The certificate is the milestone, a working security programme is the point. IrisInfosec implements ISO 27001, ISO 27701, ISO 42001, SOC 2 and NIST CSF 2.0 as one control set, prepares your evidence and stands beside you through the audit. We design for the certificate and for the year after it, so your second audit is a review, not a rebuild.
ISO 27001, SOC 2 and NIST CSF share most of their underlying controls. Run them as separate projects and you pay for the same work three times. We build one management system and one control set, then produce the specific evidence each standard requires.
The aim is a programme your teams can operate, not a binder that satisfies an auditor once and then drifts out of date. That is the difference between passing an audit and being secure.
Framework implementation is the work of designing, documenting and operating the controls a standard requires, then preparing the evidence and supporting you through certification or attestation.
Frameworks we implement
Implemented from one foundation, so adding the next framework is an extension, not
a fresh start.
The international information security management standard. The backbone most other frameworks extend from.
The privacy extension to ISO 27001, aligning your information security and privacy management in one system.
The AI management system standard, for organisations that build or deploy AI and want to govern it credibly.
The attestation report US customers expect, against the trust services criteria, at a point in time or over a period.
A risk-based framework with the new Govern function, useful as an organising backbone across the others.
Benchmarks and cloud assurance schemes layered on where your sector or customers require them.
Common question
The two most requested, and the two most confused. Here is how they differ, and why
many firms run both from one programme.
| ISO 27001 | SOC 2 | |
|---|---|---|
| What it is | Certification of a management system | Attestation report on controls |
| Origin | International standard, recognised globally | US standard, common with US buyers |
| Covers | The whole information security system | Selected trust services criteria |
| Outcome | A three-year certificate with surveillance | A point-in-time or period report |
| Run together | One control set produces evidence for both, so you are not running two parallel projects. | |
How we work
A staged programme that respects your delivery commitments and ends in evidence an
auditor accepts.
Define the boundary, the assets and the Statement of Applicability that frames the whole programme.
Measure current state against the standard and run a risk assessment that drives the treatment plan.
Build the policies, processes and technical controls, working with your teams to make them stick.
Run internal audit and management review, then collect and organise the evidence each clause needs.
Stand beside you through the external audit, then support surveillance so the certificate holds.
What you receive
The artefacts an external auditor will ask to see, written for your organisation and organised
against each clause.
A Statement of Applicability and a full policy and standards set written for your organisation.
A documented risk assessment and a treatment plan that ties every risk to an owner and a control.
Internal audit results, management review records and the evidence organised against each clause.
Built to pass, designed to hold
Tell us your target standard and timeline. We will assess your current maturity and send a realistic plan to the certificate and beyond.
Questions, answered
Related services