-
The service is available all over Ukraine (Kyiv, Kharkiv, Dnipro, Odessa, Lvov, Kamianske, Chernigov, Vinnitsa, Zhitomir, Khmelnitsky). Offer different methods of payment
We prepare IT companies and data-driven businesses in Ukraine for ISO/IEC 27001 information security certification. We run the risk assessment, write the Statement of Applicability, policies and procedures, prepare the legal documents and support the audit with an accredited body. From you: a description of your product or services, infrastructure and team, and a technical owner.
What ISO/IEC 27001 confirms
The standard requires managing risks to the confidentiality, integrity and availability of information. The company defines the scope, assesses risks, selects controls from Annex A (93 controls in four themes: organisational, people, physical and technological) and records the selection in the Statement of Applicability.
Current edition
The current edition is ISO/IEC 27001:2022 with Amendment 1:2024. The transition from the 2013 edition ended on 31 October 2025, and ISO/IEC 27001:2013 certificates are no longer valid.
Our process
- Define the ISMS scope: offices, products, teams, cloud services.
- Asset register, risk assessment and risk treatment plan.
- Statement of Applicability and policies: access control, backup, incidents, suppliers, secure development.
- Staff awareness, internal audit and management review.
- Two-stage certification audit and surveillance audits.
The legal side of ISO 27001
Several controls concern contracts and personal data: NDAs, supplier and data processing agreements, confidentiality terms in employment contracts. We prepare them with our IT lawyers and help with GDPR for EU clients.
A client asks for ISO 27001?
Describe your product, team and deadline. We will propose a scope, a plan and a quote.
Дата оновлення 27.09.2026How long does ISO 27001 certification take?
It depends on team size, ISMS scope and the maturity of your current security practices. We give a dated plan after diagnostics.ISO 27001 or SOC 2?
ISO/IEC 27001 is an international management system certificate from an accredited body. SOC 2 is an auditor's report under AICPA standards, common with US clients. The choice follows your clients' requirements, and much of the work overlaps.Can we certify only part of the company?
Yes, the scope can cover a specific product, unit or office if the boundaries are clearly defined.Is a penetration test mandatory?
The standard does not require one explicitly. Control 8.8 requires management of technical vulnerabilities, and a penetration test is common evidence.Is an ISO 27001:2013 certificate still valid?
No. Certificates to the 2013 edition lost validity after 31 October 2025; certification to ISO/IEC 27001:2022 is required.If you find an error or inaccuracy in the text, select it and press Ctrl + Enter
Comments