ISMS according to ISO 27001:2022 — from gap analysis to certification

ISMS Implementation: From Gap Analysis to ISO 27001 Certification

An ISMS is not a paper exercise — it is the operational backbone of your information security.

  • 01ISMS implementation and certification according to ISO 27001:2022
  • 0293 controls in 4 categories — implemented in a structured manner
  • 03TISAX readiness for automotive suppliers
  • 04NIS2- and DORA-compliant security architecture
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

Building an ISMS: The Roadmap to ISO 27001 Certification

ISO 27001:2022 has redefined the rules: 93 controls in 4 categories (organizational, people, physical, technological) replace the previous 114 controls in 14 groups. 11 new controls — including Threat Intelligence, Cloud Security, and Data Masking — reflect current threat landscapes. The transition deadline was October 2025, yet many organizations are still struggling with implementation.

Our expert consultants provide comprehensive information security management strategy services tailored to your organization's specific needs. We combine deep regulatory expertise with practical implementation experience to deliver measurable results.

6 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

ISMS Implementation according to ISO 27001:2022

Complete ISMS implementation from risk methodology through policies and processes to technical controls. Including Statement of Applicability, asset management, and documentation framework — certification-ready in 6–12 months.

02

ISMS Optimization & Transition

Migrating your existing ISMS to ISO 27001:2022: mapping the new 93 controls, integrating the 11 new requirements (Threat Intelligence, Cloud Security, ICT Readiness for Business Continuity), and closing audit findings.

03

Certification Support

From pre-audit readiness review through Stage 1 document review to on-site Stage 2 accompaniment. We know the typical pitfalls and prepare you specifically — including follow-up on minor/major non-conformities.

04

TISAX Assessment Preparation

For automotive suppliers: preparation for the TISAX assessment according to VDA ISA. We identify the gaps between your existing ISMS and TISAX-specific requirements (prototype protection, data protection, integration with OEM processes).

05

ISMS Integration into Management Systems

Smooth integration of your ISMS into existing ISO 9001 or ISO 14001 systems. Harmonization of documentation, audit cycles, and management reviews — for an integrated management system without duplication of effort.

06

BSI IT-Grundschutz Implementation

Alternative or complement to ISO 27001: building an ISMS based on the BSI IT-Grundschutz Compendium. Particularly relevant for KRITIS operators and public institutions that require the BSI standard as evidence of compliance.

6 phases

Our Approach: ISMS with a System, Not a Template

Every organization is different — your ISMS must reflect that. We work iteratively, pragmatically, and always with certification in mind.

  1. Scoping & Gap Analysis

    Assessment of the current state against ISO 27001:2022, identification of critical gaps, and definition of the ISMS scope

  2. Risk Assessment & Statement of Applicability

    Systematic risk analysis and derivation of applicable controls from Annex A

  3. Implementation

    Development of policies, processes, and technical controls — aligned with your IT landscape and organization

  4. Training & Awareness

    Embedding a security culture — from the board to student interns

  5. Internal Audit & Management Review

    Assessment of ISMS effectiveness and preparation for the external certification audit

  6. Certification Support

    Stage 1 + Stage 2 audit preparation, on-site accompaniment, and follow-up on findings

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Why Choose ADVISORI?

  • 01Deep regulatory and industry expertise
  • 02Proven track record with leading organizations
  • 03Practical, implementation-focused approach
  • 04End-to-end support from assessment to implementation

Expert Consultation Available

Contact our specialists today for a personalized assessment of your requirements.

6 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about Information Security Management Strategy

What is the difference between ISO 27001 and BSI IT-Grundschutz?

ISO 27001 is an international standard with a risk-based approach — you define which controls are relevant. BSI IT-Grundschutz is more detailed and prescribes specific measures (building blocks). ISO 27001 is globally recognized and suitable for international organizations. BSI IT-Grundschutz is particularly prevalent in Germany, especially among KRITIS operators and public authorities. Both can be combined: an ISO 27001 certification based on IT-Grundschutz combines the advantages of both approaches.

How long does an ISO 27001 certification take?

The typical timeframe is 6–12 months from project start to a successful Stage 2 audit. The duration depends on the current maturity level, the scope, and the available internal resources. Organizations with an existing management system (e.g., ISO 9001) can often achieve certification faster, as structures such as internal audit and management review are already established.

What does ISMS implementation and certification cost?

The pure certification costs (auditor fees) range from EUR 10,000–30,000 depending on company size and scope. The larger investment block is preparation: internal resources, consulting, tool implementation, and training. A realistic total budget for a mid-sized company is EUR 50,000–150,000. ADVISORI helps deploy this budget efficiently and avoid overengineering.

Is ISO 27001 mandatory under NIS2?

NIS2 does not mandate a specific framework, but requires systematic risk management, incident management, supply chain security, and governance structures — all core elements of an ISMS based on ISO 27001. In practice, an ISO 27001 certification is the most efficient way to demonstrate NIS2 compliance. In addition, management bears personal responsibility for cybersecurity — another reason for a structured ISMS.

What changes with ISO 27001:2022 compared to 2013?

The key changes concern Annex A: instead of 114 controls in 14 groups, there are now 93 controls in 4 categories (organizational, people, physical, technological). 11 new controls have been introduced, including Threat Intelligence, Cloud Security, ICT Readiness for Business Continuity, and Data Masking. The transition deadline was 31 October 2025 — certifications based on the 2013 version are no longer valid.

What is TISAX and do we need it?

TISAX (Trusted Information Security Assessment Exchange) is the information security standard of the automotive industry, based on the VDA ISA questionnaire. If you are a supplier or service provider for OEMs such as VW, BMW, or Mercedes, a TISAX assessment is generally a prerequisite for collaboration. TISAX and ISO 27001 have significant overlaps — an existing ISMS considerably facilitates TISAX readiness.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance