ISO 27001:2022, without the mystique.
If your clients are insurers, your security posture is now their regulatory problem — and their questionnaires are yours. Here is what certification actually takes, phase by phase, for a South African service provider.
Why your clients keep asking
Joint Standard 1 of 2024 (outsourcing) obliges insurers to perform due diligence on material service providers, with legacy arrangements compliant by 1 December 2026. Joint Standard 2 of 2024 (cybersecurity and cyber resilience) makes their accountability explicit. An accredited ISO/IEC 27001 certificate is the one answer that satisfies every client at once — it is independently audited, annually surveilled, and internationally understood.
The realistic timeline: 7–9 months
| Phase | Months | What happens |
|---|---|---|
| Foundation | 1–2 | Scope the ISMS, write the information security policy, define roles, set your risk methodology. Appoint the ISMS manager with real allocated time — nothing proceeds reliably without this. |
| Risk & SoA | 2–3 | Asset inventory, risk assessment against your own scales, treatment decisions, and the Statement of Applicability — the document your auditor will live in. |
| Controls & documents | 3–5 | Close the gaps the SoA exposed: policies, procedures, supplier agreements, and the operational registers (assets, suppliers, obligations, incidents). |
| Evidence window | 5–7 | Run the ISMS and let it generate proof: backup checks, DR tests, access reviews, training records. Evidence cannot be backfilled — auditors check dates. Start this window early. |
| Internal audit & review | 7–8 | An internal audit against the full standard, corrective actions, and a minuted management review — all mandatory before stage 1. |
| Certification audit | 8–9 | Stage 1 (documentation) and stage 2 (implementation). Findings get corrective actions; the certificate follows. |
What auditors actually ask for
- The chain, not the binder. For any control: show the policy that mandates it, the risk it treats, and dated evidence it operates. Disconnected documents fail this test; a system of record passes it.
- Recorded decisions. Who accepted each residual risk, and when? Was the acceptance re-confirmed after the score changed?
- Operating rhythm. Recurring activities with owners, due dates, and completion evidence — not screenshots assembled the week before.
- Supplier oversight. A.5.19–A.5.22 expect you to manage your suppliers the way your clients manage you.
Where Evidently fits
Evidently is a system of record for exactly this journey: the catalog is seeded, the methodology gate enforces clause 6.1.2 ordering, the SoA links every control to its documents, risks and evidence, and the evidence engine runs your operating rhythm on a calendar. Watch the training videos to see each phase on real screens, or start your workspace — the first hour covers scope, roles and methodology.