ISO 27001 — Information
Security
Certification of information security management systems against ISO 27001:2022 — for organisations whose clients need proof their data is protected.
What does ISO 27001 prove?
That client data is protected by a system rather than by luck.
The standard requires you to inventory your information assets, assess the risks to them, and operate controls that hold up under audit: access management, backup, change control, incident response. Banks, corporate clients and government contracts increasingly ask suppliers for exactly this.
Built for teams
like yours.
- IT, SaaS and outsourcing companies selling into Western markets
- Financial and insurance organisations
- Contractors handling government or client data
- Any business whose clients audit supplier security
If one of these is you, it is worth a conversation.
Request a quoteWhat's included.
The handover pack
06 items- An accredited ISO 27001:2022 certificate, valid three years
- A certificate entry anyone can confirm online on the public verification page
- The Stage 1 readiness result: the gaps listed for you before the main audit
- The two-stage certification audit report and its nonconformity records
- A certification decision signed off by an independent decision-maker
- An annual surveillance programme, and recertification at the end of the cycle
3 reasons to choose us.
We replace long security questionnaires with a single certificate — one that can actually be verified.
-
The audit follows the Statement of Applicability.
Which control was selected, and why another was left out, is examined in its own right. This is not an audit you pass with a list of logins and backups, and that difference is exactly what a bank’s supplier review is looking for.
-
Controls are scaled to the company’s size and risk profile.
A small IT firm does not carry a large bank’s control load. The Statement of Applicability selects only the controls that apply to you, and justifies the ones that do not.
-
We settle the SOC 2 question before we quote the audit.
ISO 27001 is a globally recognised accredited certificate (attestation AZ 03.0031.01.26); SOC 2 is a US-centred attestation. We work out with you which one your partner is actually asking for.
Asked &
answered.
Three years, subject to annual surveillance audits that confirm the system is still operating. In year three a recertification audit renews the cycle.
Yes — General Group Co. is accredited by the Azerbaijan Accreditation Centre under AZS ISO/IEC 17021-1:2021 (attestation AZ 03.0031.01.26), so the certificates we issue are independently recognised, not self-declared.
Anyone can. Every certificate we issue can be checked online through our public verification page at any time — no account, no request, no waiting.
No — impartiality rules prohibit a certification body from certifying a system it built. We can certify a system prepared in-house or with an independent consultant; our procedures explain exactly what the audit will examine.
ISO 27001 is a globally recognised accredited certificate; SOC 2 is a US-centred attestation. Which one you need is decided by what your Western partner specifically asks for, and we work that out with you.
No — the controls are scaled to the size and risk profile of the company. The Statement of Applicability selects only the controls that actually apply to you.
No, that is a separate legal obligation. ISO 27001 shows that data management is structured and audited; it is not a formal confirmation of legal compliance.
Increasingly, yes. They want structured security evidence from any supplier handling sensitive data, and the certificate is the short answer to that.
Still unsure this is the right fit? Tell us your situation — we reply the same day.
Get in touchISO Certification — more services.
Describe your situation in a sentence or two — a named specialist gives you a clear answer the same working day. Call, WhatsApp or the short form, whichever suits you.