Cookie Consent by Free Privacy Policy Generator

ISO 27001 Internal Audit & Certification Readiness

Test your ISMS. Identify issues early. Approach certification with confidence.

Tell us your current cyber challenges

Are you ready for your ISO 27001 certification audit?

Our ISO 27001 Internal Audit & Certification Readiness Assessment provides an evidence-based review of your Information Security Management System against ISO/IEC 27001:2022.

We assess conformity across Clauses 4 - 10 and the Annex A controls applicable to your organisation, reviewing evidence, speaking to key stakeholders and assessing how controls operate in practice.

The assessment follows a formal audit methodology and is designed to satisfy the internal audit requirement under Clause 9.2 while helping you identify issues before your external certification assessment.

Why complete an ISO 27001 Internal Audit?

An internal audit is a mandatory part of ISO 27001, but it can also be an incredibly useful opportunity to understand how your ISMS is performing before an external auditor reviews it.

Assess actual conformity

Go beyond policies and documentation to understand whether ISO 27001 requirements are being met in practice.

Test control effectiveness

We review and sample evidence to assess whether applicable controls are implemented and operating effectively.

Identify issues before certification

Surface major or minor nonconformities and opportunities for improvement before your external assessment.

Meet the Clause 9.2 requirement

Receive a formal internal audit and audit outputs suitable for demonstrating that your internal audit obligation has been completed.

How Secarma Delivers Value
Independent Evidence-Based Audit
Our consultants independently assess your ISMS against ISO/IEC 27001:2022, reviewing evidence to determine whether controls are implemented and operating effectively.
Formal Internal Audit Report
Receive a comprehensive audit report including conformity assessments, findings, nonconformities and practical corrective action recommendations.
Certification Readiness Assessment
We identify issues before your certification body does, giving your team time to address nonconformities and approach certification with greater confidence.
Experienced ISO 27001 Auditors
Our experienced consultants apply a practical audit methodology, helping your team understand not only what we've found, but why it matters.
Clause 9.2 Compliance
Our assessment is designed to satisfy the ISO 27001 internal audit requirement under Clause 9.2, providing the documentation needed to demonstrate compliance.
Support Beyond the Audit
Need help addressing the findings? We can support remediation, validate corrective actions and help prepare your organisation for certification.
Advise
 
We help you understand where you are today and build a clear, realistic plan for improving your cybersecurity in a way that fits your business.

Measure Maturity. Identify Gaps. Build Resilience.

Secure Your Supply Chain. Protect What Matters.

Scalable security support, built around your business.

Strengthen Your Response Before a Real Attack Hits.

Plan Securely. Develop with Confidence.

Align your privacy practices with ICO standards.

Simulate, Measure, and Strengthen User Awareness.

Understand where you are. Identify the gaps. Build a clear path towards certification.

Measure resilience. Identify gaps. Build confidence.

Resources
Stay up to date with expert-written blogs, security labs, downloadable guides and more, all designed to support your journey.
Cyber Essentials Made Easy Pack
1
2
3
4
5
6
Get in touch
See how we’ve helped hundreds of businesses to improve their cyber security and regain their calm.

Alternatively, you can call us on 0161 513 0960

News and blog posts
Today's brief highlights the operational challenges of preparing for long-term...
The National Cyber Security Centre has published a detailed report following...
OpenAI has disclosed that autonomous AI agents powered by its GPT-5.6 Sol...
Security researchers have identified a new variant of the TrickBot malware that...
Cyber Essentials Certification Body Cyber Essentials Plus ISO 9001 ISO 27001 CREST IoTSF IASME Cyber Assurance NCSC Assured Service Provider IoT Cyber Scheme