What the file actually contains

System documentation

Policy set, procedures, work instructions, templates the process owner can run without us in the room.

Risk & SoA

Risk assessment and treatment. Statement of Applicability mapped to applicable controls — including all 93 for ISO 27001:2022 when that is in scope.

Competence

Role-based training and awareness. Attendance and comprehension on file.

Internal audit

Executed against the live system, not the binder. Findings tracked to close.

Certification support

CB shortlist with relevant sector experience. Stage 1 and Stage 2 sitting with you.

After the frame

Post-certification hypercare, then surveillance-year support as scoped.

Commercial shape

Fixed project fee for the agreed scope. Certification-body fees are paid by you, directly to a NABCB-accredited body — typically a separate line. GST extra.

Ask for a scoped number

Usual rhythm

Advance to open the file. Second tranche after documentation and internal audit. Close on successful certification. Exact splits sit in the engagement letter.