ISO 27001 roadmap

Your biggest customer requires ISO 27001. In most cases you do not need the certificate right away.

The risk team has to be able to document a risk. They want to see that you take information security seriously. At first, a solid roadmap and honest communication are enough. We deliver both in three weeks. We build the ISMS in parallel.

That also holds if your customer falls under NIS2, you do not, and they pass their supply-chain security questionnaire on to you.

Exception: with a knock-out criterion in a tender, with a public-sector buyer, in a corporate RFP, or as a DORA-critical supplier, you do need the passed certificate right away. We clarify that in the first call, before you sign.

ISO 27001 roadmap Three weeks, fixed price 15,000 to 25,000 euros

Your customer's risk team

Requires ISO 27001.

The pressure lands here. We run the conversations with the risk team.

controlpunkt

This is where it ends.

Three weeks to the roadmap. We build the ISMS in parallel.

After three weeks: the roadmap is in your customer's hands.

Your company

A few hours of your time.

We absorb the pressure from your major customer.

Who carries the pressure while the ISMS is built.

What you get

  • A document you can hand to your customer. We write it so it lands where it needs to land.
  • Communication with your customer's risk team. We handle it.
  • A timeline that holds up, because it comes from your system.
  • A roadmap to certification readiness, against clauses 4 to 10 and Annex A, shaped around your business.

15,000 to
25,000 euros

Duration
Three weeks
Price
Fixed, assessment included
Your time
A few hours

No framework contract, no automatic renewal. What comes after is your call.

What you are buying is not a document. It is the proof your customer's risk team accepts. And the pressure is gone before the certificate arrives.

Sample data, no client material

Two lines from a security questionnaire

  • “How do you ensure former employees no longer have access?” An answer with system, deadline and proof: offboarding runs through the identity service, access is revoked on the last working day, a monthly reconciliation against the HR list, and the report is attached to the answer.
  • “Do you test restoring from your backups?” The honest answer when it is not yet true: today no, the test run is scheduled, the owner is named, the deadline is in the roadmap. A risk team accepts a date. It does not accept an evasion.

This is how we answer your customer's questionnaire: every line with system, deadline and proof, and where something is missing, the date from which it holds.

How it runs

  1. Assessment. What is in place, what is missing, what does it cost.
  2. Prioritization. What has impact stays. What does not, drops out, and we tell you why.
  3. The big picture. We draw it together with you.
  4. Step by step. After each deployment: what worked, what did not, what we change.

Later, if you want it

The ISMS to audit readiness, built in parallel, on a timeline your customer knows. 40,000 to 80,000 euros, eight months, at a fixed price. Your own effort across those eight months varies. We give you the exact figure in the first call.

How we differ from compliance software, and what comes after

A compliance platform gives you a checklist. It does not take the pressure from your major customer off you, it does not talk to their risk team, and it does not know what that team is actually looking for. We do, because we have sat on both sides of that table, see Case 1.

A case

A trading company was given a deadline by its largest customer: ISO 27001 or no new framework agreement. No ISMS, no security staff.

  • After three weeks, a strategy with a defensible timeline was in place, and the customer accepted it. The pressure was off.
  • After eight months, the ISMS stood: risk register, Statement of Applicability, 22 management documents, approved by leadership. Certification is underway.
  • From day one, we run the conversations with the major customer's risk team.

The full path to the certificate, at a fixed price:

Roadmapassessment included 15,000 to 25,000 euros
ISMSeight months, after that if you want 40,000 to 80,000 euros
Together with us 55,000 to 105,000 euros
The exact sum is set after the assessment. The certification body is not part of our offer. You choose it freely and pay their fee directly to them.

A certificate is not a state. It is a recurring deadline.

If you have no one for that, we carry the ISMS forward as Fractional CISO. 5,000 to 12,000 euros per month, depending on scope and system landscape, cancellable. If you have someone, we hand everything over and step back. We take on the role, not the duty. Your management approves and oversees the measures itself (section 38 BSIG). Under DORA, your management body carries ultimate responsibility per Article 5. The implementation can be delegated, the responsibility cannot.

What we build, we hand over. You get the documentation, the access and the knowledge behind it. You retain ownership of your systems. If something needs permanent support, we tell you beforehand. Then you decide whether we take it on.

If the certification body finds a deviation in something we built, we fix it at no extra charge. If the certification body requires a follow-up audit, you pay for it directly to them, not to us.

Intro call

hello@controlpunkt.com

We reply within one business day.

What to put in the first email

  • Who you are and your company.
  • What it is about: the trigger, the real problem. A sentence or two is enough.
  • If a customer, an investor or a regulator has set a deadline: add the date.
  • After an incident: where the forensics stand.