From “we don't know what we have” to certification in seven months.
Starting point
A major OEM customer requires an ISO 27001 certificate for new contracts. Internal IT: two people, no security processes, no time.
Approach
Risk assessment in the first phase, policies and TOMs implemented in two quarters, audit support through both stages.
Result
Certified after seven months. The OEM contract is in — and the second audit ran without new critical findings.