Skip to main content

ISO 27001 readiness

Build an ISO 27001-ready ISMS your organization can actually operate.

EK Treasure helps define scope, establish governance, assess risk, implement controls, organize evidence and prepare your organization for independent certification.

ISMS implementation and certification-readiness support for growing and regulated organizations.

Build it. Prove it. Operate it.

Implementation support—not another gap report.

  • Controls with accountable owners
  • Evidence mapped to requirements
  • A remediation path teams can execute
  • An operating cadence that survives the project

A working ISMS

Build the governance, risk and evidence foundation behind certification readiness.

ISO 27001 readiness is an operating-model change, not a document exercise. Delivery is configured around your scope, current maturity and certification objective.

01

Define ISMS scope

Document the organizational, service, technology and location boundaries of the ISMS.

02

Establish context

Identify interested parties, obligations, governance and decision rights.

03

Operationalize risk

Define the assessment method, build the risk register and record treatment decisions.

04

Build the SoA

Create and maintain the Statement of Applicability with rationale and implementation status.

05

Implement controls

Establish ownership, policies, operating procedures and priority technical controls.

06

Prepare for certification

Organize evidence and prepare for management review, internal audit and certification-body requests.

How the work creates value

Pressure becomes trust when implementation and evidence move together.

EK Treasure connects the commercial trigger to the controls, proof and operating rhythm needed to answer it credibly.

01

Enterprise pressure

Questionnaire · SOC 2 request · audit deadline

02

Control implementation

Requirements become owned operating controls

03

Evidence

Current, reviewable proof mapped to each control

04

Independent assurance

Customer, CPA firm or certification-body review

05

Enterprise trust

A defensible answer to the buyer’s risk question

06

Commercial momentum

Less friction across procurement and renewals

Build it. Prove it. Operate it.

We don’t just tell you what’s missing.

EK Treasure helps build the program, prove it with credible evidence and establish the rhythm needed to keep it working.

Build

01

Turn requirements into specific operating practices your teams can execute.

  • Controls
  • Policies
  • Ownership
  • Remediation

Prove

02

Create credible proof and prepare the organization for independent review.

  • Evidence
  • Testing
  • Readiness
  • Customer assurance

Operate

03

Install the cadence that keeps ownership, controls and evidence current.

  • Monitoring
  • Reviews
  • Updates
  • Audit continuity

ISO 27001 delivery path

Readiness is sequenced; certification timing remains independent.

The twelve-week Accelerator can establish and advance the ISMS foundation. Final certification timing depends on scope, implementation maturity, internal audit, corrective actions and the certification body.

  1. WEEKS 1–201

    Scope & context

    ISMS boundary, interested parties, obligations and governance.

  2. WEEKS 2–402

    Risk architecture

    Methodology, risk register, treatment plan and decision rights.

  3. WEEKS 3–603

    Statement of Applicability

    Control selection, exclusions, rationale and ownership.

  4. WEEKS 4–1004

    Implementation

    Policy, control and remediation sprints with evidence capture.

  5. WEEKS 9–1205

    Readiness review

    Management-review preparation, evidence validation and corrective actions.

  6. AFTER READINESS06

    Certification process

    Independent Stage 1 and Stage 2 assessment by an accredited certification body.

Responsibility model

One program. Three clearly separated responsibilities.

EK Treasure prepares and supports implementation. Your team owns the environment and decisions. The independent reviewer remains responsible for its own assessment and conclusion.

ISMS readiness and implementation lead

EK Treasure

  • Scope the program and translate the business trigger into a delivery plan
  • Assess the current state and map priority controls
  • Build the remediation roadmap and facilitate implementation
  • Develop or tailor policies, ownership and evidence requirements
  • Validate evidence quality and track remediation decisions
  • Prepare leadership and support independent-review interactions

ISMS leadership and control owners

Your team

  • Provide system access and existing documentation
  • Assign control owners and a senior decision-maker
  • Implement agreed technical changes with EK Treasure support
  • Generate source evidence and attend working sessions
  • Approve policies and make business or risk decisions

Independent certification

Certification body

  • Perform the independent certification audit
  • Assess conformity with ISO/IEC 27001
  • Report findings and required corrective action
  • Make and issue the certification decision

Tool-agnostic delivery

Already using a compliance platform? Good. Keep it.

EK Treasure works through your existing environment where practical. The platform can track the work; we help configure the control model, establish ownership, close gaps, validate evidence and make the program operate. Tool names are illustrative only and do not imply a partnership.

  • Vanta
  • Drata
  • Secureframe
  • Sprinto
  • Thoropass
  • ServiceNow
  • Jira
  • SharePoint
  • Google Workspace

What the client receives

A practical ISMS delivery kit—not a shelf of generic templates.

The exact artefacts are confirmed during scoping. Typical ISO 27001 work products include:

ISMS scope

Boundaries, services, systems, locations and interfaces.

Context & interested parties

Needs, obligations, governance and accountable roles.

Risk methodology & register

Repeatable assessment, treatment and acceptance decisions.

Statement of Applicability

Control rationale, status, ownership and evidence mapping.

Policy library

Applicable policies and procedures tailored to operations.

Control Blueprint

Implementation requirements, owners and definitions of done.

Remediation backlog

Prioritized corrective work and decision gates.

Evidence catalogue

Evidence sources, periods, owners and refresh schedules.

Management review pack

Readiness, risk, objectives, decisions and actions.

Internal audit preparation

Audit plan, evidence readiness and finding follow-up.

Your trust operating system

What a client operating environment looks like.

These static previews illustrate the structured delivery workspace and operating model. They are not a claim that EK Treasure sells proprietary compliance software.

Illustrative demo data

Executive Trust Dashboard

Audit readiness: On track

Weekly snapshot
78%
Readiness
6
Open blockers
1
Critical blockers
42 / 54
Controls implemented
81%
Evidence validated
3
Upcoming decisions

Control register

Control: Access review
Owner: IT Lead
Status: Operating
Evidence: Validated
Control: Vendor review
Owner: Ops
Status: In progress
Evidence: Needs evidence
Control: Change approval
Owner: Engineering
Status: Operating
Evidence: Current

Evidence library

Evidence: E-104
Control: Access review
Owner: IT Lead
Next refresh: Sep 30
Evidence: E-118
Control: Backups
Owner: Engineering
Next refresh: Oct 14
Evidence: E-126
Control: Vendor review
Owner: Ops
Next refresh: Blocked

Remediation tracker

Gap: Logging coverage
Impact: High
Owner: Engineering
Status: In progress
Gap: Risk approvals
Impact: Medium
Owner: Leadership
Status: Decision due
Gap: Policy review
Impact: Low
Owner: Security
Status: On track

Questionnaire answer library

Question: Encryption
Owner: Engineering
Evidence: E-044
Reviewed: Current
Question: Incident response
Owner: Security
Evidence: E-071
Reviewed: Current
Question: Vendor risk
Owner: Ops
Evidence: E-126
Reviewed: Refresh due

Demo content only · No client or audit data shown

From compliance chaos to operating trust

The transformation is visible in ownership, evidence and repeatability.

Illustrative states show the operating difference an implementation program is designed to create. Actual scope and outcomes depend on the agreed objective and client environment.

Before

Access reviews
Missing
Incident response
Not evidenced
Vendor risk
Ad hoc
MFA
Evidence incomplete
Change management
Inconsistent
Security questionnaires
Rebuilt from scratch
Control ownership
Unclear

After

Access reviews
Operating & evidenced
Incident response
Tabletop completed
Vendor risk
Defined & operating
MFA
Implemented & evidenced
Change management
Standardized
Security questionnaires
Reusable response library
Control ownership
Assigned & accountable

Where EK Treasure fits

The platform tracks the work. The auditor tests the program. Someone still has to make it work.

EK Treasure works alongside your team between advice, tooling and independent assurance—without replacing the legitimate role of any of them.

Useful for diagnosis

Traditional advisory

Identifies gaps and recommends what should change.

Useful infrastructure

Compliance platforms

Track tasks, controls, evidence and recurring workflows.

Required independent role

Independent auditors

Test the program and issue an independent conclusion.

Implementation + operating discipline

EK Treasure

Helps build the program, establish ownership, close gaps, organize evidence and prepare teams to operate it.

ISO 27001 certification is issued by an independent accredited certification body. EK Treasure provides readiness, implementation and operating support and does not guarantee certification or an audit outcome.

Start with the live business pressure

Know what is blocking the deal. Fix it. Prove it.

Use the Enterprise Trust Triage to clarify the trigger, scope, ownership and most useful next step.