
ISO 27001 implementation and certification, in eleven months
End-to-end ISO 27001:2022 implementation for Canadian SMBs. We scope your ISMS, write 22 bilingual policies, roll out all 93 Annex A controls, and walk you through Stage 1 and Stage 2 certification audits — fixed-fee, with a documented 100% first-attempt pass rate.
The international standard for information security management.
ISO 27001 — formally ISO/IEC 27001:2022 — is the international standard that specifies the requirements for an Information Security Management System (ISMS). It is the most widely recognized security certification in the world, required by most enterprise procurement teams, regulated industries, and large SaaS customers.
An ISMS is the documented set of policies, procedures, and controls an organization uses to manage information security risk. ISO 27001 certification demonstrates to customers, auditors, regulators, and insurers that your organization has independently verified controls in place to protect the confidentiality, integrity, and availability of your data.
The 2022 revision of the standard — published October 2022 — consolidated the previous 114 Annex A controls into 93 controls across four themes: Organizational, People, Physical, and Technological. Organizations certified against the 2013 version must transition to ISO 27001:2022 by 31 October 2025.
Why ISO 27001 certification matters in 2026
Canadian SMBs increasingly need ISO 27001 certification to:
- Win enterprise and government contracts. Most Canadian federal RFPs and large corporate procurement requirements now list ISO 27001 as mandatory or strongly preferred.
- Answer vendor security questionnaires at speed. A certified ISMS replaces weeks of per-customer questionnaire work with a single attestation.
- Satisfy Quebec Law 25 and PIPEDA. ISO 27001 does not replace privacy law, but its clause-level alignment makes compliance with Law 25 and PIPEDA materially faster.
- Obtain cyber insurance at reasonable rates. Most Canadian cyber insurers now discount premiums for ISO 27001 or SOC 2 certified organizations.
- Harden operations beyond the audit. A well-scoped ISMS creates a year-round cadence of risk reviews, control testing, and management attention that survives long after the certificate is issued.
“ISO 27001 is not a checklist. It’s a commitment to run a business that deserves its customers’ data.”
What you need to achieve ISO 27001 certification
Every ISO 27001:2022 certification audit examines seven mandatory documents and the implementation of applicable Annex A controls. At minimum, your ISMS must include:
- Scope statement — the boundary of your ISMS (systems, locations, people, data)
- Information security policy — the top-level policy signed by leadership
- Risk assessment methodology and risk register with a documented treatment plan
- Statement of Applicability (SoA) — the single most reviewed artifact in the audit
- Evidence of control implementation across all applicable Annex A controls
- Internal audit report and management review records
- Continual improvement and corrective action logs
Our ISO 27001 implementation engagements deliver every one of these artifacts, reviewed by a certified ISO 27001 Lead Auditor before they reach your certification body.
Six phases, each with a signed exit criterion.
Predictable, fixed-fee phases. We don’t bill by the hour, and we don’t move to the next phase until your team and ours have signed off on the current one. Most Canadian SMBs reach Stage 2 certification in eleven to twelve months.
Gap assessment & ISMS scoping
Structured review of your current security posture against ISO 27001:2022. Interviews, evidence walk, and documented gaps scored by control. Finalized ISMS scope statement.
Risk methodology & risk register
Risk assessment methodology, asset inventory, threat library, and a fully scored risk register with documented treatment options. Aligned with ISO 31000 where applicable.
Statement of Applicability & policy library
Complete Statement of Applicability (SoA) covering all 93 Annex A controls with justified inclusions and exclusions. Twenty-two bilingual policies and supporting procedures, signed off.
Annex A control implementation
Rollout of all applicable Annex A controls with named owners, evidence cadence, and automated workflows in your GRC platform of choice — Vanta, Drata, Sprinto, or a properly-configured alternative.
Internal audit & management review
Independent internal audit against ISO 27001:2022, nonconformity register with corrective action plans, and a formal management review of ISMS effectiveness. Stage 1 readiness assessment.
Certification audit · Stage 1 & Stage 2
Shepherding through both stages of the certification audit with your accredited certification body. Stage 1 documentation review, then Stage 2 on-site/virtual audit. Closing nonconformities and certificate issuance.
All 93 controls, mapped to owners and evidence.
The 2022 revision consolidates the prior 114 controls into 93, organized across four themes. Our Statement of Applicability documents every control, its justification for inclusion or exclusion, and the specific evidence your certification body will review.
Organizational controls
Policies, roles and responsibilities, supplier and cloud-service agreements, threat intelligence, information classification, and secure information transfer.
People controls
Pre-employment screening, terms of employment, awareness and training, disciplinary process, remote work, and responsibilities after employment.
Physical controls
Security perimeters, physical entry, equipment protection, clear-desk and clear-screen, secure disposal, supporting utilities, and cabling security.
Technological controls
Access management, cryptography, logging and monitoring, vulnerability management, secure software development, backups, and network security.
