ISO 27001 Readiness for Growing Businesses

BlueKey IT helps businesses prepare for ISO/IEC 27001 certification. We support your information security management system, implement the technical controls, and build the documentation and records so you are ready for your certification audit.

ISO/IEC 27001:2022

  • ISMS and risk assessment support
  • Annex A technical controls
  • Records for your certification audit
Google

Trusted by Businesses Across the U.S.

Real reviews from real customers. See why businesses choose BlueKey IT.

Read All Reviews
Posted on Google Google
Nilam Khurana profile picture
Nilam Khurana
September 12, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Bluekey IT has been helping our businesses for years. From setting up offices, setting up security measures and continued monitoring to make sure we are safe, they have been there. I would highly recommend them.
Posted on Google Google
Katlyn Kaiser profile picture
Katlyn Kaiser
July 31, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I have had a great experience working with BlueKey IT. Their team is knowledgeable, responsive, and always willing to go the extra mile to ensure issues are resolved quickly.
Posted on Google Google
Corey Nash profile picture
Corey Nash
July 29, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Bluekey has been keeping my business systems running smoothly for nearly a decade. If my systems are down, I cannot make money, when I call Bluekey with a problem they are always quick to answer the phone and give me back up and going in short order. I am so thankful to have them on my side.
Posted on Google Google
Anthony Weinberg profile picture
Anthony Weinberg
July 27, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Amazing team of tech professionals, always there when you need them!
Posted on Google Google
Amy Baer profile picture
Amy Baer
July 27, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I own a large company with over 100 employees. We have used BlueKey for many years area and very happy with the service they provide. Their Management and staff are all amazing.
Posted on Google Google
Undrea Smith profile picture
Undrea Smith
July 27, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
We've worked with Blue Key for well over a decade, and they've been much more than just an IT company. As our firm has grown, they've been a true technology partner, helping us upgrade our systems, improve security, and make sure our infrastructure keeps pace with our business. One of the things we value most is their responsiveness. Our team is spread across the country, so having 24/7 support that anyone on our team can access is incredibly important. No matter when an issue comes up, Blue Key is there to help quickly and professionally. If you're looking for an IT company that is proactive, knowledgeable, and genuinely invested in your success, I highly recommend Blue Key. They've played an important role in supporting our growth, and we're grateful for the partnership.
Posted on Google Google
David Robinson profile picture
David Robinson
July 27, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
BlueKey It Services are very knowledgeable and caring. They provide white glove service and top of the line support for all their clients needs. They are all trained to the highest level in their respective industry and I would recommend them to anyone that needs IT services.
Posted on Google Google
Ed Wiegner profile picture
Ed Wiegner
April 8, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Had an AMAZING iT support experience with Alex at Blu Key IT today. In over 25 years this IT support professional wen above and beyond. Patient focused kind focused and understanding. Jason's following up just appreciate that kind of service and knowledge. Thank You
Posted on Google Google
C W Macc profile picture
C W Macc
April 2, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Harrison at BlueKeyIT is quick to answer, courteous, knowledgeable, and professional. I continue to be 100% satisfied with the genuine Customer Care provided by the entire Team at BlueKeyIT. Highly recommended!

Build a Security Program an Auditor Can Verify

ISO 27001 certification rewards companies that manage security as a system: defined scope, assessed risks, selected controls, and records that prove it all works. BlueKey IT supports the management system, implements the technical controls, and builds the evidence, so you are ready for your certification body.

ISMS support · Technical controls · Documentation and records · 200+ customers and 6,000+ endpoints managed

ISO 27001 in Plain Terms

ISO/IEC 27001 is the international standard for an information security management system, or ISMS. It does not prescribe a fixed list of tools. It requires you to understand your context, assess your risks, choose controls that treat them, operate those controls, measure the results, and keep improving. Certification means an independent, accredited certification body has audited your ISMS against the standard.

The standard has two parts. The management system clauses, 4 to 10, are mandatory. Annex A is a reference set of 93 controls from which you select based on your risk assessment.

