. Internal audit, corrective actions, and management review generate the operating evidence Stage 2 asks to see.

ISMS operating - audit trail
Phase 04 - gated

Stage 1, Stage 2, certificate

The body reviews documentation, then audits operation. We work nonconformities to closure and keep you ready for the surveillance audit twelve months later.

Certificate issued - surveillance ready
Pricing

ISO 27001 is $3,000 a year.
The security department is the rest.

Every other vendor in this category makes you book a demo to learn what ISO 27001 costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.

Startup plan + ISO 27001
$20,000 / year

For companies under $5M revenue or 50 staff. The whole department, included.

  • Penetration testing
  • Vulnerability management
  • Monitoring & detection 24/7
  • Incident response
  • Compliance & GRC support
  • A named human on call
  • The Sythe Labs platform, run by us
+ $3,000 / yr for ISO 27001 - scoping, evidence, gap closure, and the path to an accredited certificate. Add other frameworks at the same rate, only when you need them.
Book a call
Enterprise
Custom

Over $5M revenue or 50 staff. Negotiated to your scale and obligations.

  • Everything in Startup
  • Dedicated security lead
  • Custom SLAs & response times
  • Audit & board reporting
  • Scaled to your headcount
  • Procurement & MSA support
Talk to us
IncludedISO 27001 does not mandate a penetration test by name, but Annex A technical controls and most certification bodies expect one. Yours is already in the flat plan.
Compliance billed per framework - no per-seat fees, ever. Auditor and certification-body fees are billed by them, not by us.

The people who already handed it over.

"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
EchoWin
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
Maru AI
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Naked Denver

ISO 27001, honestly answered.

The questions that come up on every ISO 27001 scoping call, answered before you have to ask them.

How long does ISO 27001 certification take?
Three to six months is realistic for a company with reasonable engineering hygiene. The binding constraint is operating evidence - certification bodies want to see the ISMS having actually run, not just documented.
Do you issue the certificate?
No. Certificates come from an accredited certification body, and independence is the entire value of the certificate. We build and operate the ISMS, prepare you, and work the findings.
Is the certification body's fee included?
No. The $3,000/yr covers our work running the programme. The body bills separately for Stage 1, Stage 2, and each annual surveillance audit. We will give you the realistic range up front.
We already have SOC 2. How much extra is ISO 27001?
Less than the first one, materially. The control sets overlap heavily and evidence collected once maps to both. What ISO adds is the management-system machinery - risk method, internal audit, management review - which SOC 2 does not require in the same form.
What changed in the 2022 revision?
Annex A was restructured from 114 controls in 14 domains to 93 in four themes, with 11 new controls covering things like threat intelligence, cloud services, and secure coding. We scope to the current revision.

Certified, and still certified next year.

A 30-minute call. We will tell you what your ISMS scope should be, what Stage 2 will actually probe, and what the path to a certificate costs - whether or not you hire us.