How ISO 27001:2022 compares to neighbouring frameworks.
| Dimension | ISO 27001:2022 | SOC 2 Type II | Quebec Law 25 |
|---|---|---|---|
| Scope | Information security management system | Service-organization controls | Personal-information protection law |
| Geography | International · widely recognized | North America-centric | Quebec-only (applies globally to QC data) |
| Certification vs attestation | Third-party certificate | CPA attestation report | Statutory compliance · no certificate |
| Typical timeline | 11–12 months | 9–14 months | 4–6 months (alongside ISMS) |
| Core artifact | Statement of Applicability + ISMS | Description + trust-service criteria | PIA / DPIA + consent flows |
| Renewal cadence | Annual surveillance · 3-year recert | Annual | Continuous statutory obligation |
| Noordev covers | ✓ Full implementation | ✓ Parallel to ISO 27001 | ✓ Bundled with ISMS for QC clients |
Measured across thirty-one ISMS engagements.
Every Noordev ISO 27001 engagement closes with a written measurement of what improved. These are medians across our portfolio from 2019 to 2026.
Zero to ISO 27001 certified, in eleven months.
Meridian’s enterprise sales pipeline was stalling on vendor security questionnaires. We delivered a full ISO 27001:2022 implementation in eleven months, from gap assessment through Stage 2 certification — zero major nonconformities, two minor findings closed during the audit window.
ISO 27001 explained.
The most common questions we receive from Canadian SMBs considering ISO 27001 certification. For anything else, our team is one call away.
How long does ISO 27001 certification take in Canada?
For a Canadian SMB of 20–200 employees, ISO 27001:2022 certification typically takes 11–12 months from kickoff to Stage 2 audit pass. Our fastest documented engagement, Meridian Bank in Toronto, reached certification in 11 months with zero major nonconformities. Larger or more complex organizations often take 14–18 months.
How much does ISO 27001 implementation cost?
A gap assessment starts at $12,000 CAD. Full ISO 27001:2022 implementations range from $85,000 to $180,000 CAD depending on organization size, ISMS scope, and whether a fractional CISO is included. Certification body audit fees are additional and typically run $18,000–$35,000 for the first three-year cycle. We send a fixed-fee proposal after the gap assessment — no hourly billing.
What is the difference between ISO 27001:2022 and the 2013 version?
ISO 27001:2022 is the current revision of the standard. It consolidates the previous 114 Annex A controls into 93 controls organized across four themes: Organizational (A.5), People (A.6), Physical (A.7), and Technological (A.8). Eleven controls are new, including threat intelligence, information security for cloud services, and data masking. Existing ISO 27001:2013 certificates must transition to :2022 by 31 October 2025.
Can ISO 27001 and SOC 2 Type II be done together?
Yes. Approximately 85% of the work overlaps between ISO 27001 and SOC 2 Type II. We write one policy library, one control matrix, and one evidence workflow that satisfies both audits. Parallel implementation usually adds 6–8 weeks to an ISO 27001 project, compared to doing SOC 2 separately afterward — a significant cost and effort saving.
Does ISO 27001 cover Quebec Law 25 compliance?
ISO 27001 significantly overlaps with Quebec Law 25 but does not fully replace it. Law 25 requires specific Canadian privacy artifacts — DPIAs, consent flows, breach-notification procedures, and a named privacy officer. For Québec clients we bundle Law 25 compliance into the ISMS rollout at no additional cost; most of the documentation maps directly to Annex A controls A.5.34 (Privacy and PII) and A.5.33 (Protection of records).
Which certification body should we use?
We are not a certification body — by design, implementers cannot also certify. We prepare you for Stage 1 and Stage 2 audits and recommend three accredited certification bodies that have worked well for our Canadian clients: Schellman, BSI, and ISED-accredited Canadian CBs. Final selection is yours; we help you evaluate fit and pricing.
What is an ISMS?
An Information Security Management System (ISMS) is the documented set of policies, procedures, controls, and processes an organization uses to protect the confidentiality, integrity, and availability of its information assets. ISO 27001 is the international standard that defines the requirements for a certifiable ISMS.
What is the Statement of Applicability (SoA)?
The Statement of Applicability is a mandatory ISO 27001 document that lists all 93 Annex A controls, indicates which apply to your organization, and justifies any exclusions. It is the single most reviewed artifact in the Stage 2 certification audit. Our SoA template has been through 31 successful audits.
Do you work outside Canada?
Yes. We deliver ISO 27001 implementation engagements from our offices in Montréal, Toronto, Miami, and Rabat. Canadian clients are our largest segment, followed by North-African SMBs serving European customers who require ISO 27001. All engagements are delivered in English, French, or Arabic.
Cybersecurity & GRC
Our full security practice — vCISO, risk management, SOC 2, awareness training.
Explore Security → TrainingISO 27001 Internal Auditor
Two-week bilingual cohort: ISO 27001 clauses, Annex A, audit planning and reporting.
View catalog → Case studyMeridian Bank · Toronto
Full ISO 27001:2022 certification in eleven months, zero major nonconformities.
Read the case → AboutWho is Noordev?
Fourteen years, four partners, offices in Montréal, Toronto, Miami, and Rabat.
Meet the team →Book a free 45-minute gap conversation.
Tell us what’s driving the timeline — a customer requirement, a board directive, a transition from ISO 27001:2013 — and we’ll tell you, honestly, what the next three months should look like. No sales pitch, no discovery-call theatre.
ISO 27001 implementation, cybersecurity GRC, and Odoo ERP consulting for Canadian and North-African SMBs since 2012.
Services
Offices
- Montréal · HQ
- Toronto
- Miami
- Rabat