Skip to main content

Local expertise. Enterprise capability. Practical solutions.

ClickITTauranga · NZ · Global

Compliance, Demystified · Tauranga, New Zealand

ISO/IEC 27001 certification, without the overwhelm

Clients, tenders and insurers are asking for it. You're not sure what it actually involves. Click IT guides New Zealand businesses through ISO/IEC 27001 implementation - the ISMS, the risk work, the controls and the audit - in plain language, at a pace that fits your business.

Honest scoping first - we'll tell you if a lighter approach fits better.

Why It Matters

Four reasons NZ businesses pursue certification

ISO/IEC 27001 has moved from 'nice to have' to a real commercial requirement - especially for professional services, healthcare, technology and government supply.

Win tenders and keep clients

More RFPs, supplier panels and enterprise clients now list ISO/IEC 27001 as a condition of doing business. Certification keeps you in the conversation.

Answer security questionnaires with confidence

Instead of panicking over a 200-question spreadsheet, you have documented answers - and the evidence to back them.

Satisfy insurers and partners

Cyber insurance underwriters and strategic partners increasingly expect structured security management. A certified ISMS is the strongest signal there is.

Actually reduce risk

The certification journey forces real improvements: asset registers, access reviews, incident plans and tested backups - security that works, not just paperwork.

In plain English

What ISO/IEC 27001 actually is

ISO/IEC 27001 is the international standard for information security management. At its core is the ISMS - the Information Security Management System - a documented, working set of policies, processes and controls for keeping your information safe.

It is risk-based: you assess the risks that actually matter to your business and apply controls proportionate to them. Certification means an independent, accredited auditor has verified that your ISMS exists, works, and is actually followed.

The honest part: it's a real project with real discipline. The good part: done properly, it makes your business genuinely more secure - not just better at answering questionnaires.

The ISMS at a glance

  • Policies - what your business commits to
  • Risk assessment - what could go wrong, and how likely
  • Controls - the technical and human measures in place
  • Processes - how incidents, access and change are handled
  • Evidence - proof it all actually happens
  • Audit - independent verification by an accredited body

We handle the engineering and the documentation. You make the business decisions. That division of labour is what keeps the project honest - and the audit passing.

The Journey

Six steps from 'where do we start?' to certified

A structured path, with a clear plan after the very first step. No step is skipped, and nothing is rushed.

  1. 01

    Gap analysis

    We map where you are against the standard and produce a prioritised implementation plan. You get the truth about effort and cost before committing.

  2. 02

    Scope it

    We help you define the certification scope - which locations, systems and teams are in - so the project stays proportionate to your business.

  3. 03

    Build the ISMS

    Policies, roles, risk assessment and procedures developed around how your business actually operates - never a template dump.

  4. 04

    Implement controls

    The technical and organisational controls behind the standard: identity, endpoint, email, backup, access reviews, awareness and more.

  5. 05

    Internal audit

    We pre-audit your ISMS, fix gaps and build the evidence file an external auditor will expect.

  6. 06

    Certification audit

    An accredited certification body performs the audit. We support you through it - so it's a formality, not a gamble.

Who Does What

You stay in control. We do the heavy lifting.

A certification project works when responsibilities are clear. Here's how we split them.

Click IT handles

  • Gap analysis and scoping
  • ISMS design and documentation
  • Policy and procedure development
  • Risk assessment and treatment planning
  • Technical control implementation
  • Evidence collection and audit readiness
  • Internal audit preparation and support
  • Surveillance audit support after certification

You provide

  • Decide the business case and scope
  • Appoint an owner who can make decisions
  • Give staff the time to adopt real practices
  • Sign off policies and risk decisions
  • Let auditors see your real (good) practices
The non-negotiable: auditors can tell when processes exist only on paper. The people part has to be real - and that's exactly what makes the certification valuable.

Practicalities

How long, how much, and what you need to bring

Straight answers - the same ones you'll get from us in a gap analysis.

Typical timeline

Six to twelve months for a small organisation with good foundations. Scope and starting point move it either way - the gap analysis tells you which.

Cost

Varies with scope and size - including the certification body's own fees, which they quote directly. We quote our work after the gap analysis, and we'll tell you if a lighter approach meets your needs.

What you need to bring

  • An executive sponsor with authority to make decisions
  • A realistic idea of which clients or tenders need certification
  • Willingness to run processes for real - certification audits find fake paperwork
  • Roughly half a day a month from key people during the project
  • A budget conversation - we quote honestly after the gap analysis

Questions

ISO/IEC 27001, asked and answered

No - certification is issued by an accredited certification body, and we can't issue it. Our job is to prepare you so thoroughly that the audit is a formality, not a gamble.

Start with a gap analysis - not a leap of faith

A gap analysis tells you exactly where you stand against ISO/IEC 27001, what the honest effort is, and whether certification is the right move at all. That first step is a conversation, not a contract.

Also see our ISO/IEC 27001 services page for the full service scope.