ISO 27001 · Canada

ISO 27001 Readiness Consulting in Canada

I help Canadian startups and SMBs stand up an ISO 27001 information security management system that's ready for certification, without burying your team in paperwork. I've run ISO 27001 readiness across cross-border environments, including medtech and data centre operators.

76control SOC 2 Type II program built at Humera
20+client security & compliance engagements
9.1CVSS, CVE-2024-45163, Mirai kill switch
5,000+users on a live platform I secured

A right-sized ISMS that passes audit and survives it.

ISO 27001 is about a working security management system, not a binder of documents nobody reads. I scope an ISMS to your business, run the risk assessment, write your Statement of Applicability, and implement the Annex A controls that actually apply to you.

If you also need SOC 2 or ISO 42001 for AI, I map the overlapping controls once so you collect evidence a single time instead of running three projects in parallel. The compliance workspace is included, with all three frameworks pre-loaded.

Everything the engagement covers.

ISMS scope definition and context of the organization
Risk assessment and risk treatment plan
Statement of Applicability (SoA)
Annex A control implementation and evidence
Mandatory ISO 27001 documentation set
Internal audit and management review support
Stage 1 and Stage 2 certification audit coordination
Integrated SOC 2 and ISO 42001 control mapping

A clear path from where you are to done.

Scope & gap analysis

We define the ISMS scope and assess your current state against ISO 27001 clauses and Annex A controls.

Risk assessment & SoA

I run a right-sized risk assessment, build the treatment plan, and produce your Statement of Applicability.

Control implementation

We implement and document the applicable controls and stand up the evidence your certification body will request.

Internal audit & certification

I run the internal audit, prep the management review, and coordinate your Stage 1 and Stage 2 certification audits.

Questions founders ask before we start.

ISO 27001 or SOC 2, which do I need?

SOC 2 is expected by North American SaaS buyers; ISO 27001 is the global standard often required in Europe, the UK, and enterprise procurement. Many companies need both, and I can run them together so evidence is collected once.

How long to get certification-ready?

Most startups reach certification-ready in 3–6 months depending on scope and current maturity. Certification then involves Stage 1 and Stage 2 audits by an accredited body.

What is the Statement of Applicability?

The SoA is the core ISO 27001 document listing which Annex A controls apply to you, why, and their status. Auditors live in it, so getting it right early saves a lot of rework.

Do you cover ISO 42001 for AI?

Yes. ISO 42001 (AI management systems) is pre-loaded in my compliance workspace and maps cleanly onto an existing ISO 27001 ISMS if you're shipping AI features.

Do you work outside Canada?

I'm Canada-based and work with startups across the country, but ISO 27001 engagements are remote and I work with international teams regularly.

Build an ISMS that's ready for certification.

Tell me about your company and what's driving the timeline. I respond to every message personally.