Skip to main content

Readiness

ISO 27001 and SOC 2 readiness, and who is allowed to do it

The scheme that awards the certificate also decides who may help you earn it. Internal audit and management system consultancy both sit outside what your certification body is permitted to offer you, so somebody else has to do them.

This page sets out what that work reaches when we do it, what arrives at the end, and what changes the size of it.

The clause that decides it

ISO/IEC 17021-1:2015 governs bodies that certify management systems. Two of its impartiality clauses decide who may prepare you.

“The carrying out of internal audits by the certification body and any part of the same legal entity to its certified clients is a significant threat to impartiality. Therefore, the certification body … shall not offer or provide internal audits to its certified clients.”

ISO/IEC 17021-1:2015, §5.2.6

“The certification body and any part of the same legal entity and any entity under the organizational control of the certification body shall not offer or provide management system consultancy.”

ISO/IEC 17021-1:2015, §5.2.5

Security Brigade prepares organisations for certification and runs the clause 9.2 internal audit programme. The certification decision, the Stage 2 audit and the certificate itself belong to your certification body. A SOC 2 examination and the opinion that comes with it belong to a licensed CPA firm.

The three checklists on this site are the same work in a form you can run yourself: the ISO 27001 checklist, the clause 9.2 internal audit programme and the SOC 2 checklist.

What the engagement reaches

A gap assessment against the standard as it stands

Where the management system is today against what the standard asks of it, with each gap carrying the clause it comes from and what closing it involves. The output is a list you can schedule, not a score.

The clause 9.2 internal audit programme

The programme itself, its schedule, its criteria and scope for each audit, and the records clause 9.2 requires you to retain. This is the piece your certification body is forbidden to provide, and the piece an assessor samples first.

Management review inputs, in the form clause 9.3 lists

The inputs assembled and put in front of the people who have to take the decisions, so the review is a meeting with evidence in it.

SOC 2 readiness against the criteria your report will cover

Controls mapped to the Trust Services Criteria in scope, and the evidence the examining firm will ask you to produce, gathered before they ask.

What arrives

  • A finding register with the clause reference against every entry, ordered so the items your certification body would raise at Stage 2 are closed first.
  • The internal audit programme and its records, in a form that survives being handed to somebody else next year.
  • Management review inputs assembled against the clause that lists them.
  • For SOC 2, a control-to-criteria map and the evidence request list your examining firm is likely to issue.
  • A re-check after remediation, so the register closes on evidence and not on assertion.

What moves the size of it

  • How many sites and legal entities sit inside the scope statement.
  • Whether a management system already exists or is being written from the start.
  • How many of the controls you have declared applicable are already operating, with records.
  • Whether the internal audit is a first cycle or a repeat with a prior programme to build on.
  • For SOC 2, which criteria the report has to cover, and whether the window is a point in time or a period.

Security Brigade has been CERT-In empanelled since 2008. Empanelment is what SEBI’s CSCRF requires of the auditing organisation for audits under that framework, and the RBI Directions, 2026 at paragraph 159 direct a bank engaging an auditor to be guided by CERT-In’s audit policy guidelines. Certification to ISO 27001 runs on its own chain, through a body accredited for that purpose.

Tell us where the scope stops

The scope statement and the date your certification body expects to see you decide almost everything else about the engagement.

Talk to our team