Discover
Security / quality baseline, context, interested parties, risk.
2–3 wksMethodology
Indicative 16–24 weeks. Moves with readiness, named owners, and multi-site complexity. Remote-first; on-site when a plant walkthrough or physical control cannot be evidenced on a call.
Security / quality baseline, context, interested parties, risk.
2–3 wksPolicies, procedures, SoA, control design, roles.
3–4 wksTraining, awareness, live operation of the system.
4–6 wksInternal audit, nonconformity close, management review.
3–4 wksMock certification. Gaps closed before the CB arrives.
2–3 wksStage 1 / Stage 2 handholding through certificate award.
1–2 wksPolicy set, procedures, work instructions, templates the process owner can run without us in the room.
Risk assessment and treatment. Statement of Applicability mapped to applicable controls — including all 93 for ISO 27001:2022 when that is in scope.
Role-based training and awareness. Attendance and comprehension on file.
Executed against the live system, not the binder. Findings tracked to close.
CB shortlist with relevant sector experience. Stage 1 and Stage 2 sitting with you.
Post-certification hypercare, then surveillance-year support as scoped.
Fixed project fee for the agreed scope. Certification-body fees are paid by you, directly to a NABCB-accredited body — typically a separate line. GST extra.
Ask for a scoped numberAdvance to open the file. Second tranche after documentation and internal audit. Close on successful certification. Exact splits sit in the engagement letter.