ISO 27001
Certification Audit Support
A certification audit is the first time the management system is examined by someone with no stake in it. Stage 1 tests whether the documentation is coherent; Stage 2 tests whether what it describes is actually happening. Most organisations are ready for one and not the other, and find out at the worst moment. This is the engagement that separates those two questions and answers them before the auditor does.
Methodology
- 01
Readiness Review
Establish where the management system stands against what Stage 1 and Stage 2 each examine.
- 02
Stage 1 Readiness
Documentation review readiness — scope, policy, risk methodology, Statement of Applicability and the mandatory records.
- 03
Mock Audit
A pre-certification dry run under real audit conditions, so the first time anyone is asked an audit question is not in the audit.
- 04
Stage 2 Readiness
Implementation audit readiness — control owners, live evidence and the ability to demonstrate operation rather than intent.
- 05
Certification Body Liaison
Coordination with the certification body is managed on the client's behalf.
- 06
Audit Attendance
Present through Stage 1 and Stage 2, so questions are answered in the room.
- 07
Non-Conformity Remediation
Fast, structured closure of findings, tracked to the certification body's satisfaction.
Approach to testing
- Requirement — what does the applicable standard, regulation or framework require?
- Control — what control has the organisation established?
- Implementation — how is the control actually implemented?
- Evidence — what evidence demonstrates that the control operates?
- Risk — what happens if the control is ineffective or absent?
- Action — what needs to be changed?
- Validation — has the corrective action actually addressed the issue?
Types of assessment
Black-Box
Assessment begins with limited organisational information, to provide an independent perspective of the governance environment.
Grey-Box
Selected organisational documentation, process information and evidence are provided for structured assessment.
White-Box
Full documentation, evidence, stakeholder and process access is provided for detailed control validation.
Hybrid
Combines independent assessment techniques with detailed evidence and stakeholder validation.
Frameworks and standards
- ISO/IEC 27001:2022
- The standard the certification audit is conducted against.
- ISO/IEC 27002:2022
- Control guidance underpinning the Annex A sample.
- ISO/IEC 17021
- The requirements certification bodies themselves work to, which is what makes Stage 1 and Stage 2 predictable.
- CSS Internal Audit Toolkit
- The mock audit is run from the same checklist an internal audit uses.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
CSS Internal Audit Toolkit
Mock audit planning, checklists, findings and corrective action tracking.
CSS ISO 27001 Toolkit
Documentation completeness check against the mandatory set.
PlyoGRC
Where appropriate, findings and corrective actions are tracked as controlled records through to closure.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Stage 1 — documentation readiness
- ISMS scope statement consistent with what is actually operated
- Information Security Policy approved and current
- Risk assessment and treatment methodology defined
- Statement of Applicability complete, with exclusions justified in writing
- Risk Treatment Plan traceable to the risk assessment
- Internal audit programme and results available
- Management review records available
Stage 2 — implementation readiness
- Every applicable control has a named, accountable owner
- Control owners can describe their control without referring to the policy
- Live evidence exists and is retrievable within the audit window
- Monitoring and measurement results demonstrate operation over time
- Corrective actions from the internal audit are closed
- Competence evidence exists for the roles the ISMS depends on
Audit management
- Certification body selected and scheduled
- Audit plan reviewed and scope confirmed
- Interviewees identified and prepared
- Evidence pack assembled and indexed
- Non-conformities classified, owned and tracked
- Corrective action evidence submitted within the required window
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Framework Mapping Agent — maps requirements and controls across applicable frameworks.
Policy Analysis Agent — identifies potential missing, inconsistent or outdated requirements.
Evidence Analysis Agent — associates evidence with applicable controls and identifies evidence gaps.
Risk Analysis Agent — identifies recurring risk themes and potential control weaknesses.
Blind-Spot Detection Agent — looks for issues that may not be immediately visible through conventional checklist assessment.
Executive Reporting Agent — helps transform detailed assessment information into concise management reporting.
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
We stay in the room
Through Stage 1, Stage 2 and every finding. Readiness advice delivered by email and withdrawn before the audit is the point at which most support engagements stop being useful.
Mock audit under real conditions
A dry run before the certification body arrives, so the first time a control owner is asked to evidence their control is not in front of an auditor.
Stage 1 and Stage 2 assessed separately
They test different things — documentation coherence and demonstrated operation. Organisations are routinely ready for one and not the other, and a combined readiness score hides which.
Operating control, not documentation only
Evidence is validated across five stages: Designed — is it appropriately designed? Implemented — has it been implemented? Operating — is it actually performed? Evidenced — can operation be shown? Effective — is it achieving its goal?
Human-in-the-loop AI assistance
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
What you receive
A working management system, not a folder of documents
The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.
Executive layer
Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary
GRC layer
Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker
Assurance layer
Internal audit, findings, CAPA, management review, certification-readiness assessment
Operational layer
Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable
Governance cadence established
- Monthly
- Risk / action review, evidence status, control exceptions, material incidents
- Quarterly
- Risk trend, supplier / control reviews, KPI/KRI, management action tracking
- Annual
- Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan
For this engagement specifically
- Control owners
- IT teams
- Security teams
- Compliance teams
- Process owners
- Auditors
- Key risks
- Significant gaps
- Business impact
- Priority actions
- Ownership
- Target timelines
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.