Edition status as of October 2026: ISO/IEC 27001:2022 is the current edition, with Amendment 1:2024 adding climate change considerations to the context clauses. The transition period for the 2013 edition ended on October 31, 2025, so valid certificates reference the 2022 edition. Only an accredited certification body can certify your business, and BlueKey IT is not one.

The Management System Clauses

Clauses 4 to 10 are where most of the documented information the standard requires comes from. Several are about leadership and management decisions that only your organization can own. We support the technical inputs and the records.

ClauseWhat it requiresHow BlueKey IT helps
4 Context of the organizationUnderstand internal and external issues, interested parties and their requirements, and define the scope of the ISMSTechnical scoping input: systems, locations, and services in scope
5 LeadershipTop management commitment, an information security policy, and assigned roles and responsibilitiesPolicy drafting and role documentation. Decisions stay with your leadership
6 PlanningRisk assessment and treatment process, the Statement of Applicability, security objectives, and planning for changesTechnical risk inputs, control selection support, and tracked treatment plans
7 SupportResources, competence, awareness, communication, and control of documented informationSecurity awareness training, training records, and document control support
8 OperationCarrying out the plans, running risk assessments, and implementing the risk treatment planImplementation of the technical controls and operational procedures
9 Performance evaluationMonitoring and measurement, internal audit, and management reviewMonitoring reports, metrics, and evidence for internal audit and management review
10 ImprovementCorrective action when nonconformities occur, and continual improvementCorrective action tracking and remediation of technical findings

Annex A: 93 Controls in Four Themes

The 2022 edition reorganized Annex A from 114 controls in 14 clauses into 93 controls in four themes. Each control has attributes and a stated purpose in ISO/IEC 27002, which provides implementation guidance. Here is how the themes map to IT work.

ThemeControlsWhat it coversHow BlueKey IT helps
Organizational37Policies, roles, asset management, access control policy, supplier relationships, incident management, business continuity, and legal and compliancePolicies and documentation, asset inventory, vendor review support, incident response, and continuity planning
People8Screening, terms of employment, awareness and training, disciplinary process, and remote workingSecurity awareness training and employee onboarding and offboarding processes
Physical14Secure areas, physical monitoring, equipment security, and secure disposalDevice inventory, workstation security, and secure disposal of retired equipment
Technological34Endpoint security, access rights, authentication, encryption, logging, monitoring, vulnerability management, configuration, backup, and secure developmentMFA, encryption, 24/7 monitoring, endpoint protection, patching, backups, and secure configurations

The 11 controls that are new in 2022

If your last ISMS review used the 2013 edition, these are the controls to look at first.

ControlWhat it expects
5.7 Threat intelligenceCollect and analyze information about threats to inform risk decisions
5.23 Information security for use of cloud servicesDefine processes to acquire, use, manage, and exit cloud services
5.30 ICT readiness for business continuityPlan and test ICT recovery against business continuity objectives
7.4 Physical security monitoringMonitor premises for unauthorized physical access
8.9 Configuration managementEstablish, document, and review secure configurations for systems and networks
8.10 Information deletionDelete information when it is no longer required
8.11 Data maskingMask data according to access control and business requirements
8.12 Data leakage preventionApply measures to systems and networks that handle sensitive information
8.16 Monitoring activitiesMonitor systems for anomalous behavior and take action on it
8.23 Web filteringManage access to external websites to reduce exposure to malicious content
8.28 Secure codingApply secure coding principles to software development

How Control Selection Works

ISO 27001 does not ask you to implement everything in Annex A. It asks you to decide, based on risk, and to show your reasoning.

1. Assess risks

You define a risk assessment process, identify risks to the confidentiality, integrity, and availability of information in scope, and rate them against criteria you set.

2. Choose treatments and controls

For each risk you choose a treatment, such as reducing it with controls, accepting it, avoiding it, or sharing it. You determine the controls needed and compare them with Annex A to check you have not missed any.

3. Write the Statement of Applicability

The Statement of Applicability lists each Annex A control, states whether it is implemented, and justifies any exclusion. It ties your risk decisions to the controls your auditor will test.

4. Operate and measure

You implement the risk treatment plan, run the controls, measure how they perform, and review results with management.

The Documented Information the Standard Requires

Certification auditors ask to see these records. Some are documents you write once. Others are records produced by running the ISMS.

