I will implement iso 27001 and prepare for certification audit
About this Gig
A note before ordering: I take on a limited number of clients at a time because this is hands-on work. If you are looking for documentation alone, this gig is not for you. Reach out if you want to actually build your controls. Message me before ordering so we can confirm fit.
Most ISO 27001 gigs sell you a folder of template policies and call it compliance. That is not what this is.
I am an ISO 27001 Lead Auditor and Lead Implementer working full time in GRC consulting. I have taken SaaS, fintech, and security companies through certification audits, and I know exactly what auditors look for and where companies fail.
This gig is a real consultation. I sit down with you and your team, conduct structured interviews, examine how your organization actually operates, and map your true posture against ISO 27001:2022. You get findings based on your reality, not a generic checklist.
Business type:
Corporates
•
SMBs
Service type:
Compliance & regulatory
•
Cybersecurity risks
Industry:
Crypto & blockchain
•
Financial services
FAQ
Is this a hands-off service or would we have to do most of the work?
This is a collaborative consultancy, not a hands-off service. I lead the assessment end to end: interviews, evidence review, gap analysis, and prioritized findings. Where remediation is included (Standard and Premium), I direct the work, draft policies where needed, and guide your team through fixes
What do you need from us to start?
A kickoff call, a brief overview of your organization and tech stack, and access to the stakeholders responsible for each control area for interviews. For Standard and Premium, you will also share evidence such as screenshots, configuration exports, and existing policy drafts.
Does "audit ready" mean we are guaranteed to pass certification?
No consultant can guarantee certification outcomes, and you should be cautious of anyone who does. What I deliver is a security posture genuinely aligned to ISO 27001:2022, with gaps either closed or formally documented with justification, which is exactly what certification auditors assess.
What timezone are sessions held in?
Sessions will be held in UK (BST) mornings-noon/ US (ET) Evenings
Do you work with Vanta, Drata, or similar platforms?
Yes I have hands-on experience with Vanta and I am knowledgeable in other GRC tools as well.

