Home/ISO Certification/ISO 27001
ISO 27001 Certification,
Scoped to the Service Your Customers Buy
We help technology and service businesses build an information security management system that meets ISO 27001 and answers the security questionnaire in front of them — a scope that covers what the customer is actually asking about, a risk assessment that holds up, and a Statement of Applicability an auditor can work from.
- A division of Liberty Management Group Ltd — established 2009
- Aurora, IL · Greater Chicago
- Submission-ready documentation
- On-time delivery
An ISMS Built Around Real Risk
What ISO 27001 requires
ISO 27001 does not hand you a list of security controls to install. It requires a management system: you assess your own risks, select controls against them from Annex A, and justify in writing every control you include and every one you leave out. Two certified companies can look quite different, and that is by design.
- Scope definition — which systems, which sites, which services
- Information security risk assessment and treatment
- The Statement of Applicability and control justification
- The 93 Annex A controls across four themes
- Internal audit, management review and incident response
From scope to certificate
Scope is the decision that determines both what the project costs and whether the resulting certificate satisfies the customer who asked for it. We get that right first, then build the risk methodology and the control set around it, and prepare your team to be audited on what they actually do.
- Scope definition tested against your customers’ expectations
- Risk assessment methodology, criteria and risk register
- Statement of Applicability with justified inclusions and exclusions
- Annex A control implementation and evidence
- Support through Stage 1 and Stage 2 certification audits
ISO 27001 or SOC 2?
They are different instruments and increasingly companies hold both. ISO 27001 certifies a management system against an international standard and is the expected answer in UK, EU and multinational procurement; SOC 2 is an attestation report on controls, produced by a CPA firm, and is more established with US enterprise buyers. If your customers are asking for one by name, that settles it. If they are simply asking how you protect their data, the choice is worth thinking through properly. One thing to know either way — the 2013 edition of ISO 27001 expired on 31 October 2025, so a certificate on that edition is no longer valid, whether it is yours or a vendor’s. If you are weighing it up, we can work through that with you before any implementation begins.
More ISO Consulting from Liberty Compliance
Need Help with Compliance?
Our experts are ready to help you navigate regulatory requirements and achieve your certification goals.
Experienced Experts
Hands-on experience in regulatory compliance and management systems.
Tailored Solutions
Solutions that fit your business, industry, and product requirements.
On-Time Delivery
Efficient and reliable service to help you meet your business deadlines.