Governance, Risk & Compliance
Most ISO 27001 projects produce documentation that satisfies the auditor but does not reflect how the organisation works day to day. We build it the other way around.
Who this is for: Organisations pursuing ISO 27001 certification, remediating a failed audit, or meeting a client or procurement requirement.
The problem: Most ISO 27001 projects produce documentation that passes the audit but does not reflect how the organisation actually works.
The outcome: A certified ISMS your team can run and maintain, built from a scoped gap assessment rather than a template.
The problem
Organisations pursuing ISO 27001 certification face two risks. The first is building an ISMS that passes the audit but sits in a drawer afterwards. The second is spending six months on the wrong controls and failing the certification audit anyway.
Both happen when the project is treated as a documentation exercise. ISO 27001 requires you to identify your real risks, implement controls proportionate to those risks, and demonstrate continuous improvement. Auditors are looking for evidence that the system works, not evidence that you can write a policy.
For Nigerian organisations, the challenge is compounded. Your ISO 27001 controls often need to align with NDPA 2023 and CBN cybersecurity requirements simultaneously. Running three separate compliance programmes for overlapping obligations is expensive and error-prone.
The cost question adds a further layer of uncertainty. Without a clear scope, organisations struggle to budget for certification, and quotes from different consultancies can vary widely because they are pricing different amounts of work. A gap assessment fixes this early, because it turns a vague certification goal into a defined, costed plan.
Time pressure makes the problem worse. A board or a major client sets a certification deadline, and the project gets compressed into a documentation sprint. Controls get written up without being properly implemented, which either fails the audit or produces a certificate that does not reflect a working system.
What we do
FortressPoint delivers ISO 27001 implementation across UK and Nigerian markets. We start with a gap assessment against all 93 Annex A controls and your current environment, not a generic risk matrix. The gap assessment tells you exactly what needs to change and in what order.
From there we design an ISMS that reflects your actual operations. We write policies your team will follow, build a risk register that names real threats, and run the internal audit before your certification body does. No surprises at the audit stage.
For Nigerian clients we align the ISO 27001 controls to NDPA 2023 requirements and CBN frameworks from the start. You meet three regulatory obligations through one structured programme.
We work in phases so the project stays visible to your board. The gap assessment gives you a scoped plan and a realistic cost estimate. The build phase produces the documentation and implements the controls. The internal audit and management review confirm the system works before you invite your certification body in. Each phase has a clear output, so progress is never guesswork.
Selecting the certification body is part of the process, not an afterthought. We help you choose a UKAS-accredited or equivalent body appropriate to your sector and geography, and we coordinate directly with them through Stage 1 and Stage 2 audits so nothing gets lost between your team and theirs.
Who this is for
What you get
Why FortressPoint
The consultant who assesses your environment is the same one who writes your documentation and prepares your team for the audit. You will not be handed to a junior team after scoping.
We have dual-market expertise that most ISO 27001 consultancies do not. If your organisation operates in both Nigeria and the UK, we build one programme that satisfies both sets of obligations. You do not run separate compliance tracks for overlapping requirements.
We build for maintainability. If your team cannot run the ISMS after we leave, we have not done the job properly. Every deliverable is designed to be owned by your people, not dependent on continued consultancy.
We quote against a defined scope, not a guess. The gap assessment gives you and us the same picture of the work involved, so the cost estimate that follows is grounded in your actual environment rather than a generic day-rate multiplied by an assumption.
Common questions
Cost depends on the size of your organisation, the number of Annex A controls already in place, and which certification body you use. The main cost components are the gap assessment, the ISMS build, internal audit support, and the certification body’s own audit fees, which are billed separately by the body. A gap assessment is the fastest way to turn this into a specific figure for your organisation rather than a general range.
Most first-time certifications take three to nine months from gap assessment to Stage 2 audit, depending on how much of the ISMS already exists and how quickly your team can implement remediation actions. Organisations remediating a failed audit or renewing certification typically move faster, because the core documentation and controls are already in place.
Smaller organisations with a dedicated, experienced security lead sometimes run the process internally. Most organisations bring in a consultant because the gap assessment, documentation, and audit preparation take specific expertise and pull time away from day-to-day security work. A consultant also reduces the risk of failing the audit because of a control that was implemented but not evidenced correctly.
Stage 1 is a documentation review. Your certification body checks that your ISMS documentation is complete and that you are ready to be assessed. Stage 2 is the substantive audit, where the auditor tests whether your controls are actually operating as documented. Certification is awarded after a successful Stage 2 audit.
Yes, in most cases. We design a single ISMS that satisfies ISO 27001:2022 and maps its controls to NDPA 2023 and CBN cybersecurity framework requirements where they overlap with your Nigerian operations, so you are not running duplicate compliance programmes for the same underlying controls.
Your certification body issues a nonconformity report describing what needs to be fixed. Minor nonconformities usually require a corrective action plan and evidence submitted within a set period. Major nonconformities can require a follow-up audit. We support remediation either way, and a failed audit usually points to a small number of specific gaps rather than a need to restart the whole programme.
If you are starting an ISO 27001 programme, remediating a failed audit, or aligning to Nigerian regulatory requirements, contact us.