// ISO27001.jsx — Verigo Global: dedicated ISO/IEC 27001 framework + support page const { V: IV, MAXW: IMW, FONT: IFT } = window; /* ── DATA ─────────────────────────────────────────────────── */ const ANNEX_THEMES = [ ['briefcase', 'Organizational', '37', 'Policies, roles, supplier relationships, threat intelligence, and the governance backbone of the ISMS.'], ['users', 'People', '8', 'Screening, awareness, responsibilities, and the human controls that turn policy into practice.'], ['building', 'Physical', '14', 'Secure areas, equipment, clear-desk and clear-screen, and protection of physical assets.'], ['cpu', 'Technological', '34', 'Access control, cryptography, logging, secure development, and configuration management.'], ]; const SUPPORT_STAGES = [ { step: '01', icon: 'search', overline: 'Assess', title: 'ISO 27001 Readiness Assessment', lead: 'Know exactly where you stand against ISO/IEC 27001:2022.', desc: 'We benchmark your current state against Clauses 4–10 and all 93 Annex A controls, score your gaps by risk and effort, and hand you an independent remediation roadmap — the foundation for everything that follows.', deliverables: ['Clause 4–10 gap analysis', 'Annex A control-by-control review', 'Risk-scored remediation roadmap', 'Indicative certification timeline'], link: 'services', linkLabel: 'About readiness assessments', }, { step: '02', icon: 'layers', overline: 'Implement', title: 'ISMS Implementation Toolkit', lead: 'We build the Information Security Management System with you — not for a shelf.', desc: 'A practitioner-led program that stands up the full ISMS: risk assessment methodology, Statement of Applicability, the complete policy set, control implementation, and the internal audit and management-review machinery that keeps it alive.', deliverables: ['Risk assessment & treatment methodology', 'Statement of Applicability (SoA)', 'Full ISMS policy & procedure set', 'Internal audit & management review program'], link: 'toolkits', linkLabel: 'Explore the toolkits', }, { step: '03', icon: 'clipboard', overline: 'Prepare', title: 'Stage 1 & Stage 2 Pre-Audit Preparation', lead: 'Walk into the certification audit knowing you will pass.', desc: 'A mock Stage 1 documentation review and a full Stage 2 mock audit run by a lead auditor independent of your implementation team — surfacing nonconformities while there is still time to close them.', deliverables: ['Mock Stage 1 documentation review', 'Full Stage 2 mock audit', 'Nonconformity log & corrective actions', 'Auditor-readiness coaching for your team'], link: 'services', linkLabel: 'About pre-audit preparation', }, { step: '04', icon: 'award', overline: 'Certify & Sustain', title: 'Certification & Surveillance Support', lead: 'Get certified — and stay certified across the three-year cycle.', desc: 'We support you through the certification body’s Stage 1 and Stage 2 audits, manage findings to closure, then keep the ISMS audit-ready through annual surveillance and three-year recertification.', deliverables: ['Certification body coordination', 'Findings management to closure', 'Annual surveillance audit support', 'Year-three recertification'], link: 'contact', linkLabel: 'Talk to a practitioner', }, ]; const JOURNEY = [ ['search', 'Gap analysis', '2–4 wks', 'Readiness assessment against the 2022 standard.'], ['layers', 'Build the ISMS', '3–6 mo', 'Risk method, SoA, policies, controls, evidence.'], ['file', 'Stage 1 audit', '~1 wk', 'Certification body reviews ISMS documentation.'], ['shield', 'Stage 2 audit', '1–2 wks', 'On-site assessment of operating effectiveness.'], ['award', 'Certified', '—', 'Three-year ISO/IEC 27001 certificate issued.'], ['refresh', 'Surveillance', 'Yr 1 & 2', 'Annual checks, then recertify in year three.'], ]; const CROSS = [ ['cpu', 'iso42001', 'ISO 42001', 'Extend your ISMS governance and risk methodology to cover AI systems under a certifiable AI management system.'], ['shield', 'soc2', 'SOC 2', 'Reuse your ISMS controls and evidence to satisfy the AICPA Trust Services Criteria.'], ['lock', 'cmmc', 'CMMC 2.0', 'ISO 27001 controls map directly onto the NIST 800-171 practices behind CMMC Level 2.'], ['building', 'nist', 'NIST', 'Annex A aligns with the NIST control families that underpin US federal compliance.'], ['heart', 'hitrust', 'HITRUST', 'HITRUST CSF harmonizes ISO 27001 with HIPAA into a single certifiable framework.'], ]; const ISO_FAQ = [ ['What changed in the 2022 edition?', 'ISO/IEC 27001:2022 restructured Annex A from 114 controls into 93, organized under four themes — Organizational, People, Physical, and Technological — and introduced 11 new controls covering areas like threat intelligence, cloud security, and secure coding. Organizations certified to the 2013 edition transitioned by the October 2025 deadline.'], ['How long does certification take?', 'For a mid-market organization, expect roughly 4–8 months end to end: a 2–4 week readiness assessment, 3–6 months to build and operate the ISMS, then the certification body’s Stage 1 and Stage 2 audits. We give you a firm timeline in the scoping proposal.'], ['What is the difference between Stage 1 and Stage 2?', 'Stage 1 is a documentation review where the certification body confirms your ISMS is designed and ready. Stage 2 is the full on-site (or remote) audit of whether your controls are actually operating. Our pre-audit preparation runs mock versions of both.'], ['Can Verigo both build and audit our ISMS?', 'We support you through the full lifecycle, but the certification audit itself must be performed by an independent, accredited certification body — never the firm that implemented your controls. To preserve that independence, our pre-audit lead auditor is also kept separate from your implementation team.'], ['Do we have to recertify every year?', 'No. The ISO 27001 certificate is valid for three years. In years one and two the certification body performs lighter surveillance audits; in year three you complete a full recertification. We keep your ISMS audit-ready throughout so each one is a non-event.'], ]; /* ── BREADCRUMB ───────────────────────────────────────────── */ const Crumb = ({ onNav }) => (
/ / ISO 27001
); const crumbBtn = { background: 'none', border: 'none', cursor: 'pointer', color: '#7A7A8A', fontSize: 13, fontWeight: 600, padding: 0, fontFamily: "'DM Sans', system-ui, sans-serif" }; /* ── HERO ─────────────────────────────────────────────────── */ const Hero = ({ onNav }) => (
International ISMS ISO/IEC 27001:2022

