What to expect from the external assessment — and how MAST positions you to pass first time.
ISO/IEC 27001 Certified
ISO/IEC 27701 Certified
ISO 9001 Certified
Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation
Selecting an audit body or assessor
Accreditation status and recognition in your target markets
Experience in your sector and geography
Lead auditor availability for the desired audit window
Commercial terms, surveillance frequency and re-certification cycle
Audit-body selection criteria
Checklist titled "Audit-body selection criteria" with 4 items, every item marked complete: Accreditation status and recognition in your target markets; Experience in your sector and geography; Lead auditor availability for the desired audit window; Commercial terms, surveillance frequency and re-certification cycle.
✓Accreditation status and recognition in your target markets
✓Experience in your sector and geography
✓Lead auditor availability for the desired audit window
✓Commercial terms, surveillance frequency and re-certification cycle
Stage 1 readiness review
Documentation and design review — typically two to three days. Outcome is either readiness to proceed or a corrective action list before Stage 2.
Stage 2 / main assessment
On-site or hybrid fieldwork against the implemented control set. MAST attends in an observation role to clarify evidence and protect engagement momentum.
Surveillance and re-certification
Annual surveillance plus three-yearly re-certification for ISO standards; comparable cycles for SOC 2 (annual) and regulator submissions. MAST's Managed Compliance Service maintains evidence continuously between audits.
End-to-end certification journey
From engaging an assessor to maintaining certification — the full CIS Controls v8 lifecycle on one timeline.