• Now booking Q3 · Montréal · Toronto · Miami · Rabat · • Odoo 17 migrations scheduling 6 weeks out
● ISO 27001:2013 transitions due 31 October 2025 — book your 2022 upgrade gap call
Home / Security / ISO 27001 Implementation
Auditor's hand stamping a bound ISMS audit report with a brass seal on a walnut desk, open standard with crimson ribbon beside it
● ISO 27001:2022 · ISMS · Certification · Canada

ISO 27001 implementation and certification, in eleven months

End-to-end ISO 27001:2022 implementation for Canadian SMBs. We scope your ISMS, write 22 bilingual policies, roll out all 93 Annex A controls, and walk you through Stage 1 and Stage 2 certification audits — fixed-fee, with a documented 100% first-attempt pass rate.

● 31 ISMS implementations ● 100% Stage 2 first-pass ● EN · FR · AR ● Fixed-fee, not T&M
Book a free gap assessment → See the 12-month path Reply in 1 business day · No sales pitch
What is ISO 27001?

The international standard for information security management.

Open ring binder with navy tabbed dividers and one crimson tab, fountain pen resting on the page, brass ruler beside on a slate desk
The ISMS · 7 mandatory documents

ISO 27001 — formally ISO/IEC 27001:2022 — is the international standard that specifies the requirements for an Information Security Management System (ISMS). It is the most widely recognized security certification in the world, required by most enterprise procurement teams, regulated industries, and large SaaS customers.

An ISMS is the documented set of policies, procedures, and controls an organization uses to manage information security risk. ISO 27001 certification demonstrates to customers, auditors, regulators, and insurers that your organization has independently verified controls in place to protect the confidentiality, integrity, and availability of your data.

The 2022 revision of the standard — published October 2022 — consolidated the previous 114 Annex A controls into 93 controls across four themes: Organizational, People, Physical, and Technological. Organizations certified against the 2013 version must transition to ISO 27001:2022 by 31 October 2025.

Why ISO 27001 certification matters in 2026

Canadian SMBs increasingly need ISO 27001 certification to:

  • Win enterprise and government contracts. Most Canadian federal RFPs and large corporate procurement requirements now list ISO 27001 as mandatory or strongly preferred.
  • Answer vendor security questionnaires at speed. A certified ISMS replaces weeks of per-customer questionnaire work with a single attestation.
  • Satisfy Quebec Law 25 and PIPEDA. ISO 27001 does not replace privacy law, but its clause-level alignment makes compliance with Law 25 and PIPEDA materially faster.
  • Obtain cyber insurance at reasonable rates. Most Canadian cyber insurers now discount premiums for ISO 27001 or SOC 2 certified organizations.
  • Harden operations beyond the audit. A well-scoped ISMS creates a year-round cadence of risk reviews, control testing, and management attention that survives long after the certificate is issued.
“ISO 27001 is not a checklist. It’s a commitment to run a business that deserves its customers’ data.”

What you need to achieve ISO 27001 certification

Every ISO 27001:2022 certification audit examines seven mandatory documents and the implementation of applicable Annex A controls. At minimum, your ISMS must include:

  • Scope statement — the boundary of your ISMS (systems, locations, people, data)
  • Information security policy — the top-level policy signed by leadership
  • Risk assessment methodology and risk register with a documented treatment plan
  • Statement of Applicability (SoA) — the single most reviewed artifact in the audit
  • Evidence of control implementation across all applicable Annex A controls
  • Internal audit report and management review records
  • Continual improvement and corrective action logs

Our ISO 27001 implementation engagements deliver every one of these artifacts, reviewed by a certified ISO 27001 Lead Auditor before they reach your certification body.

12-month implementation path

Six phases, each with a signed exit criterion.

Predictable, fixed-fee phases. We don’t bill by the hour, and we don’t move to the next phase until your team and ours have signed off on the current one. Most Canadian SMBs reach Stage 2 certification in eleven to twelve months.

Phase 01Month 1

Gap assessment & ISMS scoping

Structured review of your current security posture against ISO 27001:2022. Interviews, evidence walk, and documented gaps scored by control. Finalized ISMS scope statement.

