ISO/IEC 27001:2022 is the gold-standard Information Security Management System for systematically identifying, treating, and monitoring information-security risk across people, processes, and technology. QSECS provides end-to-end ISO 27001 consulting and implementation — building and operationalising your ISMS, the Statement of Applicability, and the Annex A cryptography controls with quantum-readiness designed in from the start. We implement the ISMS and prepare you for certification; an accredited certification body performs the audit and issues the certificate. The result is an ISMS that stays defensible as cryptographic standards shift.
ISO/IEC 27001:2022 sets out the requirements for establishing, operating, and continually improving an Information Security Management System that protects the confidentiality, integrity, and availability of your information.
At its core, ISO 27001 is a risk-based ISMS: you define the scope and context, assess information-security risks, and apply a structured treatment plan. The 2022 revision reorganised Annex A into 93 controls grouped across four themes — organizational, people, physical, and technological — making the control set clearer to scope and easier to map against modern threats. A Statement of Applicability records which controls apply and why, while internal audit and management review keep the system honest.
Certification follows a defined cycle. A Stage 1 audit reviews your documentation and readiness, a Stage 2 audit assesses the ISMS in operation, and certification is then maintained through annual surveillance audits with full recertification every three years. Between audits, the continual-improvement loop — corrective actions, internal audits, and management reviews — ensures the ISMS adapts as risks, technology, and regulatory expectations evolve.
ISMS scope & context: defining boundaries, interested parties, and information-security objectives.
Risk assessment and treatment: identifying, analysing, and treating information-security risks with documented controls.
Annex A (2022) controls, including cryptography (A.8.24) and key-management practices.
Statement of Applicability: justifying which controls are included or excluded and how they are implemented.
Internal audit, management review, and continual improvement to keep the ISMS effective over time.
Your ISMS Risk Register Now Includes Quantum
An ISO 27001 ISMS exists to manage information-security risk, and the quantum threat to RSA and ECC is now a risk your Statement of Applicability and cryptography controls (e.g. A.8.24, use of cryptography) must address. U.S. Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks," sets legally binding federal post-quantum deadlines — key establishment by December 31, 2030 and digital signatures by December 31, 2031 — signalling the bar certifiers and customers will expect. And because "Harvest Now, Decrypt Later" attacks make data encrypted today a future liability, crypto-agility belongs in your risk treatment plan now.
QSECS keeps your ISMS current through the post-quantum transition, treating cryptographic obsolescence as a tracked risk and aligning controls and audits with emerging PQC standards.
We add quantum-computing and "harvest now, decrypt later" exposure to your risk register, so cryptographic obsolescence is formally assessed, owned, and tracked within the ISMS.
We strengthen your cryptography and key-management controls (A.8.24) by mapping them to the NIST post-quantum standards — FIPS 203, 204, and 205 — and documenting a crypto-agile migration path.
We use the continual-improvement cycle and annual surveillance audits as checkpoints to plan and verify your migration well before the NIST 2030-2035 deadline.
We provide ongoing ISMS upkeep — refreshing the Statement of Applicability, risk treatment plans, and control evidence as your environment and the threat landscape change.
We support you through internal audits, management reviews, and surveillance and recertification audits, keeping certification continuous and audit-ready year over year.
A defined ISMS scope and an asset inventory covering the information you want certified
Identified risk owners for the people, process and technology areas the controls touch
Management commitment to the ISMS — no cryptography expertise required on your side
The risk assessment and treatment plan, the Statement of Applicability and the full Annex A control set, including crypto-agile key management
Internal audit preparation, management review inputs and the documentation an auditor will examine
Hand-off to the accredited certification body — QSECS consults and implements, it does not certify
If customers, regulators or partners expect a certified ISMS, structured consulting and implementation is the fastest path to an audit-ready system.
The leaders accountable for standing up and maintaining a defensible information-security management system.
Get a complete ISMS built through QSECS consulting and implementation, with crypto-agility designed into the risk treatment plan.
Those who own the risk register, the Statement of Applicability and internal audit readiness.
Receive a documented risk treatment plan and SoA we implement with you, with cryptographic obsolescence tracked as a crypto-agile risk.
The teams who run the systems and key-management the Annex A controls depend on day to day.
Have crypto-agile cryptography controls (A.8.24) implemented into your stack so future algorithm swaps need no re-architecting.
An illustrative path through implementation — every engagement is scoped to your environment before work begins.
Define the ISMS boundary, context and interested parties, and inventory the information assets the certification will cover.
Run the risk assessment, agree a risk treatment plan and produce the Statement of Applicability across the Annex A controls.
QSECS implements the organizational, people, physical and technological controls, including crypto-agile key management for A.8.24.
Prepare and run an internal audit, close any nonconformities, and feed results into the management review.
Hand off to the accredited certification body, which performs the Stage 1 and Stage 2 audits and issues the certificate.
Timelines vary with scope and team availability. QSECS provides consulting and implementation up to the external certification audit — it does not certify your ISMS.
What teams usually ask before starting an ISO 27001 consulting and implementation engagement.
No. QSECS provides consulting and implementation — we build your ISMS, the risk treatment plan, the Statement of Applicability and the Annex A controls, then prepare you for audit. The certificate is issued by an independent accredited certification body, which performs the Stage 1 and Stage 2 audits.
ISO/IEC 27001:2022 reorganised Annex A into 93 controls grouped across four themes — organizational, people, physical and technological — and refined several controls, including cryptography. We implement to the current 2022 control set and themes from the outset.
For a focused scope, our consulting and implementation typically reaches audit-readiness in a few months, after which the accredited body runs the Stage 1 and Stage 2 audits. The exact timeline depends on ISMS scope, current maturity and team availability.
We run the risk assessment, build the SoA, design and implement the Annex A controls, prepare internal audit and assemble evidence; your team provides system access, assigns risk owners and approves changes. We embed with your people so the ISMS is owned internally once the engagement ends.
We record quantum and "harvest now, decrypt later" exposure as a tracked risk in your register, and make your cryptography controls (A.8.24) crypto-agile by mapping them to the NIST PQC standards (FIPS 203/204/205) — aligning your risk treatment plan with the Executive Order 14412 deadlines.
Yes. Engagements run onsite, remote or hybrid, and we tailor the ISMS scope, controls and evidence to your cloud providers, systems and existing tooling under NDA. Scope and tailoring are agreed during the requirement-analysis call.