ISO 27001: certified once, defensible all year

ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS) — and the security credential most often demanded in European commercial contracts and tenders. The 2022 revision restructured Annex A into 93 controls across four themes: organisational, people, physical and technological.

The certificate is issued by an accredited certification body. The hard, ongoing work — running the ISMS, operating the controls and proving they operate through a three-year cycle of surveillance and recertification audits — is yours. That ongoing proof is what RASDefense automates.

How we get you there

  1. Gap assessment (expert-led). Scope definition, risk assessment, Statement of Applicability, and an honest picture of the distance to certification.
  2. ISMS build-out. Policies, risk treatment and control implementation matched to your organisation — not a template binder that auditors have learned to distrust.
  3. Continuous evidence (AI-led). The platform verifies your technological controls on a schedule with deterministic rules and files the output against the Annex A control set. An RAS expert reviews exceptions and counter-signs every cycle — so surveillance audits stop being archaeology.
  4. Audit support. We stand beside you during Stage 1, Stage 2 and every surveillance audit.

ISO 27001 and NIS2: one control set, two obligations

If you are in NIS2 scope, ISO 27001 is the natural implementation backbone: most of the Article 21 measures — risk analysis, incident handling, continuity, supplier security, cryptography, access control — correspond to Annex A controls. But the directive adds what a certificate cannot discharge: registration with your national authority, the 24h/72h/one month incident-reporting clocks, and personal management accountability.

We maintain the mapping in both directions, so the evidence collected for your ISMS serves your NIS2 compliance — and vice versa. The same applies to SOC 2 and the NIST CSF; see the compliance hub for how the frameworks interlock.

Why RASDefense

RASDefense is the cybersecurity arm of RAS Institute — vetted through competitive EU procurement to hold three framework contracts with ENISA, the European Union Agency for Cybersecurity. The vetting is a benchmark, not an endorsement: documented proof that our methodology and data-protection discipline withstood EU-grade scrutiny. Your ISMS is built to that standard, with GDPR-aligned data protection and residency to match your jurisdiction.

FAQ

Does RASDefense issue ISO 27001 certificates?

No — certificates are issued by accredited certification bodies after an independent audit. RASDefense builds and operates the readiness side: the ISMS, the Annex A control mapping, and continuously fresh evidence, so the certification and surveillance audits become routine.

How long does ISO 27001 readiness take?

Typically three to six months from gap assessment to certification-ready, depending on your size and how much of the control set already operates. Continuous evidence automation shortens the path because controls are verified as they are implemented, not reconstructed at the end.

Does ISO 27001 cover NIS2?

It helps substantially but is not sufficient by itself. ISO 27001 covers most NIS2 Article 21 measures via Annex A controls, but NIS2 adds legal obligations — registration with national authorities, strict 24h/72h incident reporting and management accountability — that an ISMS alone does not discharge. We map the two so one control set serves both.

Make your compliance defensible.

Tell us where you are on the journey — we'll show you the fastest credible route to readiness, built on an EU-vetted methodology and agentic AI.

Email us