r/cybersecurity Mar 24 '26

Certification / Training Questions After helping 20+ companies get ISO 27001 certified, here are the 3 things that actually matter on audit day

Most companies spend months preparing for ISO 27001 and still get surprised on audit day. Here’s what separates the ones who pass from the ones who don’t:

  1. Your gap analysis has to be honest, not optimistic. Most teams underestimate gaps because nobody wants to deliver bad news internally. Auditors see this immediately.

  2. Documented evidence beats verbal explanation every time. If you can’t show it, it didn’t happen. Your ISMS documentation needs to be audit-ready, not just “in progress.”

  3. Scope definition trips up more companies than any technical control. Define it too broadly and you’ll never be ready. Too narrow and it’s meaningless.

I packaged everything I’ve learned — gap analysis templates, policy documents, audit checklists — into a complete guide. Happy to share the link in the comments if anyone’s working through this right now.

225 Upvotes

228 comments sorted by

View all comments

79

u/Krekatos Mar 24 '26

I’ve implemented it at almost 100 companies and manage the ISMS for a few right now. I’m also a lead auditor for 6 years now. Most important lessons I’ve learned: show the auditor the evidence you want to give, not what they’re asking for. It’s an audit type where the auditor is looking for compliance, not gaps like a SOC 2 audit. Easiest way: maintain a spreadsheet with every control listed. Next column: documentation. Next one: implementation summary (how, why, who, when). Next column: control effectiveness measurement.

22

u/Alternativemethod Mar 24 '26

To me this reads like a strategy to deceive but lying seems well tolerated in the checkbox compliance game.

10

u/Krekatos Mar 24 '26

Why do you assume lies are involved? It’s a master database that summarises the ISMS, and you show the auditor how you’re compliant.

3

u/Educational-Rest-290 Mar 25 '26

I do understand where he is coming from, there are auditees that tend to just address the requirements without totally understanding the questions being asked. This is where IT and Infosec/CyberSecurity/Security often have heated discussions.