Deliverables Gap assessment report ISMS scope statement Context & interested parties
Exit criterion Scope statement signed by executive sponsor. Gap report reviewed with stakeholders.
Phase 02Month 2

Risk methodology & risk register

Risk assessment methodology, asset inventory, threat library, and a fully scored risk register with documented treatment options. Aligned with ISO 31000 where applicable.

Deliverables Risk methodology document Asset inventory Risk register & treatment plan
Exit criterion Risk register approved by risk committee. Residual risks within stated tolerance.
Phase 03Month 3

Statement of Applicability & policy library

Complete Statement of Applicability (SoA) covering all 93 Annex A controls with justified inclusions and exclusions. Twenty-two bilingual policies and supporting procedures, signed off.

Deliverables Statement of Applicability 22 policies (EN/FR) Standards & procedures
Exit criterion SoA and policies ratified by management. Version-controlled repository in place.
Phase 04Months 4–8

Annex A control implementation

Rollout of all applicable Annex A controls with named owners, evidence cadence, and automated workflows in your GRC platform of choice — Vanta, Drata, Sprinto, or a properly-configured alternative.

Deliverables Control-to-evidence matrix GRC tool configuration Awareness training · all staff
Exit criterion All applicable Annex A controls operating. Evidence accumulated for 90+ days.
Phase 05Months 9–10

Internal audit & management review

Independent internal audit against ISO 27001:2022, nonconformity register with corrective action plans, and a formal management review of ISMS effectiveness. Stage 1 readiness assessment.

Deliverables Internal audit report NC register & CAPs Management review minutes
Exit criterion All majors closed. Minors with CAPs scheduled. Stage 1 readiness confirmed.
Phase 06Months 11–12

Certification audit · Stage 1 & Stage 2

Shepherding through both stages of the certification audit with your accredited certification body. Stage 1 documentation review, then Stage 2 on-site/virtual audit. Closing nonconformities and certificate issuance.

Deliverables Audit prep pack Evidence requests answered ISO 27001:2022 certificate
Exit criterion ISO 27001:2022 certificate issued. Year-1 surveillance plan agreed.
Annex A · ISO 27001:2022

All 93 controls, mapped to owners and evidence.

The 2022 revision consolidates the prior 114 controls into 93, organized across four themes. Our Statement of Applicability documents every control, its justification for inclusion or exclusion, and the specific evidence your certification body will review.

A.5 · Organizational

Organizational controls

Policies, roles and responsibilities, supplier and cloud-service agreements, threat intelligence, information classification, and secure information transfer.

Controls37
A.6 · People

People controls

Pre-employment screening, terms of employment, awareness and training, disciplinary process, remote work, and responsibilities after employment.

Controls8
A.7 · Physical

Physical controls

Security perimeters, physical entry, equipment protection, clear-desk and clear-screen, secure disposal, supporting utilities, and cabling security.

Controls14
A.8 · Technological

Technological controls

Access management, cryptography, logging and monitoring, vulnerability management, secure software development, backups, and network security.

Controls34
ISO 27001 vs SOC 2 vs Law 25

How ISO 27001:2022 compares to neighbouring frameworks.

Dimension ISO 27001:2022 SOC 2 Type II Quebec Law 25
Scope Information security management system Service-organization controls Personal-information protection law
Geography International · widely recognized North America-centric Quebec-only (applies globally to QC data)
Certification vs attestation Third-party certificate CPA attestation report Statutory compliance · no certificate
Typical timeline 11–12 months 9–14 months 4–6 months (alongside ISMS)
Core artifact Statement of Applicability + ISMS Description + trust-service criteria PIA / DPIA + consent flows
Renewal cadence Annual surveillance · 3-year recert Annual Continuous statutory obligation
Noordev covers ✓ Full implementation ✓ Parallel to ISO 27001 ✓ Bundled with ISMS for QC clients
What ISO 27001 delivers

Measured across thirty-one ISMS engagements.

Every Noordev ISO 27001 engagement closes with a written measurement of what improved. These are medians across our portfolio from 2019 to 2026.

