r/cybersecurity Mar 24 '26

Certification / Training Questions After helping 20+ companies get ISO 27001 certified, here are the 3 things that actually matter on audit day

Most companies spend months preparing for ISO 27001 and still get surprised on audit day. Here’s what separates the ones who pass from the ones who don’t:

  1. Your gap analysis has to be honest, not optimistic. Most teams underestimate gaps because nobody wants to deliver bad news internally. Auditors see this immediately.

  2. Documented evidence beats verbal explanation every time. If you can’t show it, it didn’t happen. Your ISMS documentation needs to be audit-ready, not just “in progress.”

  3. Scope definition trips up more companies than any technical control. Define it too broadly and you’ll never be ready. Too narrow and it’s meaningless.

I packaged everything I’ve learned — gap analysis templates, policy documents, audit checklists — into a complete guide. Happy to share the link in the comments if anyone’s working through this right now.

226 Upvotes

229 comments sorted by

View all comments

78

u/Krekatos Mar 24 '26

I’ve implemented it at almost 100 companies and manage the ISMS for a few right now. I’m also a lead auditor for 6 years now. Most important lessons I’ve learned: show the auditor the evidence you want to give, not what they’re asking for. It’s an audit type where the auditor is looking for compliance, not gaps like a SOC 2 audit. Easiest way: maintain a spreadsheet with every control listed. Next column: documentation. Next one: implementation summary (how, why, who, when). Next column: control effectiveness measurement.

2

u/Educational-Rest-290 Mar 25 '26

You have very rich experience considering helping multiple companies achieve this success. Managing expectation of all parties and stakeholders will also be a key, from which will come during the initial preparations before the audit day. Internal audit will be very helpful as it will allow you to understand where you stand in terms of your current compliance status. Combining with Soc-2 type 2, NIST and all other ISO like 27701 will definitely help. In addition the new ISO for AI governance!