ISO 27001, delivered end to end.

The international gold standard for information security management. Verigo takes you from first gap analysis to a certified ISMS — and keeps you certified across the full three-year cycle, with senior practitioners on every engagement.

onNav('contact')}>Start a Conversation document.getElementById('support')?.scrollIntoView({ behavior: 'smooth', block: 'start' })}>See how we help
At a glance
{[ ['globe', 'Scope', 'Global — all four markets'], ['layers', 'Standard', '93 Annex A controls, 4 themes'], ['refresh', 'Cycle', '3-year certificate + surveillance'], ['gauge', 'Typical timeline', '4–8 months to certified'], ].map(([ic, k, val], i) => (
{k}
{val}
))}
); /* ── STATS STRIP ──────────────────────────────────────────── */ const Stats = () => (
{[ ['USD 18.6B', 'Certification market (2025)'], ['USD 74.6B', 'Projected market (2035)'], ['81%', 'Planned or current adoption'], ['93', 'Annex A controls (2022)'], ].map(([v, l], i) => (
{v} {l}
))}
); /* ── WHAT IT IS / ANNEX A ─────────────────────────────────── */ const Overview = () => (
What ISO 27001 certifies

A living system, not a binder of policies.

ISO/IEC 27001 certifies a complete Information Security Management System — a risk-based, continuously improving framework that spans people, process, and technology across your whole organization.

The standard pairs management-system requirements (Clauses 4–10) with a catalog of 93 Annex A controls. Verigo’s Compliance by Design approach embeds those controls into how you already operate — so evidence is generated by the process, not assembled in a panic before each audit.

{[ 'Risk-based — controls follow your actual threats, not a checklist', 'Internationally recognized across all four Verigo markets', 'The natural hub for SOC 2, CMMC, NIST, and HITRUST evidence', ].map((t, i) => (
{t}
))}
Annex A — 2022 structure

93 controls, four themes.

{ANNEX_THEMES.map(([ic, name, count, desc], i) => (
{count}

{name}

{desc}

))}
); /* ── THE SUPPORT MODEL (CORE) ─────────────────────────────── */ const Support = ({ onNav }) => (
Four service lines, mapped
to the ISO 27001 lifecycle.} sub="Engage any single stage or move through the whole journey with one accountable, senior-led team — and a peer-review quality gate on every deliverable." maxSub={640} />
{SUPPORT_STAGES.map((s) => (
{s.step}
{s.overline}

{s.title}

{s.lead}

{s.desc}

What you receive
{s.deliverables.map((d, j) => (
{d}
))}
))}
); /* ── CERTIFICATION JOURNEY ────────────────────────────────── */ const Journey = () => (
{JOURNEY.map(([ic, t, dur, d], i) => (
{dur}
{t}
{d}
))}
); /* ── WHY VERIGO + CROSS-FRAMEWORK ─────────────────────────── */ const WhyAndCross = ({ onNav }) => (
Why certify with Verigo

Implementation and audit, under one roof.

{[ ['users', 'Senior-led, always', 'Every engagement is run by practitioners with 20+ years and credentials including CISSP, CISM, and ISO 27001 Lead Auditor — never junior consultants with templates.'], ['gauge', 'Audit-ready by design', 'Controls are embedded into how you operate, so evidence accumulates continuously instead of being reconstructed before each audit.'], ['scale', 'Independence preserved', 'Our pre-audit lead auditor is kept separate from your implementation team, protecting the integrity of the certification.'], ].map(([ic, t, d], i) => (

{t}

{d}

))}
One certification, many doors

ISO 27001 is your evidence hub.

Our cross-framework control mapping lets a single ISO 27001 control — and its evidence — serve multiple certifications. Build it once, reuse it across:

{CROSS.map(([ic, id, name, desc]) => ( ))}
); /* ── FAQ ──────────────────────────────────────────────────── */ const FAQ = ({ onNav }) => { const [open, setOpen] = React.useState(0); return (
ISO 27001 questions

Good to know before we start.

Questions on scope, timeline, or the 2022 transition? A senior practitioner will walk you through it.

onNav('contact')}>Start a Conversation
{ISO_FAQ.map(([q, a], i) => { const isOpen = open === i; return (
{isOpen && (

{a}

)}
); })}
); }; /* ── PAGE ─────────────────────────────────────────────────── */ const ISO27001Page = ({ onNav }) => (
); Object.assign(window, { ISO27001Page });