11mo
Median time to certification
100%
Stage 2 first-attempt pass rate
3.2×
Faster vendor questionnaire turnaround
$2.1M
Median enterprise pipeline unblocked
Glass bank tower in Toronto's financial district at blue hour with a crimson-lit lobby canopy
M
Financial services Toronto · 120 ppl ISO 27001:2022
Case study · Meridian Bank

Zero to ISO 27001 certified, in eleven months.

Meridian’s enterprise sales pipeline was stalling on vendor security questionnaires. We delivered a full ISO 27001:2022 implementation in eleven months, from gap assessment through Stage 2 certification — zero major nonconformities, two minor findings closed during the audit window.

11mo
Gap → certified
0
Major NCs
$2.1M
Pipeline unblocked
Frequently asked questions

ISO 27001 explained.

The most common questions we receive from Canadian SMBs considering ISO 27001 certification. For anything else, our team is one call away.

How long does ISO 27001 certification take in Canada?

For a Canadian SMB of 20–200 employees, ISO 27001:2022 certification typically takes 11–12 months from kickoff to Stage 2 audit pass. Our fastest documented engagement, Meridian Bank in Toronto, reached certification in 11 months with zero major nonconformities. Larger or more complex organizations often take 14–18 months.

How much does ISO 27001 implementation cost?

A gap assessment starts at $12,000 CAD. Full ISO 27001:2022 implementations range from $85,000 to $180,000 CAD depending on organization size, ISMS scope, and whether a fractional CISO is included. Certification body audit fees are additional and typically run $18,000–$35,000 for the first three-year cycle. We send a fixed-fee proposal after the gap assessment — no hourly billing.

What is the difference between ISO 27001:2022 and the 2013 version?

ISO 27001:2022 is the current revision of the standard. It consolidates the previous 114 Annex A controls into 93 controls organized across four themes: Organizational (A.5), People (A.6), Physical (A.7), and Technological (A.8). Eleven controls are new, including threat intelligence, information security for cloud services, and data masking. Existing ISO 27001:2013 certificates must transition to :2022 by 31 October 2025.

Can ISO 27001 and SOC 2 Type II be done together?

Yes. Approximately 85% of the work overlaps between ISO 27001 and SOC 2 Type II. We write one policy library, one control matrix, and one evidence workflow that satisfies both audits. Parallel implementation usually adds 6–8 weeks to an ISO 27001 project, compared to doing SOC 2 separately afterward — a significant cost and effort saving.

Does ISO 27001 cover Quebec Law 25 compliance?

ISO 27001 significantly overlaps with Quebec Law 25 but does not fully replace it. Law 25 requires specific Canadian privacy artifacts — DPIAs, consent flows, breach-notification procedures, and a named privacy officer. For Québec clients we bundle Law 25 compliance into the ISMS rollout at no additional cost; most of the documentation maps directly to Annex A controls A.5.34 (Privacy and PII) and A.5.33 (Protection of records).

Which certification body should we use?

We are not a certification body — by design, implementers cannot also certify. We prepare you for Stage 1 and Stage 2 audits and recommend three accredited certification bodies that have worked well for our Canadian clients: Schellman, BSI, and ISED-accredited Canadian CBs. Final selection is yours; we help you evaluate fit and pricing.

What is an ISMS?

An Information Security Management System (ISMS) is the documented set of policies, procedures, controls, and processes an organization uses to protect the confidentiality, integrity, and availability of its information assets. ISO 27001 is the international standard that defines the requirements for a certifiable ISMS.

What is the Statement of Applicability (SoA)?

The Statement of Applicability is a mandatory ISO 27001 document that lists all 93 Annex A controls, indicates which apply to your organization, and justifies any exclusions. It is the single most reviewed artifact in the Stage 2 certification audit. Our SoA template has been through 31 successful audits.

Do you work outside Canada?

Yes. We deliver ISO 27001 implementation engagements from our offices in Montréal, Toronto, Miami, and Rabat. Canadian clients are our largest segment, followed by North-African SMBs serving European customers who require ISO 27001. All engagements are delivered in English, French, or Arabic.

● Start your ISO 27001 engagement

Book a free 45-minute gap conversation.

Tell us what’s driving the timeline — a customer requirement, a board directive, a transition from ISO 27001:2013 — and we’ll tell you, honestly, what the next three months should look like. No sales pitch, no discovery-call theatre.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.