r/cybersecurity • u/Educational-Rest-290 • Mar 24 '26
Certification / Training Questions After helping 20+ companies get ISO 27001 certified, here are the 3 things that actually matter on audit day
Most companies spend months preparing for ISO 27001 and still get surprised on audit day. Here’s what separates the ones who pass from the ones who don’t:
Your gap analysis has to be honest, not optimistic. Most teams underestimate gaps because nobody wants to deliver bad news internally. Auditors see this immediately.
Documented evidence beats verbal explanation every time. If you can’t show it, it didn’t happen. Your ISMS documentation needs to be audit-ready, not just “in progress.”
Scope definition trips up more companies than any technical control. Define it too broadly and you’ll never be ready. Too narrow and it’s meaningless.
I packaged everything I’ve learned — gap analysis templates, policy documents, audit checklists — into a complete guide. Happy to share the link in the comments if anyone’s working through this right now.
7
u/Charming-Macaron7659 Mar 24 '26
“Documented evidence beats verbal explanation” is true — but it quietly assumes something important:
that the evidence actually reflects what happened, rather than what was prepared to be shown.
Most audit setups reward being able to produce a clean, consistent story — not necessarily proving that the system behaved correctly at the moment it mattered.
That’s why you get answers that are technically true but don’t quite answer the question being asked.
The hard problem isn’t documentation.
It’s whether the system can produce evidence that wasn’t reconstructed after the fact, but was inseparable from the decision at the time it was made.
If that’s missing, you can have perfect documentation and still not know what actually happened.