BlueKey IT helps businesses prepare for ISO/IEC 27001 certification. We support your information security management system, implement the technical controls, and build the documentation and records so you are ready for your certification audit.
Real reviews from real customers. See why businesses choose BlueKey IT.
Read All Reviews →Posted on Google![]()
Nilam KhuranaSeptember 12, 2026Trustindex verifies that the original source of the review is Google.
Bluekey IT has been helping our businesses for years. From setting up offices, setting up security measures and continued monitoring to make sure we are safe, they have been there. I would highly recommend them.Posted on Google![]()
Katlyn KaiserJuly 31, 2026Trustindex verifies that the original source of the review is Google.
I have had a great experience working with BlueKey IT. Their team is knowledgeable, responsive, and always willing to go the extra mile to ensure issues are resolved quickly.Posted on Google![]()
Corey NashJuly 29, 2026Trustindex verifies that the original source of the review is Google.
Bluekey has been keeping my business systems running smoothly for nearly a decade. If my systems are down, I cannot make money, when I call Bluekey with a problem they are always quick to answer the phone and give me back up and going in short order. I am so thankful to have them on my side.Posted on Google![]()
Anthony WeinbergJuly 27, 2026Trustindex verifies that the original source of the review is Google.
Amazing team of tech professionals, always there when you need them!Posted on Google![]()
Amy BaerJuly 27, 2026Trustindex verifies that the original source of the review is Google.
I own a large company with over 100 employees. We have used BlueKey for many years area and very happy with the service they provide. Their Management and staff are all amazing.Posted on Google![]()
Undrea SmithJuly 27, 2026Trustindex verifies that the original source of the review is Google.
We've worked with Blue Key for well over a decade, and they've been much more than just an IT company. As our firm has grown, they've been a true technology partner, helping us upgrade our systems, improve security, and make sure our infrastructure keeps pace with our business. One of the things we value most is their responsiveness. Our team is spread across the country, so having 24/7 support that anyone on our team can access is incredibly important. No matter when an issue comes up, Blue Key is there to help quickly and professionally. If you're looking for an IT company that is proactive, knowledgeable, and genuinely invested in your success, I highly recommend Blue Key. They've played an important role in supporting our growth, and we're grateful for the partnership.Posted on Google![]()
David RobinsonJuly 27, 2026Trustindex verifies that the original source of the review is Google.
BlueKey It Services are very knowledgeable and caring. They provide white glove service and top of the line support for all their clients needs. They are all trained to the highest level in their respective industry and I would recommend them to anyone that needs IT services.Posted on Google![]()
Ed WiegnerApril 8, 2026Trustindex verifies that the original source of the review is Google.
Had an AMAZING iT support experience with Alex at Blu Key IT today. In over 25 years this IT support professional wen above and beyond. Patient focused kind focused and understanding. Jason's following up just appreciate that kind of service and knowledge. Thank YouPosted on Google![]()
C W MaccApril 2, 2026Trustindex verifies that the original source of the review is Google.
Harrison at BlueKeyIT is quick to answer, courteous, knowledgeable, and professional. I continue to be 100% satisfied with the genuine Customer Care provided by the entire Team at BlueKeyIT. Highly recommended!
ISO 27001 certification rewards companies that manage security as a system: defined scope, assessed risks, selected controls, and records that prove it all works. BlueKey IT supports the management system, implements the technical controls, and builds the evidence, so you are ready for your certification body.
ISMS support · Technical controls · Documentation and records · 200+ customers and 6,000+ endpoints managed
ISO/IEC 27001 is the international standard for an information security management system, or ISMS. It does not prescribe a fixed list of tools. It requires you to understand your context, assess your risks, choose controls that treat them, operate those controls, measure the results, and keep improving. Certification means an independent, accredited certification body has audited your ISMS against the standard.
The standard has two parts. The management system clauses, 4 to 10, are mandatory. Annex A is a reference set of 93 controls from which you select based on your risk assessment.
Edition status as of October 2026: ISO/IEC 27001:2022 is the current edition, with Amendment 1:2024 adding climate change considerations to the context clauses. The transition period for the 2013 edition ended on October 31, 2025, so valid certificates reference the 2022 edition. Only an accredited certification body can certify your business, and BlueKey IT is not one.
