Cybersecurity / Certification Readiness

ISO 27001 and ISO 27701 Certification Readiness

Most ISO 27001 projects fail in the same four places: a scope drawn too wide to defend, a risk method invented once and abandoned, a document set written for an auditor instead of for the people doing the work, and a certification date agreed before anyone counted the effort. We run the implementation with you and avoid all four.

Gap analysis, scope and risk methodology Statement of Applicability and control implementation Internal audit, management review and stage 1 preparation
Overview

ISO 27001 & 27701 Certification Readiness

What it is

An implementation engagement that takes an organisation from wherever it is now to the point where a certification body can audit it, covering ISO 27001 for information security and ISO 27701 where privacy certification is also in scope.

Why organisations need it

ISO 27001 has become a procurement question rather than a security aspiration. Tenders require it, enterprise customers ask for it in security reviews, and group parents mandate it. The organisations that struggle are rarely the ones with weak security. They are the ones who treated a management system as a documentation exercise.

Key features

What the engagement covers

Sized to your starting point. An organisation with mature security and no management system needs different work from one starting with neither.

Gap analysis and readiness assessment

Where you stand against every clause and every applicable Annex A control, with the gaps ranked by the effort to close them and the risk of leaving them. This is what turns a certification ambition into a costed plan.

Scope definition

The decision that determines cost, timeline and how much the certificate is actually worth to a customer. We draw a scope that is defensible to an auditor and meaningful to your buyers, and document the interfaces and dependencies that come with it.

Risk methodology and assessment

A repeatable risk assessment method with criteria your board has agreed, then the assessment itself: assets, threats, risk owners, evaluation and treatment decisions, producing a register that will still make sense next year.

Statement of Applicability and controls

Selecting controls against treatment decisions, justifying inclusions and exclusions, and implementing what is missing across the organisational, people, physical and technological themes. Existing controls are mapped rather than rebuilt.

Documentation and operating rhythm

The policies, procedures and records the standard actually requires, written for the people who have to follow them. Then the recurring calendar that makes the system operate: risk review, awareness, supplier review, internal audit and management review.

Internal audit and stage 1 preparation

Running the internal audit and management review the standard requires before certification, closing the findings, and preparing your people for what the external auditor will ask them.

Business value

What the business gets out of it

The certification date is realistic

Effort is estimated against your actual gap rather than a generic timeline, so the date you commit to a customer is one you can meet.

The scope is defensible and useful

A narrow scope that excludes what customers care about passes the audit and fails the sales conversation. Getting this right the first time avoids a costly re-scope later.

You are not left with a system nobody runs

The operating calendar, owners and templates are handed over deliberately, because a management system that depends on the consultant collapses at the first surveillance audit.

Privacy certification comes almost free

ISO 27701 extends the same management system. Organisations pursuing both together spend far less than those that certify separately eighteen months apart.

It answers the security questionnaire too

Most of what an enterprise customer's security review asks for is evidence the ISMS already produces, so the questionnaire burden drops once the system operates.

Existing work counts

Organisations that hold SOC 2, or that run BNM RMiT or PDPA programmes, already satisfy a substantial share of the requirements. We map what exists before proposing anything new.

How it works

How the engagement runs

01

Gap analysis

Assessment against the clauses and applicable controls, producing a ranked gap register and a costed implementation plan with a realistic certification date.

02

Scope and mandate

Fixing the scope statement, confirming leadership commitment and interested party requirements, and standing up the project team.

03

Risk methodology and assessment

Designing the method, running the assessment, agreeing risk acceptance criteria and producing a prioritised risk register with named owners.

04

Control implementation

Closing gaps across the four control themes, with your team implementing and us sequencing the work so evidence accumulates early.

05

Documentation and operation

Producing the required documented information and starting the operating rhythm, so there is a real audit trail before the auditor arrives.

06

Internal audit and certification support

Internal audit, management review, corrective action, then support through stage 1 and stage 2 including attendance where useful.

Deliverables

What you receive

Gap analysis and implementation plan

Clause and control gap register, ranked, costed and sequenced against a certification date.

Scope statement and context analysis

The documented scope, interested parties and their requirements, and the interfaces and dependencies.

Risk methodology and risk register

The documented method, criteria, and a populated register with owners and treatment decisions.

Statement of Applicability

Every control with an inclusion or exclusion decision and the justification an auditor will test.

Policy and procedure set

The documented information the standard requires, written to be usable rather than to be filed.

Internal audit and management review records

Completed audit reports, nonconformities, corrective actions and the management review record needed before stage 1.

Who it is for

Who this is built for

Industries

Technology and SaaSFinancial servicesBusiness process outsourcingHealthcareLogisticsProfessional servicesManufacturingGovernment suppliers

Company sizes

Startups pursuing enterprise customersSMEsMid-marketLarge enterpriseMalaysian subsidiaries of foreign groups

Departments

IT and securityCompliance and riskLegalOperationsExecutive leadership
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

How long does certification take?

For a mid-sized organisation with reasonable security already in place, six to nine months from gap analysis to stage 2 is realistic. Starting from nothing, or with a wide multi-site scope, extends that. Anyone promising three months is either working with a tiny scope or planning to write documents nobody will follow.

Can you also certify us?

No. Certification must come from an accredited certification body that is independent of the implementation. We prepare you and support you through the audit, and we will help you select a certification body, but the certificate itself comes from them.

We already have SOC 2. Does that help?

Considerably. The control overlap is substantial and much of your evidence already exists. What SOC 2 does not give you is the management system layer: context, scope, risk methodology, internal audit and management review. That is usually where the remaining work sits.

What does scope actually change?

Cost, timeline and commercial value. A scope covering one product line is faster and cheaper to certify but may not satisfy a customer asking about the service they buy. We work the scope decision through commercially, not only technically.

Do we need ISO 27701 as well?

Only if your buyers or regulators are asking about privacy specifically. It extends the same system, so doing both together is far cheaper than adding it later. For organisations whose main obligation is the Malaysian PDPA, a well-run privacy programme is sometimes sufficient without certification.

Who does the actual work, us or you?

Both, deliberately. We run the analysis, methodology, documentation and audit preparation. Your team implements the controls and operates the system, because a management system your people did not build is one they will not run after we leave.

What happens after certification?

Surveillance audits, usually annually, and recertification on a three year cycle. The handover includes the calendar and templates for that. Organisations wanting ongoing support usually move to a vCISO arrangement.

Get started

Find out how far you actually are

Tell us your headcount, what you do, and what triggered this, whether that is a tender, a customer security review, a group mandate or a board decision. We will come back with scope, a realistic certification date and a fixed quotation for the gap analysis.