Sample audit report — see how a Hackerbane report is structured. Open the report →

ISO 27001 compliance

ISO/IEC 27001 is the international standard for an information security management system. Hackerbane runs the gap assessment, audits your controls, acts as your independent internal auditor, and prepares the evidence so you walk into the certification audit knowing what the auditor will find.

What ISO 27001 is

ISO/IEC 27001 is the international standard for building and running an information security management system. The management clauses require you to define scope, assess and treat risk, set objectives, run internal audits, review performance at management level, and improve continually. Annex A lists the security controls you select from, and the Statement of Applicability records which ones apply and why.

Certification is a two-stage external audit by an accredited certification body, followed by surveillance audits and recertification on a fixed cycle. Customers, partners, and regulators ask for the certificate because it shows the security programme is real and independently checked.

Who it applies to

  • Any organisation that needs to prove its security programme to customers, partners, or regulators; it is the most common security requirement in enterprise procurement.
  • Exchanges, custodians, and blockchain infrastructure providers, where ISO 27001 is frequently expected by VARA, DORA supervisors, and banking partners.
  • AI product companies selling into regulated sectors, often alongside ISO/IEC 42001 for AI management.
  • Organisations using ISO 27001 as the backbone for NIS2 or DORA compliance.

What Hackerbane does

  • Gap assessment: we map your existing policies, processes, and technical controls to the management clauses and the Annex A controls, and tell you what is missing, weak, or undocumented.
  • Scope and risk treatment: we review the scope statement, the risk assessment, the risk treatment plan, and the Statement of Applicability so they describe the system you actually run.
  • Controls audit: we test the selected controls as they operate. Access control, cryptography and key management, secure development, logging, supplier security, and change management are verified against the production systems, including blockchain and AI components.
  • Technical testing: penetration testing and code review that satisfy the technical vulnerability management and secure development controls, with findings you can trace back to a control.
  • Internal audit: the standard requires an internal audit by someone independent of the work being audited. Hackerbane performs it and delivers the report and nonconformities your management review needs.
  • Remediation and certification support: nonconformities are fixed and retested, evidence is assembled clause by clause, and we support you through Stage 1, Stage 2, and surveillance audits.

What you get

  • A gap report against every clause and selected Annex A control, with priorities and owners.
  • A tested Statement of Applicability and risk treatment plan.
  • An internal audit report with nonconformities and observations, ready for management review.
  • Technical findings with severity, proof for the serious ones, and a fix for each.
  • An evidence pack organised the way a certification auditor reads it, and verified remediation once fixes land.

Who signs off

Only an accredited certification body can issue the ISO 27001 certificate. Hackerbane prepares you for the Stage 1 and Stage 2 audits, performs the internal audit the standard requires, and stays through the certification body's findings; the certificate itself comes from them.

Questions

Can Hackerbane be our internal auditor?
Yes. ISO 27001 requires an internal audit by someone independent of the activity being audited, and an external firm satisfies that. We audit the management system and the controls, write up nonconformities, and hand the report to your management review. We do not act as the certification body for the same system.
How long does ISO 27001 readiness take?
It depends on the scope and how mature your controls already are. A gap assessment gives you the honest size of the work first; the certification body then needs to see the management system operating for a period before Stage 2. We plan the timeline with you against your audit booking.
Do you also cover ISO/IEC 42001 for AI?
Yes. If your scope includes AI systems, we run the AI management system requirements alongside ISO 27001 against the same evidence pack, and audit the models, pipelines, and agent tooling as controls rather than as a separate exercise.

Next step

Request an audit

Tell us whether you are certifying for the first time, recertifying, or expanding scope, and when the Stage 1 or Stage 2 audit is booked. We will propose a gap assessment and internal audit plan with an estimate.