Contract requirement
ISO/IEC 27001
Not a law but a contract requirement, and increasingly the price of being allowed to bid at all. The Slovenian adoption is SIST EN ISO/IEC 27001:2023. We take organisations from a gap analysis to a management system a certification body will accept.
Why organisations start
Almost nobody certifies because they want to. They certify because a customer asked, because a tender required it, or because an insurer priced it in. That is a perfectly good reason, and it also makes the project easy to get wrong: a certificate obtained by writing documents nobody follows will pass an audit once and fail the customer who asked for it. A management system built properly does the opposite — it is more work at the start and less work every year afterwards.
What the standard asks for
- A defined scope — which parts of the organisation the system covers, and honestly
- A risk assessment method that is repeatable, and a treatment plan that follows from it
- A statement of applicability against the Annex A controls, with reasons for exclusions
- Evidence that the system runs: internal audit, management review, corrective actions
- Measurable objectives, so improvement can be demonstrated rather than claimed
What it is worth
There is no fine for not having it. There is a growing list of tenders you cannot enter, security questionnaires you answer badly, and enterprise customers whose procurement process stops at the question. Certification also does most of the work for ZInfV-1: the two overlap heavily, and an organisation with a working management system is a long way into its statutory obligations already.
WHAT WE DO ABOUT IT
The services that close this gap
Not the whole catalogue — these are the ones that map onto the obligations above. If something here is already covered internally, say so and we will scope around it.
Chief Information Security Officer
A security executive on subscription: policy, risk register, board reporting and the evidence an auditor asks for — without a six-figure hire.
Read more TPRMaaSThird-party risk management
Your suppliers are your attack surface, and under NIS2 they are also your legal responsibility. We inventory them, rate them and keep watching.
Read moreNot sure whether ISO/IEC 27001 applies to you?
Tell us your sector, your headcount and what you sell. We will tell you which regimes catch you and what the first three things to do are — in writing, at no charge, because half the organisations that ask turn out not to be in scope and we would rather say so.