Start here · 1-2 days
A fast, low-risk snapshot of where you stand. We look at the artifacts an auditor checks first and hand back your top blockers and the single next step that matters most.
What actually blocks a certification - or a regulator
These are the blockers we find most often. None of them are exotic - which is exactly why they are missed until an auditor is in the room. The same gaps fail ISO 27001 Stage 1 and leave you exposed under DORA.
No usable Statement of Applicability
You are not ready for Stage 1. The SoA is a core part of the management system the auditor needs to examine.
Internal audit never performed
Your ISMS has not completed a required assurance loop. Expect this to become an audit issue.
No management review record
Leadership oversight is not evidenced. That is a management-system gap, not a paperwork detail.
Risk register does not map to the SoA
The control story breaks immediately: risks, treatment and selected controls no longer line up.
Access reviews that never happened
A policy cannot replace evidence that access was actually reviewed.
Backups exist, recovery never tested
“We have backups” is not proof that the business can recover.
We do not guarantee outcomes and we are not a certification body. What we do is find these before the auditor does - while there is still time to fix them cheaply.
Certification is performed by an accredited certification body through Stage 1 and Stage 2 audits. Kellwick prepares you for that process; it does not perform it and cannot guarantee its outcome.
Kellwick is an independent advisory practice. We are not a certification body and do not issue ISO certifications. Certification decisions are made only by accredited certification bodies.