● ISO 27001:2022 cohort opening — Q3 2026 · 3 enrollments remaining
A pragmatic ISO 27001 and GRC practice for Canadian and North-African SMBs. We scope your ISMS, write the policies your team will actually follow, and walk you through certification without the theatre.
Typically reply in 1 business day
We don’t sell platforms. We write the documentation, run the workshops, build the evidence, and sit beside your team in the audit room.
A structured, four-week review against ISO 27001:2022 and your sector’s baseline. Findings, remediation plan, and effort estimate.
End-to-end program: scope, risk methodology, SoA, Annex A controls, internal audit, and management review — through Stage 2 certification.
Policy library, control matrix, and evidence workflows in your GRC tool of choice — Vanta, Drata, or a properly-configured Odoo.
A risk register your board will read. Quantitative where we can (FAIR), qualitative where we must, reviewed on a quarterly cadence.
A senior security leader on your exec team for 4–10 days a month. Strategy, board reporting, incident response, and vendor reviews.
Programs your team completes on purpose — scenario-driven, bilingual, reinforced with phishing exercises that match your threat model.
A predictable cadence. Each phase has a written deliverable, a signed-off exit criterion, and a clear owner on your side. No surprises at the audit.
ISMS scope statement, stakeholder map, context of the organization, interested parties.
Risk methodology, asset inventory, threat library, scored register with treatment plan.
Statement of Applicability, 22 core policies, standards and procedures — all signed off.
93 Annex A controls implemented with owners, cadence, and evidence workflows. You are here.
Independent internal audit, nonconformity register, management review, corrective action.
Stage 1 readiness audit, Stage 2 certification audit, closing NCs, certificate issued.

The 2022 revision consolidated 114 controls into 93 across four themes. We map each to an owner, a cadence, and a specific piece of evidence — not a paragraph of prose.

Policy, roles, supplier relationships, threat intelligence, information classification.
Screening, terms of employment, awareness training, disciplinary process, remote work.
Perimeters, entry, equipment, clear-desk, secure disposal, cabling and utilities.
Access, crypto, logging, vulnerability mgmt, secure dev, backups, network security.
Our security practice sits next to the team that ships websites and runs Odoo implementations. Our policies account for how your company actually builds and operates — not how a checklist imagines it.

Every lead is a practicing engineer, SRE, or sysadmin before they became a GRC consultant. Your controls will hold up to an auditor because they hold up to reality.
Policies and training materials delivered in the language your team speaks. Critical for Québec (Law 25), Morocco, and multinational teams with regulated LOBs.
We don’t drop a 400-page template. We write a scope that matches your business, your risk appetite, and your audit pressure — and nothing more.
Most clients need one framework loud and two frameworks quiet. We map once and satisfy all of them — without writing three sets of policies.
Certification is a milestone, not a finish line. Our engagements include the first year of surveillance prep, quarterly risk reviews, and incident support.
Noordev delivered our ISO 27001 certification in eleven months — and, more impressively, wrote policies our engineers actually read.
Twelve months is typical for a team of 20–200 starting from scratch. Smaller or better-organized teams can do it in 8–9. We publish a week-by-week plan before we start billing.
Yes, and we usually recommend it. About 85% of the work overlaps. We write one policy set, one control matrix, and one evidence workflow — then satisfy both audits from the same system.
Either. We’re tool-agnostic: Vanta, Drata, Tugboat Logic, Sprinto, or a well-configured Odoo for clients who prefer to keep everything in one system. We’ll recommend based on scale and budget.
Gap assessments start at $12,000 CAD. Full ISO 27001 implementations range $85k–$180k depending on scope, team size, and whether a vCISO is included. We send a fixed-fee proposal after the assessment.
Yes. Law 25 is bundled into our ISMS work for Québec clients at no extra cost — the policies, DPIAs, breach-response procedures, and consent flows map directly onto ISO 27001 Annex A.
No — by design. A certification body cannot also be your implementation partner. We prepare you and recommend three accredited CBs (Schellman, BSI, ISO-based in Canada) that have worked well for our clients.
Tell us what you’re trying to achieve — a customer requirement, a board directive, a breach response — and we’ll tell you, honestly, what the next three months should look like.