Documented informationWhere it comes from
Scope of the ISMSClause 4.3
Information security policyClause 5.2
Risk assessment and risk treatment processesClauses 6.1.2 and 6.1.3
Statement of ApplicabilityClause 6.1.3
Information security objectives and plansClause 6.2
Evidence of competenceClause 7.2
Risk assessment and risk treatment resultsClauses 8.2 and 8.3
Monitoring and measurement resultsClause 9.1
Internal audit program and resultsClause 9.2
Management review resultsClause 9.3
Nonconformities and corrective actionsClause 10

The Path to Certification

  • Step 1Define scope and context

    Decide which parts of the business, systems, and locations the ISMS covers, and who your interested parties are.

  • Step 2Assess risk and select controls

    Run the risk assessment, build the treatment plan, and write the Statement of Applicability.

  • Step 3Implement and document

    Put the technical and organizational controls in place and create the required documented information.

  • Step 4Run the ISMS and gather records

    Operate the controls, then complete an internal audit and a management review.

  • Step 5Select a certification body

    Choose a body accredited for ISO/IEC 27001 and agree on scope and timing.

  • Step 6Certification audit

    The body audits in stages: a review of documentation and readiness, then an audit of implementation and effectiveness. Nonconformities must be corrected.

  • OngoingSurveillance and recertification

    Surveillance audits are performed at least once each calendar year, with recertification at the end of the three-year cycle.

Certification bodies are accredited by national accreditation bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1. Ask any body you consider to show its accreditation for ISO/IEC 27001.

What’s Included in BlueKey ISO 27001 Readiness

  • Laptop showing analytics charts during a technology assessment
    Readiness and gap assessmentA review of your environment against the standard, with a prioritized plan for what to close before the audit.
  • Business team meeting to plan IT strategy
    ISMS and risk assessment supportvCISO support for your management system, risk assessment, and treatment plan.
  • Smartphone showing a lock screen for account security
    Access control and MFAUnique accounts, role-based access, multi-factor authentication, and documented access reviews.
  • Green code on a screen representing encrypted backup data
    Encryption and backupEncryption for devices, email, and backups, with monitored backup and recovery testing.
  • Security operations workstation with multiple monitors showing code
    Logging and monitoring24/7 monitoring and centralized logging that show how your controls operate.
  • Software update in progress on a laptop screen
    Patching and vulnerability managementManaged patching and regular vulnerability scans, with fixes tracked to completion.
  • Padlock on a keyboard representing security awareness
    Security awareness trainingOngoing staff training with records that support the people controls.
  • Binder of written security policies and procedures on a desk
    Policies and Statement of Applicability supportWritten policies and procedures, and the records your certification body will ask to see.

How It Works

  • 1. Assess

    We define the scope with you, review your current controls, and document the gaps against the standard.

  • 2. Implement and document

    We put the technical controls in place and build the policies, procedures, and records that support them.

  • 3. Prepare and maintain

    We support your internal review, hand off to your certification body, and keep controls running between annual audits.

What You Receive

  • Scope and asset inventory

    Technical inputs for ISMS scope, with systems, services, and locations documented.

  • Gap report and remediation plan

    Findings against clauses 4 to 10 and the Annex A controls, with owners and status.

  • Risk assessment inputs

    Technical risks, likelihood and impact notes, and a treatment plan you can approve.

  • Statement of Applicability support

    Control-by-control implementation status with the evidence behind it.

  • Control implementation records

    Evidence of MFA, encryption, logging, monitoring, backup, and patching configuration.

  • Policy and procedure set

    Security policies and operating procedures matched to how your company works.

  • Training records

    Awareness training with completion reports.

  • Audit support

    Help answering technical evidence requests during internal and certification audits.

Support requests follow our standard help desk response times: 1 business hour for critical issues, 2 hours for high, 4 hours for medium, and 8 hours for low priority requests.

Common Gaps Before a First ISO 27001 Audit

  • Scope that is too broad or vague

    The ISMS tries to cover the whole company without clear boundaries, which multiplies audit work.

