ISO/IEC 27001:2022 · We hold it ourselves
Most ISO 27001 implementation consultancies have never been through certification as the organisation being audited. P J Networks holds ISO/IEC 27001:2022, which means the advice comes from having answered the auditor’s questions about our own evidence rather than from having read the standard.
Gap assessment · ISMS design · control implementation · evidence · audit readiness
The programme
How an implementation runs
The certificate is issued by an accredited body, not by us.
Scope decides the cost of everything after it
The single most expensive mistake is scoping the ISMS too broadly at the start. Every system inside scope needs controls, evidence and ongoing review. A tight, defensible initial scope that expands later beats an ambitious one that stalls.
The gap assessment is the useful deliverable
Measured against the current Annex A control set, it tells you what you already have. Most organisations are further along than they expect on technical controls and further behind on documented process.
Evidence is the actual work
Controls are comparatively easy. Producing repeatable evidence that a control operated, month after month, is where implementations run aground — and it is where a running SOC or NOC already generates most of what an auditor asks for.
Internal audit exists to find it before the auditor does
A real internal audit that raises real nonconformities is worth far more than a clean one. The external audit is not the place to discover a gap.
The boundary
What we do, and what we cannot
| Activity | Who does it | Why |
|---|---|---|
| Gap assessment and ISMS design | P J Networks | Implementation support is consulting work |
| Control implementation | P J Networks with your team | Technical controls, policy, process and evidence pipelines |
| Internal audit | P J Networks or your team | Must be independent of whoever built the control |
| Certification audit | An accredited certification body | Only an accredited body can issue the certificate — no consultancy can, including this one |
Scroll the table sideways on a narrow screen.
Any provider offering to certify you as well as implement for you is describing a conflict the standard is designed to prevent.
Failure patterns
Where implementations usually stall
Four failure patterns account for most of the programmes we are asked to rescue.
Scope written by ambition
Everything in scope on day one, because narrowing it felt like admitting weakness. The programme then needs evidence for systems nobody has time to bring under control, and stalls.
Policies nobody follows
A complete policy set downloaded and lightly edited. It passes a documentation review and fails the moment an auditor asks for proof that anyone acted on it.
Risk assessment as a one-off
Completed once for the certification and never revisited. The standard expects a living process, and surveillance audits are designed to detect exactly this.
No evidence pipeline
Controls operate but nothing records that they did. Each year becomes an archaeology exercise reconstructing twelve months of proof from memory and mailboxes.
All four are avoidable, and all four are considerably cheaper to avoid at the scoping stage than to correct after a surveillance audit has raised them.
Related
Related work
These sit alongside this engagement more often than not:
Questions
ISO 27001:2022 Implementation Services India, answered
Can you certify us to ISO 27001?
No, and neither can any other consultancy. Certification is issued by an accredited certification body after an external audit. We prepare you for that audit and support you through it. The separation is deliberate and it is what makes the certificate worth holding.
How long does ISO 27001 implementation take?
It depends almost entirely on scope and on how much documented process already exists. An organisation with a tight scope and reasonable existing practice moves considerably faster than one attempting to bring every system in at once. We scope from a gap assessment rather than a calendar.
What is different about ISO/IEC 27001:2022?
The 2022 revision restructured the Annex A controls into four themes and introduced controls reflecting cloud, threat intelligence and data leakage concerns that the earlier structure handled less directly. If you certified under the previous version, transition work is a defined exercise rather than a fresh implementation.
Do we need to buy new tooling?
Usually less than vendors suggest. The standard asks you to manage risk, not to own particular products. Most gaps we find are process and evidence gaps rather than missing technology — and where technology is needed, existing firewalls, logging and monitoring often already cover it.
Does a running SOC help with certification?
Substantially. A large share of what an auditor asks for — monitoring, logging, incident records, review evidence — is produced as a by-product of an operating SOC. Organisations without one usually have to construct that evidence specifically for the audit, every year.
Are you actually certified yourselves?
Yes. P J Networks holds ISO/IEC 27001:2022. We are not aware of many implementation consultancies in this market that can say the same, and it is a fair question to ask any of them.
Next step
Talk to someone who has done this before
Tell us where you are and we will tell you what the work actually involves. If you do not need us, we will say so.



