Person am Laptop bei der Arbeit an Dokumentation in einem hellen, modernen Büro

ISMS & ISO 27001 Certification

Information security that works in daily operations.

An ISMS that gets lived, not a paper tiger

Many ISMS projects produce documents no one reads and processes no one follows. We build an information security management system to ISO 27001 that is as lean as possible and as comprehensive as necessary. From the initial assessment to certification readiness. And we stay until the system stands and the first internal audits have run.

Illustration for ISMS and ISO 27001 certification for Swiss SMEs

Regulatory context

The Information Security Act (ISG) requires operators of critical infrastructure to have an ISMS in place by 31 December 2026. The obligation to report cyberattacks has applied since April 2025, and fines of up to CHF 100,000 since October 2025. Affected sectors: energy, health, finance, transport, drinking water, wastewater, telecommunications, food, and public safety. Even without an ISG obligation, customers and partners increasingly require ISO 27001 as a precondition.

The ODCUS difference

As lean as possible, as comprehensive as necessary. We check existing controls for effectiveness and eliminate redundancies instead of piling on new tools. And we stay, rather than leaving behind a handover document that disappears into a drawer.

Service Item Image

ISO 27001 certification support

Book a free consultation

Why it matters:

An ISMS is only valuable when it works in daily operations. If a policy does not fit the workflow, the policy is wrong, not the employee. That is why we build processes people actually use, and we support you all the way to certification.

What you receive:

  • Business impact analysis and inventory of information assets
  • Risk assessment and risk treatment plan
  • Policies and processes that fit the company, not copied from a template
  • Defined responsibilities and roles
  • Enabling employees, not just training them
  • Internal audit and certification preparation

The path to certification

Three stages, from what is worth protecting to the first audits.

Assessment & BIA

Assessment & BIA

We start with what is worth protecting, not with a template.

  • Business impact analysis
  • Inventory of information assets
  • Gap analysis against ISO 27001
  • Scope definition
Risks & policies

Risks & policies

A risk treatment plan and policies that fit the company.

  • Risk assessment and treatment
  • Tailored policies
  • Roles and responsibilities
  • Controls chosen by effectiveness
Audit & certification

Audit & certification

We stay through certification readiness and the first audits.

  • Internal audit
  • Certification preparation
  • ISO 27001:2022 transition
  • Operation and continuous upkeep

Who this fits

  • Companies in ISG-regulated sectors (deadline December 2026)
  • SMEs that need ISO 27001 for customer requirements or tenders
  • Transition from ISO 27001:2013 to 2022
  • An existing ISMS that lives on paper but is not lived in practice

Proof from practice

  • Current mandate: BIA, asset inventory, ISMS build-out
  • Security policies and governance documents developed for a 1,600-employee company (backup & recovery, acceptable use, password, access and role management, incident response)
  • IT security frameworks (ISO 27001, CIS, BSI, NIST, MITRE, Zero Trust) applied operationally
  • CISM-certified (ISACA)
View all references

FAQ

Common questions about building an ISMS and ISO 27001 certification.

Two consultants in conversation in a modern office Schedule a call without obligations
How long does building an ISMS take?

For an SME with 50 to 150 employees, typically six to twelve months to certification readiness, depending on the starting point and the team's availability.

Do we absolutely have to certify?

No. Some companies want a lived ISMS without a formal certificate, others need the certificate for customers or regulation. We build in a way that makes both possible.

What if we already have an ISMS on paper?

Then we check what of it is effective and turn the paper tiger into a system that works in daily operations and is audit-ready, rather than starting from scratch.

What is the difference between an ISMS and ISO 27001?

The ISMS is the management system, that is processes, roles and controls. ISO 27001 is the standard an ISMS is certified against. A living ISMS is possible without a certificate, but a certificate is not possible without an ISMS.

Who does the ISG obligation apply to by the end of 2026?

Operators of critical infrastructure: energy, health, finance, transport, drinking water, wastewater, telecommunications, food and public safety. Even without an obligation, many customers require ISO 27001 as a precondition.

Do we need new tools for ISO 27001?

Usually not. We first check what is in place and effective. A lean ISMS often works with the existing means instead of buying new licenses.

"With ODCUS, we have a partner by our side who not only understands our IT but also tackles our challenges with us."
Jean-Claude Furegati, CEO, Furegati Holding AG

An ISMS that stands

Discuss without obligation whether an ISO 27001 ISMS is the right step for your company. In 30 minutes you know where you stand.

Two men in a relaxed conversation over coffee