  • Risk assessment without a method

    Risks are listed, but no criteria explain how likelihood and impact were scored.

  • Statement of Applicability copied from a template

    Controls are marked implemented without evidence that they are.

  • No internal audit or management review

    The two records every certification auditor asks for have never been produced.

  • New 2022 controls overlooked

    Threat intelligence, configuration management, data deletion, and web filtering have no owner or evidence.

  • Policies disconnected from practice

    Written procedures describe a process that does not match what staff actually do.

Who It’s For

Businesses whose customers, partners, or markets expect ISO 27001 certification, including technology, professional services, and manufacturing companies. Already working with an ISO consultant? We work alongside them. Have an in-house IT team? See co-managed IT. Need ongoing security leadership? See our vCISO packages.

Pricing

Readiness projects are quoted individually. Ongoing controls and support can be added to a managed IT or co-managed IT plan. Certification body fees are paid separately.

ISO 27001 Readiness FAQ

Can BlueKey IT certify us to ISO 27001?

No. Only an independent certification body that is accredited for ISO/IEC 27001 can issue a certificate, and a consultant or software vendor cannot. We prepare your environment, documentation, and records, and work alongside the certification body you choose.

What is an information security management system?

An ISMS is the set of policies, processes, roles, and records you use to manage information security risk. ISO 27001 requires you to define its scope, assess and treat risks, set objectives, measure results, audit yourself, review it with management, and improve it over time.

Do we have to implement all 93 Annex A controls?

No. You determine the controls needed to treat your risks, compare them with Annex A, and record in your Statement of Applicability whether each control is implemented and why any are excluded. The management system clauses, 4 to 10, are mandatory.

What is a Statement of Applicability?

It is a documented list of the Annex A controls, with a statement of whether each is implemented and a justification for any that are excluded. Certification auditors use it to understand your scope and the decisions behind it.

Which edition of ISO 27001 is current?

ISO/IEC 27001:2022 is current, with Amendment 1:2024 on climate action changes. The transition from the 2013 edition ended on October 31, 2025, so valid certificates now reference the 2022 edition.

What changed between the 2013 and 2022 editions?

The structure of Annex A was reorganized from 114 controls in 14 clauses to 93 controls in four themes. Eleven controls are new, 24 were merged from existing controls, and 58 were updated. The management system clauses also gained a requirement to plan changes to the ISMS, in clause 6.3.

How long does an ISO 27001 certificate last?

Certificates run on a three-year cycle. The certification body performs surveillance audits at least once each calendar year, and a recertification audit at the end of the cycle. The certificate covers the scope you define, not necessarily your whole company.

What is the relationship between ISO 27001 and ISO 27002?

ISO 27001 specifies the requirements for an ISMS and is the standard you certify against. ISO 27002 provides guidance on implementing the controls listed in Annex A of ISO 27001. Both were updated in 2022 and share the same 93 controls and four themes.

How does ISO 27001 differ from SOC 2?

ISO 27001 certifies your management system and is issued by an accredited certification body. SOC 2 is an attestation report on your controls issued by a CPA firm. Many controls overlap, so work for one often supports the other. See our page on SOC 2 readiness.

What does the certification audit involve?

Initial certification is done in stages. The certification body reviews your documentation and readiness, then audits whether the ISMS is implemented and effective across your scope. Findings are classified, and you must correct nonconformities before a certificate is issued.

Can you manage our IT and ISO 27001 readiness together?

Yes. Many companies add ISO 27001 readiness to a managed or co-managed IT plan so monitoring, patching, backups, access reviews, and documentation are handled in one place.

Talk With a Compliance Specialist

Tell us what your customers and partners expect. We will explain what ISO 27001 readiness means for your environment and put together a clear plan and quote.

Related compliance frameworks: CMMC compliance, HIPAA IT compliance, FTC Safeguards Rule compliance, PCI DSS compliance, and SOC 2 readiness. See also cybersecurity insurance readiness, cybersecurity and compliance, endpoint security, backup and disaster recovery, and Microsoft 365 and Google Workspace.

Last updated: October 2026. Based on ISO/IEC 27001:2022 with Amendment 1:2024, and IAF guidance on the transition from the 2013 edition.