Governance. Risk. Compliance. Cybersecurity.
Compliance & Certification

ISO/IEC 27001 Implementation & Certification

Build an audit-ready ISMS aligned to ISO 27001:2022.

ISO/IEC 27001 Implementation & Certification — ISO certification stamp on an audit document, MAST Consulting Group

Overview

We design, document and operationalise an Information Security Management System that passes Stage 1 and Stage 2 audits the first time. Our consultants are Lead Auditors with deep experience across banking, healthcare, oil & gas and technology sectors.

Anil Sahore
Lead partner for this service
Anil SahoreHead of Advisory — Regulatory and Compliance

Seasoned consulting leader with 35+ years of experience in IT audit, compliance and digital transformation. Held leadership roles at KPMG (Technical Director, IT Audit & Assurance — 9+ years) and Wipro Consulting before joining MAST.

In depth

A four-layer view of this service.

Context, scope, delivery and impact — written for buyers, boards, auditors and search engines alike.

Layer 01 — Context

Context & Why It Matters

01

ISO/IEC 27001:2022 is the world's most widely adopted information security management standard, mandated or expected by enterprise customers, regulators and partners across the UAE, GCC, India and EU.

  • With the 2013-to-2022 transition deadline behind us, every certified organisation must operate against the new Annex A structure of 93 controls grouped under Organizational, People, Physical and Technological themes.
  • For UAE banks, ADGM and DIFC entities, healthcare providers, SaaS exporters and government suppliers, ISO 27001 is the de-facto baseline auditors, insurers and procurement teams ask for before signing.
Layer 02 — Scope

Scope & What It Covers

02

Our implementation covers the full ISMS clause set (4–10) — context of the organisation, leadership, planning, support, operation, performance evaluation and improvement — and all 93 Annex A controls.

  • We deliver a documented risk methodology aligned to ISO/IEC 27005, a Statement of Applicability (SoA) with justified inclusions and exclusions, asset and information classification schemes, supplier and cloud-service security controls (A.5.19–A.5.23), secure development (A.8.25–A.8.31), threat intelligence (A.5.7), data masking, monitoring activities and physical security for hybrid-work environments.
Layer 03 — Approach

Our Approach & Delivery

03

Lead Auditors (ISO 27001 LA, IRCA-certified) run a five-stage delivery: gap assessment, ISMS design, control implementation, internal audit and certification support.

  • We embed evidence collection into your existing tooling — Jira, ServiceNow, Microsoft Purview, AWS Security Hub, Vanta, Drata — so the audit trail is automated, not manual.
  • Awareness training is role-based: developers, system administrators, HR and executives each receive tailored content.
  • We sit alongside you in Stage 1 and Stage 2 audits with accredited certification bodies (BSI, DNV, TÜV, Bureau Veritas, SGS).
Layer 04 — Impact

Business Impact & Outcomes

04

Certified clients typically pass first-time audits, win enterprise tenders that mandate ISO 27001, reduce cyber-insurance premiums by 10–25 percent, and cut customer security questionnaire response time from weeks to days.

  • Beyond the certificate, the ISMS provides a measurable, board-reportable view of information risk — risk register movement, control effectiveness, internal audit findings closed — that holds up to regulator and investor scrutiny.
At a glance

Process flow, compliance checklist and benefits.

A visual breakdown of how the engagement runs, what evidence we leave behind, and the business outcomes you can defend at the board.

Process flow

How we deliver ISO/IEC 27001 Implementation & Certification.

  1. 01
    Gap Assessment

    Current-state diagnostic mapped to all 93 Annex A controls.

  2. 02
    Design & Document

    Policies, SoA, risk methodology, asset inventory.

  3. 03
    Implement & Train

    Control roll-out, awareness training, evidence capture.

  4. 04
    Internal Audit

    Pre-certification audit and management review.

  5. 05
    Certification Support

    Stage 1 + Stage 2 audit support with accredited bodies.

Compliance checklist

What auditors and regulators expect to see.

Stage 2 auditors will only certify when every item below is in place, documented and demonstrably operating.

  • ISMS scope statement signed by top management

    Boundaries, locations, exclusions and interfaces formally approved.

  • Risk assessment and treatment plan

    Methodology aligned to ISO/IEC 27005 with current risk register.

  • Statement of Applicability (SoA)

    All 93 Annex A controls justified — included, excluded or N/A.

  • Information security policy suite

    70+ policies covering access, cryptography, supplier, cloud and dev.

