Compliance
ISO 27001, with ISO365
A full Information Security Management System, built inside your own Microsoft 365 environment and run by real people until you are certified and after. Delivered with ISO365, who specialise in ISO 27001 implementation and auditing, while we handle the technical controls underneath it.
Somebody has asked you for ISO 27001
Usually a tender, or a customer large enough that their procurement team sets the terms. Occasionally a regulator, or a board that has read something. Either way it arrives as a requirement rather than an ambition, with a date attached.
The common answer is a consultant, a folder of documents written to pass an audit, and a system nobody maintains once the certificate is on the wall. It works once. The surveillance audit twelve months later is where it comes apart.
Most managed service providers stop at operations. The gap between running your IT well and being able to certify it is the whole problem, and it is where this sits.
Six months, and then it keeps running
A defined pathway rather than an open-ended engagement. The dates below are the typical shape of it: build the system, embed it, certify, then maintain it so the next audit is not a project of its own.
-
Months one and two
Build. A gap analysis workshop, two to three hours, that tailors the policies to how you actually operate. A full risk assessment. Your ISMS hub built in your own SharePoint, with the policies and registers created inside it. Risk treatment starts.
-
Months three and four
Embed. Risk treatment continues and the registers get reviewed and updated rather than filed. Staff training and awareness runs. The Stage 1 certification audit happens at the end of this stretch.
-
Months five and six
Certify. Risk treatment activities are finalised, ISO365 conducts the internal audit, the management review meeting is held, and the Stage 2 certification audit follows.
-
Ongoing
Maintain. Monthly reviews of risk, performance and improvements. Support through the annual surveillance audits. Continuous alignment as the standard and your business both move.
Clients supported through this partnership have typically certified within six months with zero non-conformities. That is the partnership’s record rather than a guarantee, and your own timeline depends on how much of the groundwork already exists.
Three parties, one system
Certification needs the people who own the risks, the people who deliver the controls and the people who run the management system to be working to the same plan. Most engagements have two of the three and improvise the rest.
-
Ericom, your technical team
Delivers and maintains the infrastructure, and implements the IT and cyber controls that the risk treatments call for. We are in the workshops and the audit preparation rather than being asked for evidence afterwards.
-
You, the risk owner
Bring the operational context, the objectives and the ownership of risk. Nobody can outsource knowing what matters to your business, and a system built without that is a system built to pass rather than to work.
-
ISO365, your compliance team
Your virtual compliance officers. They build and maintain the management system, facilitate the risk assessments, internal audits and management reviews, and represent you through the external audits.
The established partnership is the point. There is no ramp-up period and no gap where each side waits for the other to explain itself, which is where most of the time goes in a three-way engagement assembled for one job.
What is included
The full scope, so you can check rather than ask. Everything below is part of the service rather than quoted as it arises.
The system 6
- A complete ISO management system
- Registers and compliance documentation
- A tailored ISMS hub in your SharePoint
- ISO-aligned policies, registers and tools
- A dedicated Microsoft Teams channel
- Gap analysis workshop, two to three hours
The rhythm 4
- Monthly risk and performance sessions
- Monthly continuous improvement sessions
- Quarterly management review meetings
- Monitoring and measurement of performance
Assurance and audit 5
- Internal audits with non-conformity logging
- Stage 1 external audit support
- Stage 2 external audit support
- Annual surveillance audit support
- Training and audit preparation
Delivered entirely within your own Microsoft 365 tenancy. The documentation, the registers and the evidence stay under your control throughout, and they stay with you if the engagement ends.
What this is, and what it is not
A management system, run by people, that gets you certified and keeps you certified. Being precise about who does what is most of why it works.
What it does
-
A system, not a document pack
Registers that get reviewed monthly, risks that get treated, corrective actions that get closed. A folder of policies passes one audit and fails the next.
-
Inside your own tenancy
The ISMS hub is in your SharePoint and the collaboration is in your Teams. Your documentation and evidence never sit on somebody else's platform.
-
Real people, on a rhythm
Monthly risk and improvement sessions, quarterly management reviews, internal audits. Named people who are in it before the audit rather than summoned for it.
