Skip to main content
RiskZeroCertifiers

Services

Certification audits for every point in the cycle

We do one thing: audit and certify information security management systems. Each service below is a defined step in the ISO 27001 certification cycle, planned around your calendar and priced before you commit.

Where each service fits

The cycle at a glance

SRG prepares and attests the package before it reaches us. Initial certification takes it from Stage 1 to a certificate. Surveillance keeps the certificate valid. Recertification starts the next cycle.

  1. Before

    SRGBuild and attest

    SRG helps you build the ISMS and attests that the package is ready. It is submitted through riskzero.us. RiskZero takes no part in this step.

  2. Month 0

    Stage 1Readiness review

    We review the package: scope, risk assessment, Statement of Applicability, and evidence of internal audit and management review, and confirm you are ready for Stage 2.

  3. Month 1 to 2

    Stage 2Certification audit

    On-site or remote audit of how the ISMS actually operates: interviews, records, sampled controls, and evidence.

  4. Month 2 to 3

    DecisionCertificate issued

    An independent reviewer checks the audit file. Once any nonconformities are closed, your certificate is issued and can be verified with us directly.

  5. Month 12

    Year 1Surveillance audit

    A shorter audit confirming the ISMS is maintained, internal audits and management reviews have happened, and corrective actions are working.

  6. Month 24

    Year 2Surveillance audit

    Second annual check, usually covering the parts of the ISMS not sampled in year one.

  7. Month 36

    Year 3Recertification

    A full audit before the certificate expires. Pass it and a new three-year cycle begins with no gap in certification.

What we do not do

No consulting. No implementation. No shared people.

Accreditation rules prohibit a certification body from auditing a management system it helped to build, and for good reason: a certificate is only worth something if the people issuing it have no stake in the outcome. RiskZero does not write policies, run risk assessments, act as an internal auditor, or implement controls.

That work is done by your consultants or your own team. Most packages we certify are built and attested bySRG and reach us through riskzero.us; we work with both and say so, and we accept packages prepared by any consultancy or in-house on the same terms. RiskZero Certifiers is a separate company with its own auditors, reviewers, and signatories, and nobody who prepared a package takes part in auditing it or in the certification decision. Read our impartiality statement for the full position.

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.