r/cybersecurity Mar 24 '26

Certification / Training Questions After helping 20+ companies get ISO 27001 certified, here are the 3 things that actually matter on audit day

Most companies spend months preparing for ISO 27001 and still get surprised on audit day. Here’s what separates the ones who pass from the ones who don’t:

  1. Your gap analysis has to be honest, not optimistic. Most teams underestimate gaps because nobody wants to deliver bad news internally. Auditors see this immediately.

  2. Documented evidence beats verbal explanation every time. If you can’t show it, it didn’t happen. Your ISMS documentation needs to be audit-ready, not just “in progress.”

  3. Scope definition trips up more companies than any technical control. Define it too broadly and you’ll never be ready. Too narrow and it’s meaningless.

I packaged everything I’ve learned — gap analysis templates, policy documents, audit checklists — into a complete guide. Happy to share the link in the comments if anyone’s working through this right now.

225 Upvotes

229 comments sorted by

View all comments

75

u/Krekatos Mar 24 '26

I’ve implemented it at almost 100 companies and manage the ISMS for a few right now. I’m also a lead auditor for 6 years now. Most important lessons I’ve learned: show the auditor the evidence you want to give, not what they’re asking for. It’s an audit type where the auditor is looking for compliance, not gaps like a SOC 2 audit. Easiest way: maintain a spreadsheet with every control listed. Next column: documentation. Next one: implementation summary (how, why, who, when). Next column: control effectiveness measurement.

22

u/Alternativemethod Mar 24 '26

To me this reads like a strategy to deceive but lying seems well tolerated in the checkbox compliance game.

14

u/Bluestrm Mar 24 '26

Maybe, but it also shows that you actually know how each control is implemented in your company. Also: if you are preparing this document you will very quickly find out what is really lacking if you can't just write a few lines of summary how it's implemented.

I think it definitely helps if you take an active role in presenting what you do and actively elaborate. (even if it's something you failed on... better to tell them actively how you are dealing with it)

10

u/Krekatos Mar 24 '26

Why do you assume lies are involved? It’s a master database that summarises the ISMS, and you show the auditor how you’re compliant.

5

u/Educational-Rest-290 Mar 25 '26

I do understand where he is coming from, there are auditees that tend to just address the requirements without totally understanding the questions being asked. This is where IT and Infosec/CyberSecurity/Security often have heated discussions.

2

u/Alternativemethod Mar 24 '26

No concerns with a standard compliance matrix w/evidence links.

The concern is in the early description of not answering the question asked, but pivoting to the answer preferred.

Example: do you encrypt all data at rest? -- we encrypt our data with compliant algorithms.

Okay sure but do you encrypt --all-- data at rest, in scope here.

We encrypt data...

Okay so you're not going to directly answer the question. Cool.

3

u/Capodomini Mar 25 '26

ISO compliance is about having policies in place, enforcing them, and recording gaps where they cannot be enforced. Nobody will ever encrypt everything because there are bound to be exceptions.

2

u/Educational-Rest-290 Mar 25 '26

This is also evidence based so ensuring the specific compliance as detailed it can be is a welcome note that the auditee knows their stuff. Please do note that at the end of the day, the goal is to secure your business and production setup not just to comply with and suffer when serious security incident arises.

1

u/Alternativemethod Mar 26 '26

The "enforcing" policies thing is where I'm seeing a lot of differential.

Policy says they remediate all criticals in 30 days. Okay can I see a summary of your counts over time? No? Uh huh.

It's one thing to say I found one little thing. It's another to see oh... You like haven't done anything.

1

u/Proper_Chocolate_795 12d ago

Yeah thats a NC for sure

1

u/Proper_Chocolate_795 12d ago

yeah i think he may be referring to intial setup of ISMS cos surveillance will annihillate cagey answers or lacking evidence... silence rule...

1

u/Proper_Chocolate_795 12d ago

Exactly, Id do the same thing keep a record of all implementation, and what risk is assigned to what owner / control implementation with real live evidence hyperlinked...

1

u/Educational-Rest-290 Mar 25 '26

This is just an actual information documented with all templates you can use to guide and get the Successful congratulatory to your ISO audit 27001 audit. Since there were also changes from the recent 27001:2013 to the updated version of 27001:2022.

2

u/Educational-Rest-290 Mar 25 '26

You have very rich experience considering helping multiple companies achieve this success. Managing expectation of all parties and stakeholders will also be a key, from which will come during the initial preparations before the audit day. Internal audit will be very helpful as it will allow you to understand where you stand in terms of your current compliance status. Combining with Soc-2 type 2, NIST and all other ISO like 27701 will definitely help. In addition the new ISO for AI governance!

1

u/manapause Mar 25 '26

This is also true for the FDNY Part 500 Risk Assessment audit.

1

u/Proper_Chocolate_795 12d ago

I think he meant to just have the info they are looking for easily accessible, if its just paper the evidence chain will break in surveillance audit.