  • Awareness training records

    Role-based training with attendance and assessment evidence.

  • Internal audit programme

    Schedule, reports and corrective actions for every clause and control.

  • Management review minutes

    Top-management review covering inputs and outputs per Clause 9.3.

  • Continuous improvement log

    Nonconformities, corrective actions and improvement initiatives tracked.

Benefits

What you walk away with.

Pass Stage 1 and Stage 2 first time

Audit-ready evidence packs designed with BSI, DNV, TUV and BV in mind.

Win enterprise and government tenders

Meet the mandatory ISO 27001 prerequisite in RFPs across UAE, KSA and India.

Reduce cyber-insurance premiums

10 to 25 percent reduction reported by certified clients after first renewal.

Faster security questionnaires

Cut customer assurance turnaround from weeks to days.

Board-reportable risk view

Live risk register and KRIs that hold up to investor and regulator scrutiny.

Foundation for 27701, 22301 and 42001

Reuse the ISMS to layer privacy, continuity and AI management systems.

FAQ

Frequently asked questions.

How long does ISO 27001 certification take in the UAE?+

Most mid-size organisations achieve certification in 12 to 16 weeks. Larger enterprises with multiple sites typically take 4 to 6 months.

What does ISO 27001 cost?+

Implementation fees depend on scope, headcount and locations. Certification body fees are separate. We provide a fixed-fee proposal after a free 30-minute scoping call.

Do you cover ISO 27001:2022 transition?+

Yes. We transition existing 2013 certifications to the 2022 version, including the 11 new controls and revised Annex A structure.

Can we use our own internal team and just have you advise?+

Yes. We routinely run co-delivery models where we own methodology, templates and audit liaison while your team executes day-to-day. It typically reduces external fees by 30–40%.

Which certification bodies do you work with?+

We have delivered audits with BSI, DNV, TÜV NORD, TÜV SÜD, Bureau Veritas, SGS, Intertek and BV. We help you select based on industry recognition, geography and price — we do not earn commission from any CB.

What happens if we fail Stage 2?+

Stage 2 nonconformities are categorised major / minor. We include 30 days of post-audit remediation support in every engagement and have a 100% first-attempt pass rate on the engagements we run end-to-end.

How much internal effort is needed from our team?+

Plan for 4–6 hours per week from a Compliance Lead and 1–2 hours per week from control owners (IT, HR, Legal, Procurement). We do the heavy lifting on documentation, mapping and evidence design.

What is included after certification?+

Year 1 surveillance support, internal audit, management review facilitation, awareness refresh and the annual ISMS update are available on a fixed-fee retainer.

Methodology

Week-by-week, how ISO/IEC 27001 Implementation runs.

A disciplined sequence that compresses 6–9 month programmes into a fixed-fee, board-defensible engagement.

  1. Week 1–2
    Step 1
    Gap assessment

    Workshops with control owners, evidence walk-through against all 93 Annex A controls, scope and SoA draft, risk methodology agreed with the steering committee.

  2. Week 3–5
    Step 2
    ISMS design

    Information security policy, 14-domain procedure set, asset inventory, supplier register, risk register populated with treatment plans, mandatory records baselined.

  3. Week 6–9
    Step 3
    Control implementation

    Annex A controls operationalised — access reviews, joiner/mover/leaver, change management, vulnerability management, supplier onboarding, incident response runbooks.

  4. Week 10–11
    Step 4
    Awareness & evidence

    Role-based training delivered, phishing simulation baseline, evidence repository structured by clause, control effectiveness metrics defined.

  5. Week 12–13
    Step 5
    Internal audit & MR

    Independent internal audit by a Lead Auditor not part of design, nonconformity closure, management review with quantified KPIs.

  6. Week 14–16
    Step 6
    Stage 1 & Stage 2

    Certification body liaison, Stage 1 documentation review support, on-site Stage 2 audit attendance, nonconformity response, certificate issued.

Deliverables

What we leave behind.

Audit-grade artefacts your team continues to operate after handover — not a one-shot consulting deck.

Statement of Applicability (SoA)

Annex A control mapping with justification, ownership and implementation status.

Risk register & methodology

Asset-based and scenario-based risks with treatment plans aligned to ISO 31000.

Policy & procedure set

70+ documents covering all 14 ISO 27001 domains, version-controlled and approved.

Internal audit programme

Three-year audit plan, audit checklists, findings log and corrective action tracker.

Management review pack

KPI dashboard, control performance metrics, board-ready decision log.

