// ISO27001.jsx — Verigo Global: dedicated ISO/IEC 27001 framework + support page const { V: IV, MAXW: IMW, FONT: IFT } = window; /* ── DATA ─────────────────────────────────────────────────── */ const ANNEX_THEMES = [ ['briefcase', 'Organizational', '37', 'Policies, roles, supplier relationships, threat intelligence, and the governance backbone of the ISMS.'], ['users', 'People', '8', 'Screening, awareness, responsibilities, and the human controls that turn policy into practice.'], ['building', 'Physical', '14', 'Secure areas, equipment, clear-desk and clear-screen, and protection of physical assets.'], ['cpu', 'Technological', '34', 'Access control, cryptography, logging, secure development, and configuration management.'], ]; const SUPPORT_STAGES = [ { step: '01', icon: 'search', overline: 'Assess', title: 'ISO 27001 Readiness Assessment', lead: 'Know exactly where you stand against ISO/IEC 27001:2022.', desc: 'We benchmark your current state against Clauses 4–10 and all 93 Annex A controls, score your gaps by risk and effort, and hand you an independent remediation roadmap — the foundation for everything that follows.', deliverables: ['Clause 4–10 gap analysis', 'Annex A control-by-control review', 'Risk-scored remediation roadmap', 'Indicative certification timeline'], link: 'services', linkLabel: 'About readiness assessments', }, { step: '02', icon: 'layers', overline: 'Implement', title: 'ISMS Implementation Toolkit', lead: 'We build the Information Security Management System with you — not for a shelf.', desc: 'A practitioner-led program that stands up the full ISMS: risk assessment methodology, Statement of Applicability, the complete policy set, control implementation, and the internal audit and management-review machinery that keeps it alive.', deliverables: ['Risk assessment & treatment methodology', 'Statement of Applicability (SoA)', 'Full ISMS policy & procedure set', 'Internal audit & management review program'], link: 'toolkits', linkLabel: 'Explore the toolkits', }, { step: '03', icon: 'clipboard', overline: 'Prepare', title: 'Stage 1 & Stage 2 Pre-Audit Preparation', lead: 'Walk into the certification audit knowing you will pass.', desc: 'A mock Stage 1 documentation review and a full Stage 2 mock audit run by a lead auditor independent of your implementation team — surfacing nonconformities while there is still time to close them.', deliverables: ['Mock Stage 1 documentation review', 'Full Stage 2 mock audit', 'Nonconformity log & corrective actions', 'Auditor-readiness coaching for your team'], link: 'services', linkLabel: 'About pre-audit preparation', }, { step: '04', icon: 'award', overline: 'Certify & Sustain', title: 'Certification & Surveillance Support', lead: 'Get certified — and stay certified across the three-year cycle.', desc: 'We support you through the certification body’s Stage 1 and Stage 2 audits, manage findings to closure, then keep the ISMS audit-ready through annual surveillance and three-year recertification.', deliverables: ['Certification body coordination', 'Findings management to closure', 'Annual surveillance audit support', 'Year-three recertification'], link: 'contact', linkLabel: 'Talk to a practitioner', }, ]; const JOURNEY = [ ['search', 'Gap analysis', '2–4 wks', 'Readiness assessment against the 2022 standard.'], ['layers', 'Build the ISMS', '3–6 mo', 'Risk method, SoA, policies, controls, evidence.'], ['file', 'Stage 1 audit', '~1 wk', 'Certification body reviews ISMS documentation.'], ['shield', 'Stage 2 audit', '1–2 wks', 'On-site assessment of operating effectiveness.'], ['award', 'Certified', '—', 'Three-year ISO/IEC 27001 certificate issued.'], ['refresh', 'Surveillance', 'Yr 1 & 2', 'Annual checks, then recertify in year three.'], ]; const CROSS = [ ['cpu', 'iso42001', 'ISO 42001', 'Extend your ISMS governance and risk methodology to cover AI systems under a certifiable AI management system.'], ['shield', 'soc2', 'SOC 2', 'Reuse your ISMS controls and evidence to satisfy the AICPA Trust Services Criteria.'], ['lock', 'cmmc', 'CMMC 2.0', 'ISO 27001 controls map directly onto the NIST 800-171 practices behind CMMC Level 2.'], ['building', 'nist', 'NIST', 'Annex A aligns with the NIST control families that underpin US federal compliance.'], ['heart', 'hitrust', 'HITRUST', 'HITRUST CSF harmonizes ISO 27001 with HIPAA into a single certifiable framework.'], ]; const ISO_FAQ = [ ['What changed in the 2022 edition?', 'ISO/IEC 27001:2022 restructured Annex A from 114 controls into 93, organized under four themes — Organizational, People, Physical, and Technological — and introduced 11 new controls covering areas like threat intelligence, cloud security, and secure coding. Organizations certified to the 2013 edition transitioned by the October 2025 deadline.'], ['How long does certification take?', 'For a mid-market organization, expect roughly 4–8 months end to end: a 2–4 week readiness assessment, 3–6 months to build and operate the ISMS, then the certification body’s Stage 1 and Stage 2 audits. We give you a firm timeline in the scoping proposal.'], ['What is the difference between Stage 1 and Stage 2?', 'Stage 1 is a documentation review where the certification body confirms your ISMS is designed and ready. Stage 2 is the full on-site (or remote) audit of whether your controls are actually operating. Our pre-audit preparation runs mock versions of both.'], ['Can Verigo both build and audit our ISMS?', 'We support you through the full lifecycle, but the certification audit itself must be performed by an independent, accredited certification body — never the firm that implemented your controls. To preserve that independence, our pre-audit lead auditor is also kept separate from your implementation team.'], ['Do we have to recertify every year?', 'No. The ISO 27001 certificate is valid for three years. In years one and two the certification body performs lighter surveillance audits; in year three you complete a full recertification. We keep your ISMS audit-ready throughout so each one is a non-event.'], ]; /* ── BREADCRUMB ───────────────────────────────────────────── */ const Crumb = ({ onNav }) => (
The international gold standard for information security management. Verigo takes you from first gap analysis to a certified ISMS — and keeps you certified across the full three-year cycle, with senior practitioners on every engagement.
ISO/IEC 27001 certifies a complete Information Security Management System — a risk-based, continuously improving framework that spans people, process, and technology across your whole organization.
The standard pairs management-system requirements (Clauses 4–10) with a catalog of 93 Annex A controls. Verigo’s Compliance by Design approach embeds those controls into how you already operate — so evidence is generated by the process, not assembled in a panic before each audit.
{desc}
{s.lead}
{s.desc}
{d}
Our cross-framework control mapping lets a single ISO 27001 control — and its evidence — serve multiple certifications. Build it once, reuse it across:
Questions on scope, timeline, or the 2022 transition? A senior practitioner will walk you through it.
{a}