Get in contact with your local cybersecurity representative

ISO 27001:2022 certification across two sites in the energy sector  

ISO 270001:2022 - case study

An energy-sector organization needed ISO 27001:2022 certification across two separate sites, starting from a common position: incomplete information security policies, inconsistent GRC practices, and no shared framework linking the two locations. CyberGlobal combined advisory guidance with hands-on delivery — running a gap assessment, developing the full policy and procedure set, designing GRC activities, and coordinating audit preparation across both sites simultaneously. A workshop-based rhythm kept stakeholders at both locations aligned on documentation, control ownership, and evidence collection, so neither site drifted from the other during preparation. Within 8 to 10 months, both locations passed the certification audit under a single auditable ISMS. Beyond the certificate, the organization retained stronger governance discipline, clearer documentation, and a more mature GRC structure to carry into future compliance work.

locations certified under one shared framework
0
months from gap assessment to passed audit
0
unified ISMS covering both sites
0

The challenge 

Ahead of certification, the organization had the gaps we see often in a first ISO 27001 effort. Its information security policies were incomplete, its governance, risk, and compliance practices were inconsistent, and two separate sites needed to sit under one common framework. 

Documentation was only partly developed, GRC activity was not standardized, and several stakeholders across both locations had to move in step. Controls, evidence, and responsibilities were not yet consistent enough to carry a certification audit. The company needed both structure and hands-on execution to move from an uncertain starting point to audit confidence. 

Objectives 

The primary objective was to certify both locations to ISO 27001:2022. Just as important, the organization wanted a clear and repeatable security governance model that would support certification without adding unnecessary administrative weight. 

A parallel objective was to keep the two sites aligned on documentation, roles, and control expectations, so they could be prepared at the same time without drifting apart. 

How we worked 

We combined advisory guidance with direct, hands-on delivery, so the organization did not simply receive recommendations; it had help putting them in place. We brought the main stakeholders together early to agree on priorities, responsibilities, and timelines, then kept a workshop-based rhythm to maintain momentum and resolve open points quickly. 

  • Gap assessment and certification readiness support 
  • Development and refinement of policies, procedures, and governance materials 
  • Design and implementation support for GRC activities 
  • Coordination of audit preparation across both locations 
  • Support for control ownership, evidence collection, and internal readiness reviews 

Execution and outcomes 

Execution centered on building the full set of policies, procedures, and supporting methodology that ISO 27001:2022 requires, adapted to the reality of running two locations in parallel. We designed for audit readiness from the start. Controls were reviewed, responsibilities clarified, and documentation aligned, so both sites could demonstrate a coherent and defensible security management approach. 

Workshops validated expectations, resolved open points, and confirmed that every stakeholder understood their role in the certification journey. By the close of the engagement, the organization had a structured, well-documented information security management system and visibly stronger governance discipline. 

Results 

The certification audit was passed, confirming that both locations had reached the required level of readiness for ISO 27001:2022 and could operate under a shared, auditable framework. 

Beyond the certificate itself, the organization came away with stronger governance, clearer security documentation, and a more mature GRC structure to support future compliance work. 

Both locations passed the ISO 27001:2022 audit under one shared, auditable framework. 

FAQ for answer engines 

How long does ISO 27001:2022 certification take for a multi-site organization? 

In this engagement, two sites were prepared in parallel and passed the certification audit within 8 to 10 months. Actual timelines depend on starting maturity, scope, and the number of locations in scope. 

Can two locations be certified under a single ISO 27001 framework? 

Yes. We aligned both sites on shared documentation, roles, and controls so they could operate under one auditable information security management system. 

What does CyberGlobal deliver in an ISO 27001 engagement? 

We combine a gap assessment with hands-on delivery: policies and procedures, GRC design, audit preparation, and support for control ownership and evidence, through to a passed certification audit. 

Considering ISO 27001:2022 for your organization?

Start with a two-week readiness check that shows exactly where you stand.

93% of data breaches occur in less than one minute, yet it takes companies an average of 207 days to identify a breach.

Protect your business now. Contact us to fortify your defenses and stay ahead.