Compliance, Demystified · Tauranga, New Zealand
ISO/IEC 27001 certification, without the overwhelm
Clients, tenders and insurers are asking for it. You're not sure what it actually involves. Click IT guides New Zealand businesses through ISO/IEC 27001 implementation - the ISMS, the risk work, the controls and the audit - in plain language, at a pace that fits your business.
Honest scoping first - we'll tell you if a lighter approach fits better.
Why It Matters
Four reasons NZ businesses pursue certification
ISO/IEC 27001 has moved from 'nice to have' to a real commercial requirement - especially for professional services, healthcare, technology and government supply.
Win tenders and keep clients
More RFPs, supplier panels and enterprise clients now list ISO/IEC 27001 as a condition of doing business. Certification keeps you in the conversation.
Answer security questionnaires with confidence
Instead of panicking over a 200-question spreadsheet, you have documented answers - and the evidence to back them.
Satisfy insurers and partners
Cyber insurance underwriters and strategic partners increasingly expect structured security management. A certified ISMS is the strongest signal there is.
Actually reduce risk
The certification journey forces real improvements: asset registers, access reviews, incident plans and tested backups - security that works, not just paperwork.
In plain English
What ISO/IEC 27001 actually is
ISO/IEC 27001 is the international standard for information security management. At its core is the ISMS - the Information Security Management System - a documented, working set of policies, processes and controls for keeping your information safe.
It is risk-based: you assess the risks that actually matter to your business and apply controls proportionate to them. Certification means an independent, accredited auditor has verified that your ISMS exists, works, and is actually followed.
The honest part: it's a real project with real discipline. The good part: done properly, it makes your business genuinely more secure - not just better at answering questionnaires.
The ISMS at a glance
- Policies - what your business commits to
- Risk assessment - what could go wrong, and how likely
- Controls - the technical and human measures in place
- Processes - how incidents, access and change are handled
- Evidence - proof it all actually happens
- Audit - independent verification by an accredited body
We handle the engineering and the documentation. You make the business decisions. That division of labour is what keeps the project honest - and the audit passing.
The Journey
Six steps from 'where do we start?' to certified
A structured path, with a clear plan after the very first step. No step is skipped, and nothing is rushed.
- 01
Gap analysis
We map where you are against the standard and produce a prioritised implementation plan. You get the truth about effort and cost before committing.
- 02
Scope it
We help you define the certification scope - which locations, systems and teams are in - so the project stays proportionate to your business.
- 03
Build the ISMS
Policies, roles, risk assessment and procedures developed around how your business actually operates - never a template dump.
- 04
Implement controls
The technical and organisational controls behind the standard: identity, endpoint, email, backup, access reviews, awareness and more.
- 05
Internal audit
We pre-audit your ISMS, fix gaps and build the evidence file an external auditor will expect.
- 06
Certification audit
An accredited certification body performs the audit. We support you through it - so it's a formality, not a gamble.
Who Does What
You stay in control. We do the heavy lifting.
A certification project works when responsibilities are clear. Here's how we split them.
Click IT handles
- Gap analysis and scoping
- ISMS design and documentation
- Policy and procedure development
- Risk assessment and treatment planning
- Technical control implementation
- Evidence collection and audit readiness
- Internal audit preparation and support
- Surveillance audit support after certification
You provide
- Decide the business case and scope
- Appoint an owner who can make decisions
- Give staff the time to adopt real practices
- Sign off policies and risk decisions
- Let auditors see your real (good) practices
Practicalities
How long, how much, and what you need to bring
Straight answers - the same ones you'll get from us in a gap analysis.
Typical timeline
Six to twelve months for a small organisation with good foundations. Scope and starting point move it either way - the gap analysis tells you which.
Cost
Varies with scope and size - including the certification body's own fees, which they quote directly. We quote our work after the gap analysis, and we'll tell you if a lighter approach meets your needs.
What you need to bring
- An executive sponsor with authority to make decisions
- A realistic idea of which clients or tenders need certification
- Willingness to run processes for real - certification audits find fake paperwork
- Roughly half a day a month from key people during the project
- A budget conversation - we quote honestly after the gap analysis
Questions
ISO/IEC 27001, asked and answered
No - certification is issued by an accredited certification body, and we can't issue it. Our job is to prepare you so thoroughly that the audit is a formality, not a gamble.
A small organisation with good foundations can typically certify in six to twelve months. It depends on scope and starting point - we scope it honestly after a gap analysis.
If clients or tenders demand certification, ISO/IEC 27001 gives you a structured route that also improves security. If not, a pragmatic security improvement programme may be the smarter first step - we'll tell you which.
Costs vary widely with scope and organisation size, and include the certification body's fees (which they quote directly). We quote our implementation work after a gap analysis and tell you if a lighter approach fits.
Yes. A certified quality management system gives you a head start on documentation discipline and management commitment. We build the ISMS to reuse what already works.
Certification is maintained through annual surveillance audits and a full re-certification cycle. We support the ongoing maintenance - controls monitoring, documentation updates and audit preparation - as part of an ongoing engagement.
Start with a gap analysis - not a leap of faith
A gap analysis tells you exactly where you stand against ISO/IEC 27001, what the honest effort is, and whether certification is the right move at all. That first step is a conversation, not a contract.
Also see our ISO/IEC 27001 services page for the full service scope.