Clauses 4 to 10 are where most of the documented information the standard requires comes from. Several are about leadership and management decisions that only your organization can own. We support the technical inputs and the records.
| Clause | What it requires | How BlueKey IT helps |
|---|---|---|
| 4 Context of the organization | Understand internal and external issues, interested parties and their requirements, and define the scope of the ISMS | Technical scoping input: systems, locations, and services in scope |
| 5 Leadership | Top management commitment, an information security policy, and assigned roles and responsibilities | Policy drafting and role documentation. Decisions stay with your leadership |
| 6 Planning | Risk assessment and treatment process, the Statement of Applicability, security objectives, and planning for changes | Technical risk inputs, control selection support, and tracked treatment plans |
| 7 Support | Resources, competence, awareness, communication, and control of documented information | Security awareness training, training records, and document control support |
| 8 Operation | Carrying out the plans, running risk assessments, and implementing the risk treatment plan | Implementation of the technical controls and operational procedures |
| 9 Performance evaluation | Monitoring and measurement, internal audit, and management review | Monitoring reports, metrics, and evidence for internal audit and management review |
| 10 Improvement | Corrective action when nonconformities occur, and continual improvement | Corrective action tracking and remediation of technical findings |
The 2022 edition reorganized Annex A from 114 controls in 14 clauses into 93 controls in four themes. Each control has attributes and a stated purpose in ISO/IEC 27002, which provides implementation guidance. Here is how the themes map to IT work.
| Theme | Controls | What it covers | How BlueKey IT helps |
|---|---|---|---|
| Organizational | 37 | Policies, roles, asset management, access control policy, supplier relationships, incident management, business continuity, and legal and compliance | Policies and documentation, asset inventory, vendor review support, incident response, and continuity planning |
| People | 8 | Screening, terms of employment, awareness and training, disciplinary process, and remote working | Security awareness training and employee onboarding and offboarding processes |
| Physical | 14 | Secure areas, physical monitoring, equipment security, and secure disposal | Device inventory, workstation security, and secure disposal of retired equipment |
| Technological | 34 | Endpoint security, access rights, authentication, encryption, logging, monitoring, vulnerability management, configuration, backup, and secure development | MFA, encryption, 24/7 monitoring, endpoint protection, patching, backups, and secure configurations |
If your last ISMS review used the 2013 edition, these are the controls to look at first.
| Control | What it expects |
|---|---|
| 5.7 Threat intelligence | Collect and analyze information about threats to inform risk decisions |
| 5.23 Information security for use of cloud services | Define processes to acquire, use, manage, and exit cloud services |
| 5.30 ICT readiness for business continuity | Plan and test ICT recovery against business continuity objectives |
| 7.4 Physical security monitoring | Monitor premises for unauthorized physical access |
| 8.9 Configuration management | Establish, document, and review secure configurations for systems and networks |
| 8.10 Information deletion | Delete information when it is no longer required |
| 8.11 Data masking | Mask data according to access control and business requirements |
| 8.12 Data leakage prevention | Apply measures to systems and networks that handle sensitive information |
| 8.16 Monitoring activities | Monitor systems for anomalous behavior and take action on it |
| 8.23 Web filtering | Manage access to external websites to reduce exposure to malicious content |
| 8.28 Secure coding | Apply secure coding principles to software development |
ISO 27001 does not ask you to implement everything in Annex A. It asks you to decide, based on risk, and to show your reasoning.
You define a risk assessment process, identify risks to the confidentiality, integrity, and availability of information in scope, and rate them against criteria you set.
For each risk you choose a treatment, such as reducing it with controls, accepting it, avoiding it, or sharing it. You determine the controls needed and compare them with Annex A to check you have not missed any.
The Statement of Applicability lists each Annex A control, states whether it is implemented, and justifies any exclusion. It ties your risk decisions to the controls your auditor will test.
You implement the risk treatment plan, run the controls, measure how they perform, and review results with management.
Certification auditors ask to see these records. Some are documents you write once. Others are records produced by running the ISMS.
| Documented information | Where it comes from |
|---|---|
| Scope of the ISMS | Clause 4.3 |
| Information security policy | Clause 5.2 |
| Risk assessment and risk treatment processes | Clauses 6.1.2 and 6.1.3 |
| Statement of Applicability | Clause 6.1.3 |
| Information security objectives and plans | Clause 6.2 |
| Evidence of competence | Clause 7.2 |
| Risk assessment and risk treatment results | Clauses 8.2 and 8.3 |
| Monitoring and measurement results | Clause 9.1 |
| Internal audit program and results | Clause 9.2 |
| Management review results | Clause 9.3 |
| Nonconformities and corrective actions | Clause 10 |
Decide which parts of the business, systems, and locations the ISMS covers, and who your interested parties are.
Run the risk assessment, build the treatment plan, and write the Statement of Applicability.
Put the technical and organizational controls in place and create the required documented information.
Operate the controls, then complete an internal audit and a management review.
Choose a body accredited for ISO/IEC 27001 and agree on scope and timing.
