The guide

ISO 27001:2022, without the mystique.

If your clients are insurers, your security posture is now their regulatory problem — and their questionnaires are yours. Here is what certification actually takes, phase by phase, for a South African service provider.

Why your clients keep asking

Joint Standard 1 of 2024 (outsourcing) obliges insurers to perform due diligence on material service providers, with legacy arrangements compliant by 1 December 2026. Joint Standard 2 of 2024 (cybersecurity and cyber resilience) makes their accountability explicit. An accredited ISO/IEC 27001 certificate is the one answer that satisfies every client at once — it is independently audited, annually surveilled, and internationally understood.

The realistic timeline: 7–9 months

PhaseMonthsWhat happens
Foundation1–2Scope the ISMS, write the information security policy, define roles, set your risk methodology. Appoint the ISMS manager with real allocated time — nothing proceeds reliably without this.
Risk & SoA2–3Asset inventory, risk assessment against your own scales, treatment decisions, and the Statement of Applicability — the document your auditor will live in.
Controls & documents3–5Close the gaps the SoA exposed: policies, procedures, supplier agreements, and the operational registers (assets, suppliers, obligations, incidents).
Evidence window5–7Run the ISMS and let it generate proof: backup checks, DR tests, access reviews, training records. Evidence cannot be backfilled — auditors check dates. Start this window early.
Internal audit & review7–8An internal audit against the full standard, corrective actions, and a minuted management review — all mandatory before stage 1.
Certification audit8–9Stage 1 (documentation) and stage 2 (implementation). Findings get corrective actions; the certificate follows.

What auditors actually ask for

Where Evidently fits

Evidently is a system of record for exactly this journey: the catalog is seeded, the methodology gate enforces clause 6.1.2 ordering, the SoA links every control to its documents, risks and evidence, and the evidence engine runs your operating rhythm on a calendar. Watch the training videos to see each phase on real screens, or start your workspace — the first hour covers scope, roles and methodology.

Start your ISMS Watch the training