-
Yours at the end
The system, the registers and the evidence remain yours. If the engagement stops, your certification foundation does not leave with it.
What it does not do
-
We do not issue the certificate
ISO 27001 certification is granted by an accredited certification body, which is neither Ericom nor ISO365. We build the system, implement the controls and represent you through the audits. An independent body decides the outcome, and that independence is what makes the certificate worth holding.
-
Not a guarantee of certification
The record through this partnership is strong and it is not a promise. Certification depends on decisions and evidence that are yours, and any provider guaranteeing the result is describing something outside their control.
-
Not the Essential Eight
Different thing entirely. The Essential Eight is ASD guidance with no certificate available at all. ISO 27001 is an international standard you can genuinely be certified against. Being asked for one is not being asked for the other.
-
Not a substitute for security controls
A management system describes and governs your controls. It does not deploy them. The technical work sits with us or with whoever runs your IT, and the standard will ask for evidence that it happened.
-
Not instant, and not off the shelf
Six months is the typical shape. A platform that promises a certifiable ISMS in a fortnight is selling templates, and templates are what surveillance audits are good at finding.
Most providers stop at operations
Running your IT well and being able to prove it to an auditor are different jobs, and the second one is where tenders are won and lost. The gap between them is not a technical problem. It is a governance problem with a technical dependency, which is why it takes both teams.
Common questions
Short answers first.
How long does ISO 27001 certification take?
Typically six months through this partnership: two months building the system, two embedding it and reaching the Stage 1 audit, two finalising risk treatment and reaching Stage 2.
It moves faster if you already have documented processes, a clear scope and somebody internally who can own decisions. It moves slower if the scope keeps changing, which is the single most common cause of delay.
Who actually issues the certificate?
An accredited certification body, independent of both Ericom and ISO365. They run the Stage 1 and Stage 2 audits and the annual surveillance audits after them. We build the system, implement the controls and represent you through the process. Nobody who helps you prepare can also certify you, and that separation is the reason the certificate means anything.
Is this the same as the Essential Eight?
No, and the difference matters if somebody has asked you for one of them. The Essential Eight is guidance published by the Australian Signals Directorate, with eight mitigation strategies, three maturity levels and no certification available at all. ISO 27001 is an international standard with a formal certification process and an accredited body behind it. Some organisations need both, for different reasons, and they are separate pieces of work.
Do we have to move our IT to Ericom?
No. The management system side works alongside whoever runs your IT. Where we do run it, control implementation is faster and the evidence the auditor wants is easier to produce, because the same team doing the technical work is in the workshops. That is an advantage rather than a requirement.
What happens after we are certified?
The rhythm continues, because the standard requires it. Monthly reviews of risk and improvements, quarterly management reviews, internal audits, and support through the annual surveillance audit. Certification is not a finish line, it is the point at which the system has to keep working.
Where does our documentation live?
In your own Microsoft 365 tenancy. The ISMS hub is a SharePoint site in your environment and the working conversation happens in a dedicated Teams channel. Nothing sits on a third-party compliance platform you would have to keep paying for to retain access to your own evidence.
What about ISO 9001, or the other standards?
ISO 27001 for information security is the documented service and the one this page describes. ISO365 works across other standards including quality, environmental and work health and safety, and the same partnership model applies. If you need more than one, say so early: the systems share a great deal and building them together is cheaper than building them twice.
Start with the gap analysis
Two to three hours, and it produces the plan rather than a proposal. It also tells you honestly how far off you are, which is occasionally further and occasionally much closer than expected.
-
Agree the scope
Which parts of the business, which systems, which locations. Getting this wrong is the main reason certifications run long, and it is much cheaper to argue about it now.
-
Run the gap analysis workshop
Two to three hours with the people who know how things actually work. It tailors the policies to your operations and populates your registers with real tasks rather than placeholders.
-
Build, embed, certify
The six month pathway starts, with monthly sessions and a defined set of audits. You will know at every point what is outstanding and who owns it.
Find out how far off you are
A gap analysis is the honest first step. It tells you what is missing, what you already have that counts, and whether the date somebody has given you is realistic.
Book a gap analysis