The body audits in stages: a review of documentation and readiness, then an audit of implementation and effectiveness. Nonconformities must be corrected.
Surveillance audits are performed at least once each calendar year, with recertification at the end of the three-year cycle.
Certification bodies are accredited by national accreditation bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1. Ask any body you consider to show its accreditation for ISO/IEC 27001.








We define the scope with you, review your current controls, and document the gaps against the standard.
We put the technical controls in place and build the policies, procedures, and records that support them.
We support your internal review, hand off to your certification body, and keep controls running between annual audits.
Technical inputs for ISMS scope, with systems, services, and locations documented.
Findings against clauses 4 to 10 and the Annex A controls, with owners and status.
Technical risks, likelihood and impact notes, and a treatment plan you can approve.
Control-by-control implementation status with the evidence behind it.
Evidence of MFA, encryption, logging, monitoring, backup, and patching configuration.
Security policies and operating procedures matched to how your company works.
Awareness training with completion reports.
Help answering technical evidence requests during internal and certification audits.
Support requests follow our standard help desk response times: 1 business hour for critical issues, 2 hours for high, 4 hours for medium, and 8 hours for low priority requests.
The ISMS tries to cover the whole company without clear boundaries, which multiplies audit work.
Risks are listed, but no criteria explain how likelihood and impact were scored.
Controls are marked implemented without evidence that they are.
The two records every certification auditor asks for have never been produced.
Threat intelligence, configuration management, data deletion, and web filtering have no owner or evidence.
Written procedures describe a process that does not match what staff actually do.
Businesses whose customers, partners, or markets expect ISO 27001 certification, including technology, professional services, and manufacturing companies. Already working with an ISO consultant? We work alongside them. Have an in-house IT team? See co-managed IT. Need ongoing security leadership? See our vCISO packages.
Readiness projects are quoted individually. Ongoing controls and support can be added to a managed IT or co-managed IT plan. Certification body fees are paid separately.
No. Only an independent certification body that is accredited for ISO/IEC 27001 can issue a certificate, and a consultant or software vendor cannot. We prepare your environment, documentation, and records, and work alongside the certification body you choose.
An ISMS is the set of policies, processes, roles, and records you use to manage information security risk. ISO 27001 requires you to define its scope, assess and treat risks, set objectives, measure results, audit yourself, review it with management, and improve it over time.
No. You determine the controls needed to treat your risks, compare them with Annex A, and record in your Statement of Applicability whether each control is implemented and why any are excluded. The management system clauses, 4 to 10, are mandatory.
It is a documented list of the Annex A controls, with a statement of whether each is implemented and a justification for any that are excluded. Certification auditors use it to understand your scope and the decisions behind it.
ISO/IEC 27001:2022 is current, with Amendment 1:2024 on climate action changes. The transition from the 2013 edition ended on October 31, 2025, so valid certificates now reference the 2022 edition.
The structure of Annex A was reorganized from 114 controls in 14 clauses to 93 controls in four themes. Eleven controls are new, 24 were merged from existing controls, and 58 were updated. The management system clauses also gained a requirement to plan changes to the ISMS, in clause 6.3.
Certificates run on a three-year cycle. The certification body performs surveillance audits at least once each calendar year, and a recertification audit at the end of the cycle. The certificate covers the scope you define, not necessarily your whole company.
ISO 27001 specifies the requirements for an ISMS and is the standard you certify against. ISO 27002 provides guidance on implementing the controls listed in Annex A of ISO 27001. Both were updated in 2022 and share the same 93 controls and four themes.
ISO 27001 certifies your management system and is issued by an accredited certification body. SOC 2 is an attestation report on your controls issued by a CPA firm. Many controls overlap, so work for one often supports the other. See our page on SOC 2 readiness.
Initial certification is done in stages. The certification body reviews your documentation and readiness, then audits whether the ISMS is implemented and effective across your scope. Findings are classified, and you must correct nonconformities before a certificate is issued.
Yes. Many companies add ISO 27001 readiness to a managed or co-managed IT plan so monitoring, patching, backups, access reviews, and documentation are handled in one place.
Tell us what your customers and partners expect. We will explain what ISO 27001 readiness means for your environment and put together a clear plan and quote.
Related compliance frameworks: CMMC compliance, HIPAA IT compliance, FTC Safeguards Rule compliance, PCI DSS compliance, and SOC 2 readiness. See also cybersecurity insurance readiness, cybersecurity and compliance, endpoint security, backup and disaster recovery, and Microsoft 365 and Google Workspace.
Last updated: October 2026. Based on ISO/IEC 27001:2022 with Amendment 1:2024, and IAF guidance on the transition from the 2013 edition.