AGIDAT – Datenschutz | Informationssicherheit

ISO/IEC 27001 – ISMS & Certification

Information security to an international standard — build it in a structured way, certify successfully.

What is ISO/IEC 27001?

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It sets requirements for establishing, implementing, maintaining, and continually improving an ISMS.

Certification to ISO 27001 is the recognized evidence that your organization manages information security systematically and to an international standard.

Why ISO 27001?

  • Customer requirements: more and more clients, particularly in industry and the public sector, require ISO 27001 certification
  • Competitive advantage: proof of security as a differentiator
  • Risk reduction: a systematic approach genuinely reduces security risks
  • Regulatory requirements: NIS2, KRITIS, and other frameworks reference ISO 27001
  • Insurance: cyber insurers reward ISMS certification

Our consulting approach

Phase 1: Gap analysis

We analyze your status quo: what do you already have, what's missing, where are the biggest gaps? The result is an action plan with a realistic timeline and cost estimate.

Phase 2: ISMS implementation

Together we build the ISMS — pragmatic and tailored to your organization:

  • Scope definition: what should the ISMS cover?
  • Risk analysis and treatment
  • Drafting the security policy and supporting policies
  • Implementing the controls from Annex A
  • Internal audits and management review

Phase 3: Certification audit

We prepare you for the certification audit conducted by an accredited certification body — and support you throughout the entire process.

Realistic timeline

An ISO 27001 project typically takes 9–18 months, depending on company size, starting position, and resource availability. We create a realistic project plan with you — without false promises.