Skip to content

ISO 27001

ISO 27001 certification: in control of information security

ISO 27001 shows customers, regulators and your own organisation that information security risk is deliberately managed, not incidentally in order.

Book an introductory call
  • Information security
  • Governance, risk & compliance
  • Audit & compliance

When ISO 27001 becomes relevant

Customers and tenders increasingly require an ISO 27001 certificate as a condition of doing business.

Without a structured ISMS, information security depends on individual knowledge rather than a system that keeps working when people leave.

  • A customer or tender asks for the certificate

  • An incident showed that responsibilities weren’t clearly assigned

  • The organisation is growing, and risk management needs to keep pace

The cost of invisible control

Without a working ISMS you risk losing contracts, as more clients demand visible control as a condition.

An incident without demonstrable policy can weigh more heavily on liability and reputation than one where the organisation was clearly in control.

What the standard concretely requires

ISO 27001 requires a risk assessment, an approved policy, assigned responsibilities and controls that work in practice, not just on paper.

  • A risk assessment of information security risks

  • An information security policy, approved by management

  • Assigned roles and responsibilities

  • Annex A controls, where applicable

  • Internal audits and a management review cycle

From baseline to certificate

Vedeum guides you from baseline assessment to certification, with an approach that matches the size of your organisation, without unnecessary bureaucracy.

  1. Baseline assessment

    We map the current situation against the standard and identify the main gaps.

  2. Implementation

    We help set up policy, risk assessment and controls, matched to your organisation.

  3. Internal audit

    We carry out an internal audit and prepare you for the certification body.

  4. Certification & maintenance

    We guide certification and help keep the ISMS alive afterwards.

Book a no-obligation introductory call

Tell us where your organisation stands. We will think through the first steps with you.

Book an introductory call