ISO 27001
Enterprise customers and certification bodies increasingly demand ISO 27001. Kellwick finds what will block Stage 1 before the certification body does.
The blockers are almost never your company's technology. They are in the management system - the scope, the risk process, the Statement of Applicability, the internal audit and the evidence that controls actually operate.
Independent advisory practice · Not a certification body · Fixed scope, evidence-based delivery
Why now
Enterprise buyers and their procurement teams increasingly make ISO 27001 a requirement, not a nice-to-have. Security questionnaires ask for the certificate by name, deals stall in vendor review without it, and certification bodies expect a real management system when your team finally books the audit.
The risk is not that your infrastructure is insecure. Most teams that fail Stage 1 fail on the management system - a scope that does not hold together, a risk process that never ran, a Statement of Applicability that contradicts the risk register, an internal audit and management review that were never done. That is the ground a certification body checks first, and it is exactly where we look.
What ISO 27001 requires
Your team does not need to memorise the clauses. In practice a certification body wants to see these seven things working together - and evidence that they are more than documents.
A defined information security management system with a scope that matches your actual product, teams and infrastructure - not a copied template.
A repeatable way to identify, assess and treat information security risks, with a risk register that reflects real decisions rather than a one-off exercise.
A justified statement of which controls apply, which do not and why - the document that ties your risk decisions to the controls you actually run.
The relevant controls implemented and operating in practice: access, suppliers, change, incidents, secure development and the rest of your applicable set.
An internal audit programme that genuinely tests the management system, with findings and corrective actions - not a checkbox completed the week before Stage 1.
Leadership reviewing the ISMS on a cadence, with recorded decisions - the evidence a certification body checks first to see the system is actually governed.
Proof that the controls run continuously - access reviews, tested restores, incident records - not just policies that describe how they are supposed to work.
What actually blocks Stage 1
None of these are about your engineering. Each one can stop a Stage 1 audit on its own - better if we find them before the auditor does.
| The blocker | What it means for Stage 1 |
|---|---|
| No usable Statement of Applicability | You are not ready for Stage 1. The SoA is a core part of the management system the auditor needs to examine. |
| Internal audit never performed | Your ISMS has not completed a required assurance loop. Expect this to become an audit issue. |
| No management review record | Leadership oversight is not evidenced. That is a management-system gap, not a paperwork detail. |
| Risk register does not map to the SoA | The control story breaks immediately: risks, treatment and selected controls no longer line up. |
| Access reviews that never happened | A policy cannot replace evidence that access was actually reviewed. |
| Backups exist, recovery never tested | “We have backups” is not proof that the business can recover. |
What you get
Whichever engagement fits where you are, this is what the work actually produces.
The engagements
Start with a snapshot, find the blockers, close them and organise the proof. Each engagement stands alone or sequences into the next.
1-2 days
Your certification body will find these gaps. Better if we find them first.
Start with a Gap Review5-10 days
We tell you what will block ISO 27001 certification before the certification body does.
Explore this engagement3-6 weeks
Readiness finds the blockers. The Remediation Sprint helps remove them.
Explore this engagement1-2 weeks
We organise your ISO 27001 evidence so your team can show the right proof, in the right order.
Explore this engagementOngoing
Keep the ISMS running and stay ready across every framework - with a vCISO retainer once you are certified.
Explore vCISOWhat it costs
The path is priced step by step, and each step stands on its own. The entry review is credited toward the next one, so starting small costs nothing if you continue.
$1,250 fixed
The low-risk entry point: your top Stage 1 blockers, fast. The easiest way to find out whether a full assessment is even needed.
100% of the Mini Gap Review fee is credited toward a Readiness Assessment booked within 30 days.
Scoped on a call
The full picture before Stage 1: clauses 4-10 and Annex A, with a scored readiness result and a gap register ranked by audit impact.
What changes the price: Employee count · ISMS scope · Number of entities · Audit date · Current evidence quality
By size: up to 50 employees from $4,500; 51-150 from $6,000; 151-250 from $7,500; multiple entities or complex scope is custom.
Scoped on a call
Hands-on closure of the gaps between the assessment and the audit - scoped from real findings, never open-ended.
What changes the price: Number of open gaps · Policies and processes to fix · Quality of the existing SoA and risk register · Number of teams and control owners · Time to the audit
Scoped from the Readiness Assessment findings. We do not offer unlimited remediation on a flat fee.
Scoped on a call
The whole journey to your certification audit as one fixed-price outcome: readiness assessment, remediation and audit support - instead of buying three separate engagements.
What changes the price: Employee count and number of entities · How much needs building versus fixing · Time to the audit · Current evidence quality
One price for the whole path to the audit. The certification body's Stage 1 and Stage 2 fee is separate and quoted by them. Best for teams that want an outcome, not a stack of line items.
Scoped on a call
Your clause 9.2 internal audit, run by an auditor with no stake in the system being audited - with the report your management review actually needs.
What changes the price: Number of controls in your Statement of Applicability · Number of legal entities and sites in scope · How many control owners have to be interviewed · Whether the last audit left open nonconformities to verify
Independent by design: we do not audit an ISMS we built. Where we have done remediation for you, the audit is run by someone who did not do that work, and we say so in the report.
Scoped on a call
For already-certified teams: confirm you will pass surveillance before the auditor arrives - find the drift first.
What changes the price: Scope · Time since certification
Scoped on a call
A control-by-control evidence map and audit-ready index - the artifact most audits actually turn on.
What changes the price: Scope size · Current evidence quality
Every engagement is fixed-scope and fixed-price before it starts. Prices exclude taxes, certification-body fees, travel and third-party services, and are set on a short scoping call. All pricing.
Fit
This is for your company if
Not the right fit if
Regulated in the EU as well? See DORA readiness for what your licence adds on top of the certificate, or GDPR & privacy to extend the same ISMS into a defensible privacy programme.
The control system you build for ISO 27001 does the heavy lifting for DORA, NIS2, SOC 2 and NIST CSF 2.0 too - so you extend it rather than rebuild from zero.
ISO 27001 questions, answered
A clear, evidence-based view of where your ISMS stands and the one next step that matters most. Scoped on a short call.
Certification is issued by accredited certification bodies; DORA supervision is performed by regulators. Kellwick prepares you for these processes; it does not perform them and cannot guarantee their outcome.
Kellwick is an independent advisory practice. We are not a certification body and do not issue ISO certifications. Certification decisions are made only by accredited certification bodies.