Skip to Content
Support until certification is obtained3 to 6 monthsIRCA Lead AuditorsTailored support
Why certify

Secure your strategic data

ISO 27001:2022 establishes an information security management system (ISMS): risk analysis, security measures (Annex A), and continuous improvement.

What certification brings you

  • Data and intellectual property protection
  • Compliance (law 09-08, GDPR, client requirements)
  • Trust from clients and partners
  • Reduction of cyber risk and data breaches
  • Competitive advantage in IT markets
  • Foundation of security governance

Our approach in 6 steps

1
Week 1

Diagnosis & gap analysis

Current status in relation to the standard requirements, prioritised action plan.

2
Weeks 2-6

System design

Risk analysis, statement of applicability, security policies, Annex A measures and ISMS documentation.

3
Weeks 6-12

Deployment & training

Operational implementation, awareness and training of teams.

4
Week 13

Internal audit

Compliance verification, identification of residual gaps.

5
Week 14

Management review & mock audit

Final preparation, simulation of the certification audit.

6
Months 4-6

Certification audit

Support on the day with the accredited certification body.

Relevant Sectors

IT & OffshoringBanking & FinanceHealth & PharmaceuticalsServicesPublic SectorTelecoms
ISO 9001 CertifiedISO 37301 CertifiedPECBIASSC Lean Six SigmaIAF · IAS — International Accreditation ServiceResponsible SME Label

Frequently Asked Questions

What version of the standard?+
The 2022 version, which includes our mastery of the new controls in Annex A.
Link to GDPR / Law 09-08?+
The ISMS greatly facilitates regulatory compliance regarding personal data.
How long does it take?+
4 to 8 months depending on the scope of the information system.
Who is the ISO 27001 certification aimed at?+
ISO 27001 applies to any organisation that handles sensitive or strategic data: IT and offshoring companies, banks and financial institutions, health and pharmaceuticals, telecoms, services, and the public sector. It often becomes essential when a client, contractor, or tender requires cybersecurity guarantees. At TargetUp, the approach is tailored to your size and information system, from offshore providers to financial institutions.
What is an ISMS and what does Annex A of the 2022 version cover?+
The ISMS (Information Security Management System) is an organisational framework that identifies your risks, defines measures to address them, and drives continuous improvement. Annex A of ISO 27001:2022 includes 93 security measures divided into 4 themes: organisational, human, physical, and technological. We work with you to select the relevant measures and formalise them in the Statement of Applicability (SoA).
How does your ISO 27001 support actually work?+
Our approach follows 6 steps: diagnosis and gap analysis, system design (risk analysis, SoA, security policies and ISMS documentation), deployment and team training, internal audit, management review and pre-certification audit, followed by the certification audit with an accredited body. At each stage, you receive actionable deliverables: risk mapping, ISMS documentation corpus, and a prioritised action plan. A dedicated security consultant will support you until the D-day.
Do you need to be certified ISO 9001 to aim for ISO 27001?+
No. ISO 27001 is a standalone standard that can be implemented independently of any other certification. If you already have an ISO 9001 system, the common structure of ISO standards (High Level Structure) accelerates deployment and facilitates integration into an Integrated Management System. Otherwise, we start from your existing setup, with no prerequisites.
Is ISO 27001 reserved for companies with significant technical resources?+
No. ISO 27001 is primarily a management approach based on risk, not a collection of technical tools. Security measures are proportionate to your actual stakes and the size of your information system. Both SMEs and large groups can achieve certification, provided their risks are properly managed — this is precisely what our methodology structures for you.
What is the difference between ISO 27001 and ISO 27701?+
ISO 27001 protects all your information (security), while ISO 27701 is an extension dedicated to the protection of personal data (privacy, PIMS). ISO 27001 serves as the foundation: it subsequently facilitates compliance with GDPR and Law 09-08. Many organisations start with ISO 27001, then add ISO 27701, ISO 20000-1 (IT services), or ISO 22301 (business continuity), which we also support.
What distinguishes TargetUp for ISO 27001 support?+
TargetUp is a triple certified firm (ISO 9001, 21001, and 37301), with a support until certification is obtained in certification audits on the first attempt. Our auditors are qualified Lead IRCA, and our support is based on a contractual commitment to success. The result is a truly operational ISMS that reduces the risk of data breaches, secures your tenders, and provides lasting reassurance to clients and partners.
Tailored support
On quotation
Free diagnosis · support until certification is obtained
  • Quotation within 48 hours
  • Dedicated information security consultant
  • Commitment to success at the audit
Book a slot · 30 min (B2B diagnostic)
or write to us
✓ Automatically detected from the page
Response within 48 working hours
★★★★★
As an offshoring provider, ISO 27001 was a prerequisite for our European clients. TargetUp certified us without any non-conformities.
YK
CISO
IT service centre · Rabat

Protect your information, gain trust

Free diagnostic to estimate your timeline, budget, and roadmap.

Get started now