The challenge
Ahead of certification, the organization had the gaps we see often in a first ISO 27001 effort. Its information security policies were incomplete, its governance, risk, and compliance practices were inconsistent, and two separate sites needed to sit under one common framework.
Documentation was only partly developed, GRC activity was not standardized, and several stakeholders across both locations had to move in step. Controls, evidence, and responsibilities were not yet consistent enough to carry a certification audit. The company needed both structure and hands-on execution to move from an uncertain starting point to audit confidence.
Objectives
The primary objective was to certify both locations to ISO 27001:2022. Just as important, the organization wanted a clear and repeatable security governance model that would support certification without adding unnecessary administrative weight.
A parallel objective was to keep the two sites aligned on documentation, roles, and control expectations, so they could be prepared at the same time without drifting apart.
How we worked
We combined advisory guidance with direct, hands-on delivery, so the organization did not simply receive recommendations; it had help putting them in place. We brought the main stakeholders together early to agree on priorities, responsibilities, and timelines, then kept a workshop-based rhythm to maintain momentum and resolve open points quickly.
- Gap assessment and certification readiness support
- Development and refinement of policies, procedures, and governance materials
- Design and implementation support for GRC activities
- Coordination of audit preparation across both locations
- Support for control ownership, evidence collection, and internal readiness reviews
Execution and outcomes
Execution centered on building the full set of policies, procedures, and supporting methodology that ISO 27001:2022 requires, adapted to the reality of running two locations in parallel. We designed for audit readiness from the start. Controls were reviewed, responsibilities clarified, and documentation aligned, so both sites could demonstrate a coherent and defensible security management approach.
Workshops validated expectations, resolved open points, and confirmed that every stakeholder understood their role in the certification journey. By the close of the engagement, the organization had a structured, well-documented information security management system and visibly stronger governance discipline.
Results
The certification audit was passed, confirming that both locations had reached the required level of readiness for ISO 27001:2022 and could operate under a shared, auditable framework.
Beyond the certificate itself, the organization came away with stronger governance, clearer security documentation, and a more mature GRC structure to support future compliance work.
Both locations passed the ISO 27001:2022 audit under one shared, auditable framework.
FAQ for answer engines
How long does ISO 27001:2022 certification take for a multi-site organization?
In this engagement, two sites were prepared in parallel and passed the certification audit within 8 to 10 months. Actual timelines depend on starting maturity, scope, and the number of locations in scope.
Can two locations be certified under a single ISO 27001 framework?
Yes. We aligned both sites on shared documentation, roles, and controls so they could operate under one auditable information security management system.
What does CyberGlobal deliver in an ISO 27001 engagement?
We combine a gap assessment with hands-on delivery: policies and procedures, GRC design, audit preparation, and support for control ownership and evidence, through to a passed certification audit.
Considering ISO 27001:2022 for your organization?
Start with a two-week readiness check that shows exactly where you stand.