Logo Gigson Solutions

ISO/IEC 27001:2022 · Information Security

ISO 27001 Certification for businesses that need the certificate without grinding their operations to a halt.

We implement an Information Security Management System on your real operations — not documentation nobody will ever use. For tech SMEs, law firms and consultancies with 10 to 250 employees.

Request free diagnosis

Why get certified now

There are strong reasons not to wait any longer.

Use Cases

01. Situations that demand it

The most common scenarios pushing companies to get ISO 27001 certified.

Methodology

02. Our approach

The difference between a consultancy that writes documents and one that implements real controls.

How we work

Four phases, one certificate.

A process designed for SMEs: diagnosis of your real operations, implementation on what you already have, and coordination with the certification body — without grinding your day-to-day to a halt.

01

Diagnosis

Gap analysis of your current situation. We identify which controls you already meet without knowing it and what is actually missing.

02

Implementation

Documentation, risk analysis, operational controls on what you already have, and training for the team involved.

03

Internal audit

Pre-certification check so you go into the external audit with certification assured.

04

Certification

We coordinate the phase 1 and phase 2 audits with the certification body.

Request free diagnosis

Frequently asked questions about ISO 27001

For an SME with 10 to 100 employees, the full process typically takes 4 to 8 months. The initial diagnosis takes 2 to 4 weeks. The actual duration depends on the complexity of your operations and how many controls you already have in place.
Implementation is the process of designing and building the ISMS (Information Security Management System) in your company. Certification is the external audit by an accredited body that validates your ISMS meets the ISO 27001 standard. You can implement without certifying, though most companies seek the certificate to demonstrate it to clients.
NIS2 is a European compliance directive, not a certification. It does not directly require ISO 27001, but many of its technical requirements are covered by a well-implemented ISMS. In practice, having ISO 27001 is the most efficient way to demonstrate NIS2 compliance to clients and auditors.
The cost has two parts: consultancy fees for the implementation (which vary by company size and complexity) and the certification body's fees for the phase 1 and phase 2 audits. We do a free diagnosis before giving you any figures, to tailor them exactly to your situation.
Not necessarily. We design the ISMS to be maintainable with the resources you already have. Many companies we work with have no dedicated security officer — the system is designed to be managed by whoever already handles other responsibilities, without extra burden.

Trusted by

Great Brands

Meet our clients and discover how we create value for them.

CáritasVikoEuropcar Mobility GroupMU DAN ZAA6KMMElogiaSTKAdockModareSpain RevealedBrandtiaTarbozColvinUNAVETSQuickSmile