Evidence repository

Structured by clause and Annex A control, ready for surveillance audits in years 2 and 3.

Regulators & frameworks

One engagement, mapped to every applicable obligation.

Evidence designed once, reused across regulators — reducing audit fatigue and total cost of compliance.

FrameworkNameWhy it matters
ISO/IEC 27001:2022Information Security Management SystemsPrimary certification standard — Annex A 93 controls.
CBUAEUAE Central Bank Information Security StandardISMS evidence accepted as foundational layer for banking licensees.
SAMA CSFSaudi Central Bank Cyber Security FrameworkISO 27001 controls map directly to SAMA CSF domains 1–4.
NCA ECCNCA Essential Cybersecurity Controls (KSA)ISMS evidence reused for ECC subdomains 1.1–1.5.
ADHICS V2Abu Dhabi Healthcare Information & Cyber SecurityISO 27001 ISMS is the recommended underlying framework.
DPDP Act 2023India Digital Personal Data Protection ActISMS provides reasonable security safeguards expected by the DPB.
Engagement tiers

Pick the model that fits your scope.

Fixed-fee where scope is clear, phased programmes where complexity demands governance — never time-and-materials drift.

Fixed fee, mid-market
Essentials

Single site, <300 employees, single cloud or hybrid estate. 12-week delivery.

Phased programme
Enterprise

Multi-site or multi-entity, complex third-party landscape, 16–22 weeks with executive steering.

Programme + rollout
Group

Holding company with multiple subsidiaries, certificate roll-out across 3+ legal entities.

Why MAST

What separates this engagement from the alternative.

Lead Auditor delivery

Every engagement is led by an IRCA / Exemplar Global certified ISO 27001 Lead Auditor — not delegated to a junior analyst pool.

First-pass certification rate

Our 100% first-pass rate across 200+ ISO 27001 engagements is the basis of our fixed-fee certification guarantee.

Regulator-aware design

ISMS controls pre-mapped to CBUAE, SAMA, NCA, ADHICS, DPDP — one programme satisfying multiple regulators.

Post-certificate care

Year-2 and Year-3 surveillance audits included in our managed compliance retainer, with continuous improvement tracking.

Compare

DIY vs Big Four vs MAST.

An honest, side-by-side comparison of what each delivery model typically gets you.

DimensionDIY / InternalBig FourMAST
Time to certificate9–18 months, often slipping6–9 months, multiple workstreams12–16 weeks, fixed fee
Senior involvementInternal team onlyPartner oversight, manager-ledLead Auditor on the engagement, every week
Evidence reuseBuilt for the audit, then abandonedBespoke per workstreamMapped to CBUAE / SAMA / NCA / ADHICS from day one
Total cost of ownershipHidden — internal hours uncountedHigh — branded premiumMid-band — boutique focus, no overhead loading
Extended FAQs

The questions experienced buyers actually ask.

Do you support the 2022 transition from ISO 27001:2013?+

Yes. We deliver gap analyses against the 2022 changes (Annex A restructured into 4 themes, 11 new controls including threat intelligence, cloud services, data masking, secure development lifecycle) and run the transition audit with your certification body.

Can you operate as our outsourced ISMS Manager post-certification?+

Yes — under our Managed Compliance retainer we run internal audits, management reviews, risk reassessments and the surveillance audit cycle on your behalf, with a named ISMS Manager and quarterly board reporting.

Which certification bodies do you typically work with?+

We work with IAS, BSI, DNV, BSCIC, TÜV, Bureau Veritas and other ANAB / IAF-accredited bodies. We will recommend the best fit for your sector, geography and customer expectations.

How do you handle scope decisions for cloud and SaaS environments?+

We map your data flows and shared-responsibility boundaries first, then scope the ISMS to cover the controls you actually own. Cloud-native services receive control inheritance documentation from your hyperscaler's audit reports (SOC 2, ISO 27017).

What if our auditor raises a major nonconformity?+

Our fixed-fee engagement includes nonconformity response support — root cause analysis, corrective action design and re-audit attendance — until the certificate is issued.

Take it with you
Download the ISO/IEC 27001 Implementation & 1-pager.

Methodology, deliverables, pricing bands and reference architecture on a single board-ready page.

Request the PDF
Get started

Ready to scope your ISO/IEC 27001 Implementation engagement?

Tell us a little about your business — a senior consultant will reach out within one business day.

By submitting you agree to be contacted by a MAST consultant. We never share your details.