Identify Gaps Before the Audit Begins

Our Certification Pre-Assessment is designed to help your organization prepare with confidence for ISO/IEC 27001, 27701, or 27018 certification.

Certification Pre-Assessment

A formal Pre-Assessment is not a requirement of certification under the ISO/IEC 27001 standard but it can be helpful for initial certification. The intention of the assessment is to save the organization time and money by identifying deficiencies in its Information Security Management System (ISMS) before seeking certification to the ISO/IEC 27001 standard.

Many organizations have found this to be an important step in the process of preparing the organization for the formal certification Audit.

During the pre-assessment, Securisea ISO will perform a high-level review of your intended scope, policies, procedures, and control processes to identify gaps in the conformity of your proposed ISMS to the ISO/IEC 27001: 2013 standard. The assessment will provide a comparison between all requirements of the standard and the processes, procedures, and controls you have in place for the design, implementation, operation, and maintenance of your ISMS. The final result will be a report providing clarity on the deficiencies that will need to be addressed before a formal certification audit.

  • Processes for granting, refusing, suspending, restoring or withdrawing certification:

    Securisea CB's process for certification decisions are designed to conform with ISO17021-1:2015 and ISO27006. In doing so our process to decide whether to grant or refuse certification to an entity begins with a formal Application for Certification.

    The process includes a number of stages including but not limited to applying for certification, undergoing a Stage 1 and Stage 2 audit and possibly the resolution of one or more non-conformities. Once this process is complete, the client's lead auditor will prepare a certification package with a recommendation to grant or refuse the certification and submit both to the certification committee for a decision. the certification committee will examine the totality of the evidence and grant or refuse the certification. This decision may be appealed according to Securisea CB's appeals process.

    Certifications must be maintained via ongoing surveillance and re-certification audits. In the event that a certificate holder is unable to show ongoing conformance to the requirements of its certification, said certification may be withdrawn. In this case the client may rectify the issues which caused the suspension in order to have the certification restored. All decisions to suspend or restore a certification are made by the audit committee and may be appealed. A certification may also be suspended at the entity's request.

    In the event that a certification is suspended for 6 months or greater the certificaiton will be withdrawn if the client has not filed an appeal. In the event that a suspension has been appealed, it will usually continue to be considered suspended until the appeal is closed, even if this is greater than 6 months.

    Process for expanding or reducing the scope of certification:

    Certification holders may apply for an expansion or reduction of the scope of a certification at any time. Securisea CB, LLC will usually need to conduct a surveillance or re-certification audit prior to the granting of a scope expansion unless the application is relatively minor in nature. The certification may also be reduced by Securisea CB in the event that that information is brough to our attention that the client's existing scope is invalid.

    All decisions to grant an expansion or reduction of certification scope must be approved by the certification committee.

  • Any statements regarding certification by Securisea CB or use of Securisea CB's certification mark may only be made by entities with active granted certification(s) and an active service agreement, in accordance with both the certification's scope and the terms of the service agreement between the client and Securisea CB.

  • Securisea CB maintains a compliants and appeals process. Complaints may be made by submitting a request via the complaints page. and must state the entity making the complaint, contact information including a working phone number, and the nature of the complaint. Valid complains will be examined and addressed by someone not a party to the specific complaint in question. Appeals should be submitted via the appeals page and must include contact information including a working telephone number. All appeal decisions are made by staff who were not involved in the related audit or certification decision.

    Requests for information must included contact information including a working phone number and may be made via the contact page