Skip to main content
Home/Readiness/ISO 27001 Readiness
ISO 27001 Compliance

ISO 27001 Readiness

Build an ISMS that operates rather than a binder that satisfies - and arrive at Stage 1 with a real management system, not a document project.

Standard ISO 27001
Typical Timeline 3-6 weeks
Starting Price $4,500
Scope Delivery Calgary, Toronto & Remote
Assessment Scope

What This Engagement Covers

ISO 27001 certifies a management system rather than a moment in time. The registrar is not looking for a policy set - they are looking for an ISMS that is defined, implemented, and operating, with a risk register that drove control selection and a Statement of Applicability that can be defended. We run readiness so that when your registrar conducts Stage 1, the ISMS exists and the Stage 2 evidence is already accumulating.

Canadian Operations & Law

What This Means for Canadian Businesses

ISO 27001 is an international standard, and its geographic reach makes it the most common certification ask for Canadian companies operating internationally - particularly in financial services, government supply chains, and technology sectors where Canadian and international buyers both require it. Canadian federal and provincial government procurement increasingly references ISO 27001 or equivalent controls as a supplier requirement. The standard's control set (Annex A, ISO 27002:2022) maps well to Canadian privacy requirements, and the risk-based approach aligns with OSFI guidance for regulated financial institutions. Where SOC 2 evidence already exists, a substantial portion carries across to Annex A without duplication.

Calgary HubAlberta Operations
Toronto HubOntario Operations
Control Framework

Domains & Controls We Assess

We evaluate every technical, operational, and administrative requirement against authoritative criteria.

Organizational Controls (A.5)

  • A.5.1 - Policies for information security: defined, approved, and communicated
  • A.5.2 - Information security roles and responsibilities assigned and documented
  • A.5.9 - Inventory of information and associated assets maintained and owned
  • A.5.15 - Access control policy governing physical and logical access decisions
  • A.5.23 - Information security requirements for cloud services defined and managed
  • A.5.30 - ICT readiness for business continuity planned and tested

People Controls (A.6)

  • A.6.1 - Screening of candidates proportionate to role sensitivity and data access
  • A.6.3 - Information security awareness, education, and training programme
  • A.6.4 - Disciplinary process for information security policy violations
  • A.6.5 - Responsibilities on change of employment or termination defined
  • A.6.8 - Information security event reporting mechanisms available to workforce

Physical Controls (A.7)

  • A.7.1 - Physical security perimeters protecting information processing facilities
  • A.7.2 - Physical entry controls restricting access to authorised personnel
  • A.7.4 - Physical security monitoring of sensitive areas
  • A.7.8 - Equipment siting and protection from environmental threats
  • A.7.14 - Secure disposal or re-use of equipment containing storage media

Technological Controls (A.8)

  • A.8.2 - Privileged access rights managed and reviewed on a defined cycle
  • A.8.5 - Secure authentication mechanisms for system and application access
  • A.8.7 - Protection against malware across end-user and server environments
  • A.8.8 - Management of technical vulnerabilities through timely remediation
  • A.8.15 - Logging of activities, exceptions, and security events; log protection
  • A.8.24 - Cryptography policy governing use of controls to protect information
  • A.8.28 - Secure coding practices applied throughout the development lifecycle

Risk Management (Clauses 6 & 8)

  • Clause 6.1.2 - Information security risk assessment process documented and repeatable
  • Clause 6.1.3 - Statement of Applicability produced with justified inclusion/exclusion of controls
  • Clause 8.2 - Risk assessment performed on a defined schedule or triggered by change
  • Clause 8.3 - Risk treatment plan implemented and tracked to completion

ISMS Operations (Clauses 9 & 10)

  • Clause 9.1 - Monitoring, measurement, analysis, and evaluation of ISMS performance
  • Clause 9.2 - Internal audit programme planned and executed at defined intervals
  • Clause 9.3 - Management review of ISMS conducted at planned intervals
  • Clause 10.1 - Continual improvement: nonconformities identified, corrected, and recurrence prevented
What You Receive

Engagement Deliverables

Everything you need to prove control operating effectiveness to your auditors and enterprise clients.

ISMS Scope Statement and Boundary Documentation

Information Security Risk Assessment and Risk Register

Statement of Applicability (all Annex A controls)

Gap Assessment Report Mapped to ISO 27002:2022

Mandatory Clause Documentation (Internal Audit, Management Review)

Audit-Ready Policy and Procedure Templates

Client Stories

Trusted by Growing Businesses

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
FAQ

Common Questions

How is ISO 27001 different from SOC 2? +

ISO 27001 certifies an information security management system against an international standard; SOC 2 is an AICPA attestation on controls at a point in time or over a period. ISO 27001 is the more common ask outside North America. The control overlap between Annex A and the SOC 2 criteria is substantial, so running both together costs far less than running them sequentially.

Do we need an internal audit before Stage 2? +

Yes, Clause 9.2 requires it, and Clause 9.3 requires a management review. Both must have occurred before Stage 2. Registrars look for genuine internal audit evidence - not a document that describes what an audit found but a programme that actually ran. We conduct the internal audit as part of readiness so it is real rather than retrospective.

What is the Statement of Applicability actually for? +

It records which Annex A controls apply to your ISMS and why. Controls excluded without a defensible justification are one of the most common Stage 1 findings. An SoA that says "not applicable" without explanation is a red flag to a registrar and to buyers who review it as part of due diligence.

Get Started

Ready for Your ISO 27001 Readiness Assessment?

Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.