ISO 27001:2022 Consulting

ISO 27001 consulting to implement a useful and defensible ISMS.

We accompany companies that need to be certified, respond to customer demands or convert information security into a maintainable and proportionate system.

Gap analysisgaps, scope and prioritiesISMSpolicies, processes and recordsRisksmatrix and treatment planSoAStatement of ApplicabilityAuditevidence and continuous improvement
for whom

When ISO 27001 stops being “someday” and becomes necessary.

Especially useful if an enterprise client requires it, you want to sell more trust, you handle sensitive information or you need to organize controls before growing.

01

SaaS and technology

Demonstrable security for B2B customers, cloud providers, MSPs, and product teams.

02

Professional services

Protection of customer information, contracts, confidential data and continuity.

03

Regulated providers

Companies that combine ISO 27001 with ENS, NIS2, DORA or contractual requirements.

04

Growing SMEs

A proportionate system, without oversizing documentation or impossible controls.

What's included

From the initial gap to a defensible audit.

We do not sell individual templates. We build the system with justified, evidence and responsible decisions.

  • Initial diagnosis and scope of the ISMS
  • Asset inventory and critical information
  • Risk analysis and treatment
  • Statement of Applicability
  • Policies, procedures and records
  • Internal audit and improvement plan
Deliverables

Documentation that the team can maintain.

Certification fails when the documentation is not used. That's why we prioritize clarity, ownership and follow-through.

  • Roadmap prioritized by risk
  • Risk and treatment matrix
  • Evidence folder
  • Training and awareness plan
  • Record of incidents and actions
  • Support for external audit
Method

ISO 27001 implementation route in five phases.

A simple roadmap for management, IT and audit to understand what is being done and why.

01

Diagnosis

Context, scope, gaps and quick wins.

Weeks 1–4 · Initial report
02

Risks

Assets, threats, impact and treatment.

Month 2 · Matrix
03

Controls

Technical and organizational measures.

Months 2–4 · SoA
04

Evidence

Records, training, incidents and audit.

Months 4–6 · ISMS Folder
05

Improvement

Corrective actions, internal audit and monitoring.

Continuous · Annual plan
WHERE THE EFFORT GOES

Typical distribution of an ISO 27001 project.

Indicative proportion of work in an SME, according to our experience accompanying implementations. The diagnosis adjusts to your case.

Risks and controls
35%
Evidence and records
30%
Diagnosis and scope
15%
Training and awareness
12%
Audit and improvement
8%

Most of the effort is not writing policies: it is deciding controls and maintaining evidence that the auditor can check.

Connected compliance

ISO 27001 does not live isolated from the rest of the requirements.

We define a coherent route when there are public contracts, regulatory requirements or the need to validate technical controls.

ENS

ENS and public providers

If you provide services to the Administration, we review what controls and evidence can be coordinated.

See ENS adaptation →
NIS2

NIS2 and government

Risk, supplier, incident and continuity management may require a common roadmap.

See NIS2 preparation →
TEST

Actual technical validation

The auditor does not accept empty policies. We complement the ISMS with real pentesting: applications, APIs and infrastructure, with a technical and executive report.

See pentesting →
ROLE

Blue Moon Role

We are not a certifying entity: we prepare the system, the evidence and the internal audit for an independent evaluation.

Forms of work

Three entry points, depending on where you are.

The price depends on the actual scope: headquarters, systems, people and maturity. After the diagnosis we give you a final written figure.

01

Diagnosis

Gap analysis, ISMS scope, gaps and prioritized roadmap. The honest starting point before committing to an entire project.

Price closed after initial call

Request diagnosis →
02

Complete implementation

From diagnosis to audit: risks, SoA, policies, evidence, training and support before the certifying entity.

Budget by scope

Request proposal →
03

Continuous support

Maintenance of the ISMS, annual internal audits, continuous improvement and support in certificate renewals.

Fee according to support level

Talk about maintenance →
FAQ ISO 27001

Common questions before implanting.

Answers designed to decide scope, times and internal effort.

How long does it take to implement ISO 27001?

In an SME it usually takes between 4 and 9 months from the diagnosis to the certification audit, depending on scope, maturity and internal availability. The initial diagnosis (3-4 weeks) allows it to be limited with a closed figure.

Does Blue Moon certify directly?

The certification is issued by an independent certifying entity. Blue Moon prepares the ISMS, evidence, internal audit and support. In addition, part of our team has the AENOR ISO 27001 Lead Auditor certification, which provides an expert vision of the certification process.

Do I need ISO 27001 if I already comply with ENS?

It depends on the objective. ENS and ISO 27001 share controls and evidence, but respond to different frameworks. They can work together to avoid duplication.

What does the client need to contribute?

Information on processes, assets, suppliers, managers, incidents, existing controls and availability to validate decisions.

You can also write to contacto@bluemooncybertech.es or use WhatsApp.

DiagnosisWhatsApp