Abstract dark navy and purple graphic representing ISO 27001 readiness
|

ISO 27001 Readiness: Where South African Organisations Start

POPIA got South African businesses thinking about compliance. ISO 27001 is where the serious ones end up. If your organisation is tendering for government contracts, supplying large enterprises, or operating in financial services, ISO 27001 is increasingly the price of entry, not a nice-to-have.

The problem is that most businesses start in the wrong place. They download the standard, read the control list, get overwhelmed, and either give up or hire a consultant who produces a 200-page policy document that nobody reads. ISO 27001 is not about policies. It is about demonstrating that you manage information security risk in a systematic way, and that your controls actually work.

Start with scope, not controls

The first question is not “which controls do we need?” It is “what are we trying to protect, and for whom?” If you are a 200-person logistics company, your scope might be your warehouse management system, your customer data, and your financial records. If you are a 20-person design agency, it might be your client files, your project management platform, and your email. The scope determines which controls apply and which ones you can justify excluding.

Getting scope wrong is the most common reason ISO 27001 projects run over budget and over time. Too broad and you are trying to secure everything, which means you secure nothing properly. Too narrow and the certification is not worth the paper it is printed on because the scope does not cover what your customers care about.

The gap assessment

Once you have a scope, the next step is a gap assessment. This is a structured comparison between what your current security setup does and what ISO 27001 requires. Not a theoretical exercise. A practical look at how you handle access control, incident response, vulnerability management, supplier risk, asset management, and the rest of the Annex A controls.

The output should be a short list of gaps with prioritised actions. Not a 200-page report. Something you can act on in 90 days.

Policies that people actually follow

ISO 27001 requires policies, but the standard does not require them to be long. A one-page acceptable use policy that staff read and sign is worth more than a 40-page document that sits in a shared drive unread. We have seen audits pass on the basis of short, clear policies backed by evidence that people follow them, and fail on the basis of comprehensive policies that nobody in the organisation could explain.

The auditor is not checking whether you have a document. They are checking whether you have a process that works. That means evidence: access reviews performed, incidents logged and resolved, vulnerabilities patched within SLA, supplier assessments completed. The policy is the framework. The evidence is the proof.

How long it takes

For a mid-sized organisation with decent security basics already in place, ISO 27001 readiness takes 3 to 6 months. The certification audit itself adds another 2 to 3 months. If you are starting from scratch with no formal security practices, expect 9 to 12 months. Anyone who tells you they can get you certified in 6 weeks is selling you a paper certificate, not a working security management system.

The practical starting point

If you are considering ISO 27001, start with three things. Define your scope in one page. List your current security tools and practices honestly. Identify the gaps between what you have and what the standard expects. That gives you a roadmap. Everything else follows from there.

If you want help with that first step, contact us. We do gap assessments and readiness work, not 200-page reports that gather dust.

The scope decision

One of the biggest mistakes organisations make with ISO 27001 is getting the scope wrong. Too broad and the project becomes unmanageable, with every system, process, and person in scope. Too narrow and the certification does not cover what customers and partners actually care about. The scope should cover the systems and processes that handle sensitive data, and the boundaries should be clear enough that an auditor can assess them without debate.

We help organisations define scope before any work starts. That means mapping where data flows, who handles it, what systems process it, and where the boundaries of the management system sit. Getting this right at the start saves months of rework later.

How long it takes

A realistic timeline for ISO 27001 readiness is 6 to 12 months, depending on the size of the organisation and the state of existing controls. Businesses that already have structured IT processes, documented policies, and basic security controls can move faster. Businesses starting from scratch need time to build the foundations before the audit can happen.

The certification audit itself is a two-stage process. Stage 1 is a documentation review. Stage 2 is an on-site assessment of whether the controls actually work. Both stages require preparation, and the gaps they find need to be closed before the certificate is issued. It is not a quick process, but it is a valuable one.

ISO 27001 begins with knowing what you’re protecting, and from what. We run a free attack-surface scan for South African companies. It’s passive, so nothing gets touched. You get a plain English report in your inbox. Start here: free security scan

Need Help With Your Security or IT?

We work with South African businesses to assess, deploy, and manage security and IT that actually fits. No jargon, no scare tactics. Practical advice and real support.

Contact Us →

See what hackers can see about your business

Get your free security scan

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *