ISO 27001 — Information
Security

Certification of information security management systems against ISO 27001:2022 — for organisations whose clients need proof their data is protected.

What it is

What does ISO 27001 prove?

That client data is protected by a system rather than by luck.

The standard requires you to inventory your information assets, assess the risks to them, and operate controls that hold up under audit: access management, backup, change control, incident response. Banks, corporate clients and government contracts increasingly ask suppliers for exactly this.

Who it's for

Built for teams
like yours.

  • IT, SaaS and outsourcing companies selling into Western markets
  • Financial and insurance organisations
  • Contractors handling government or client data
  • Any business whose clients audit supplier security

If one of these is you, it is worth a conversation.

Request a quote
Deliverables

What's included.

The handover pack

06 items
  • An accredited ISO 27001:2022 certificate, valid three years
  • A certificate entry anyone can confirm online on the public verification page
  • The Stage 1 readiness result: the gaps listed for you before the main audit
  • The two-stage certification audit report and its nonconformity records
  • A certification decision signed off by an independent decision-maker
  • An annual surveillance programme, and recertification at the end of the cycle
Why us

3 reasons to choose us.

We replace long security questionnaires with a single certificate — one that can actually be verified.

  • The audit follows the Statement of Applicability.

    Which control was selected, and why another was left out, is examined in its own right. This is not an audit you pass with a list of logins and backups, and that difference is exactly what a bank’s supplier review is looking for.

  • Controls are scaled to the company’s size and risk profile.

    A small IT firm does not carry a large bank’s control load. The Statement of Applicability selects only the controls that apply to you, and justifies the ones that do not.

  • We settle the SOC 2 question before we quote the audit.

    ISO 27001 is a globally recognised accredited certificate (attestation AZ 03.0031.01.26); SOC 2 is a US-centred attestation. We work out with you which one your partner is actually asking for.

Questions

Asked &
answered.

Three years, subject to annual surveillance audits that confirm the system is still operating. In year three a recertification audit renews the cycle.

Yes — General Group Co. is accredited by the Azerbaijan Accreditation Centre under AZS ISO/IEC 17021-1:2021 (attestation AZ 03.0031.01.26), so the certificates we issue are independently recognised, not self-declared.

Anyone can. Every certificate we issue can be checked online through our public verification page at any time — no account, no request, no waiting.

No — impartiality rules prohibit a certification body from certifying a system it built. We can certify a system prepared in-house or with an independent consultant; our procedures explain exactly what the audit will examine.

ISO 27001 is a globally recognised accredited certificate; SOC 2 is a US-centred attestation. Which one you need is decided by what your Western partner specifically asks for, and we work that out with you.

No — the controls are scaled to the size and risk profile of the company. The Statement of Applicability selects only the controls that actually apply to you.

No, that is a separate legal obligation. ISO 27001 shows that data management is structured and audited; it is not a formal confirmation of legal compliance.

Increasingly, yes. They want structured security evidence from any supplier handling sensitive data, and the certificate is the short answer to that.

Still unsure this is the right fit? Tell us your situation — we reply the same day.

Get in touch
Every certificate we issue is publicly verifiable — and our certification procedures are published. Verify a certificate
Contact

Describe your situation in a sentence or two — a named specialist gives you a clear answer the same working day. Call, WhatsApp or the short form, whichever suits you.

WhatsApp +994 99 900 99 09