38 / 63ISO 27001 Certification Support

ISO 27001 certification support, from the scope call to the surveillance audit

ISO 27001 certification support in Canada, from the first scope decision to the audit an accredited body runs.

  • ISO 27001 Lead Auditor on the team
  • CCIE Security-led engineering
  • Canadian data residency available
THE WORK

ISO 27001 certification, three pillars, one operator.

One Canadian team does the ISO 27001 consulting, builds the management system, decides every control, and stays through the audits.

  1. 1

    The management system

    An information security management system (ISMS) with scope, risk method, policies, and management review, sized to your business rather than to a template.

  2. 2

    Statement of Applicability

    All 93 Annex A controls, each carrying a written include or exclude decision and the evidence behind it. An exclusion needs a reason a stage 2 auditor accepts, not one that sounds good internally.

  3. 3

    Audit and after

    The ISO 27001 internal audit, stage 1 and stage 2 preparation, then the surveillance audits at month 12 and month 24 that nobody plans for.

THE PROOF

Built to last. Evidence over promises.

Every ISO 27001:2013 certificate expired on 2025-10-31. The 2022 version is the only one that counts now, and a buyer's procurement team checks the date before it checks anything else.

IN PRODUCTION

A certificate a Canadian buyer accepts.

We'd been told this was a document exercise. Our first attempt produced 140 pages nobody read and a Statement of Applicability that excluded controls we actually needed. SMEnode rebuilt the scope first, then the evidence, and stage 2 raised no majors.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

ISO 27001 certification in Canada, made real.

Most of what's written about this standard is written by people selling either software or a certificate. This is written by the engineer who'll sit in your stage 2 audit.

Scope is the decision that sets the price of everything else.

Draw the boundary around the whole company and you've committed to evidencing 93 controls across every team, every site, and every system. Draw it around the platform your customers actually ask about and the work halves without weakening the certificate. Buyers read the scope statement printed on the certificate, so a narrow scope has to be an honest one. Getting that line right in week one is the highest-value hour of the engagement, and it's the hour most providers skip.

The Statement of Applicability, and the evidence under it.

The middle of the work is the Statement of Applicability and what sits behind it. Every one of the 93 Annex A controls needs a written decision, and an exclusion needs a reason an auditor accepts rather than one that reads well internally. Risk hides in three places: a risk method nobody follows after month two, an ISO 27001 internal audit run by the same people who built the thing, and a management review that exists as a calendar invite instead of a record.

Two dates that matter in Canada right now.

Every ISO 27001:2013 certificate expired on 2025-10-31, so an organisation still holding one is uncertified rather than late (source: ISO transition period, ISO/IEC 27001:2022). And Amendment 1:2024 added climate change to clauses 4.1 and 4.2, so you have to determine and document whether it's a relevant issue, even where the answer is no (source: ISO/IEC 27001:2022/Amd 1:2024). Your certificate itself has to come from a body accredited by the Standards Council of Canada, the only internationally recognised ISMS accreditation body here.

Control checklist
THE METHOD

How our ISO 27001 consulting and gap analysis work runs.

Four steps, and step 01 decides the cost of the other three. We've seen the same failure twice: an organisation scopes the entire company because it sounds more impressive, then spends eleven months evidencing controls for a warehouse nobody asked about. We'd rather argue about scope in week one than find the problem at stage 2.

  1. Step 01

    Set the scope

    The boundary, the interested parties, the risk method, and the exclusions, written down and defended. This is also where we tell you if certification is the wrong instrument for what your buyer is actually asking for.

  2. Step 02

    Close the gaps

    An ISO 27001 gap analysis against all 93 Annex A controls, ranked by what stage 2 looks at hardest, with our engineers doing the technical remediation rather than handing you a spreadsheet of findings.

  3. Step 03

    Build the evidence

    Policies people can follow, records that generate themselves where possible, and a management review that produces minutes rather than a meeting.

  4. Step 04

    Audit, then stay

    Internal audit, stage 1 readiness, stage 2 support in the room, then the surveillance audits at month 12 and month 24, which is where most certificates quietly fall over.

QUESTIONS

ISO 27001 certification questions, answered straight.

Answers first, including the one thing we're not allowed to do for you. An architect takes the call, not a salesperson.

No, and nobody who builds your management system can. Certification comes from a body accredited under ISO/IEC 17021-1, and in Canada that accreditation comes from the Standards Council of Canada. We build, we prepare, and we sit in the audit with you. Anyone offering to both build and certify is selling a certificate your buyer's procurement team will reject.

Your company. This is the most common mix-up on the internet, and Google's own results carry it. ISO 27001 certifies an organisation's management system, and the certificate names the company and its scope. Individuals earn separate credentials, such as a lead auditor qualification, which are useful and a different purchase entirely.

Three separate bills, and only one is ours. The certification body charges audit days, which scale with scope and headcount. The standard itself costs money to buy. Our fee covers building the system and preparing the evidence. Scope drives all three, which is why we argue about it first, and we give you a range before you commit.

Sometimes, and the answer follows your buyers rather than your controls. SOC 2 tends to be asked for by North American software buyers. ISO 27001 travels better internationally and into government procurement, and it certifies a management system rather than reporting on a period. The control overlap is large, so a second framework costs far less than the first.

When a buyer asked for something else and nobody checked which. When you can't name an owner inside the business, because an external team cannot hold a management system for you. And when a funding round or acquisition is under six months out, since scope tends to change and you'd pay for the audit twice.

The surveillance audits happen. A certificate runs on a three year cycle, with an audit near month 12 and month 24 checking the management system is still being run rather than still being documented. Most certificates that fail do it here, because internal audit and management review quietly stopped once the celebration was over.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.