
ISMS & ISO 27001 Certification
Information security that works in daily operations.
An ISMS that gets lived, not a paper tiger
Many ISMS projects produce documents no one reads and processes no one follows. We build an information security management system to ISO 27001 that is as lean as possible and as comprehensive as necessary. From the initial assessment to certification readiness. And we stay until the system stands and the first internal audits have run.
Regulatory context
The Information Security Act (ISG) requires operators of critical infrastructure to have an ISMS in place by 31 December 2026. The obligation to report cyberattacks has applied since April 2025, and fines of up to CHF 100,000 since October 2025. Affected sectors: energy, health, finance, transport, drinking water, wastewater, telecommunications, food, and public safety. Even without an ISG obligation, customers and partners increasingly require ISO 27001 as a precondition.
The ODCUS difference
As lean as possible, as comprehensive as necessary. We check existing controls for effectiveness and eliminate redundancies instead of piling on new tools. And we stay, rather than leaving behind a handover document that disappears into a drawer.
Why it matters:
An ISMS is only valuable when it works in daily operations. If a policy does not fit the workflow, the policy is wrong, not the employee. That is why we build processes people actually use, and we support you all the way to certification.
What you receive:
- Business impact analysis and inventory of information assets
- Risk assessment and risk treatment plan
- Policies and processes that fit the company, not copied from a template
- Defined responsibilities and roles
- Enabling employees, not just training them
- Internal audit and certification preparation
The path to certification
Three stages, from what is worth protecting to the first audits.

Assessment & BIA
We start with what is worth protecting, not with a template.
- Business impact analysis
- Inventory of information assets
- Gap analysis against ISO 27001
- Scope definition

Risks & policies
A risk treatment plan and policies that fit the company.
- Risk assessment and treatment
- Tailored policies
- Roles and responsibilities
- Controls chosen by effectiveness

Audit & certification
We stay through certification readiness and the first audits.
- Internal audit
- Certification preparation
- ISO 27001:2022 transition
- Operation and continuous upkeep
Who this fits
- Companies in ISG-regulated sectors (deadline December 2026)
- SMEs that need ISO 27001 for customer requirements or tenders
- Transition from ISO 27001:2013 to 2022
- An existing ISMS that lives on paper but is not lived in practice
Proof from practice
- Current mandate: BIA, asset inventory, ISMS build-out
- Security policies and governance documents developed for a 1,600-employee company (backup & recovery, acceptable use, password, access and role management, incident response)
- IT security frameworks (ISO 27001, CIS, BSI, NIST, MITRE, Zero Trust) applied operationally
- CISM-certified (ISACA)
FAQ
Common questions about building an ISMS and ISO 27001 certification.

How long does building an ISMS take?
For an SME with 50 to 150 employees, typically six to twelve months to certification readiness, depending on the starting point and the team's availability.
Do we absolutely have to certify?
No. Some companies want a lived ISMS without a formal certificate, others need the certificate for customers or regulation. We build in a way that makes both possible.
What if we already have an ISMS on paper?
Then we check what of it is effective and turn the paper tiger into a system that works in daily operations and is audit-ready, rather than starting from scratch.
What is the difference between an ISMS and ISO 27001?
The ISMS is the management system, that is processes, roles and controls. ISO 27001 is the standard an ISMS is certified against. A living ISMS is possible without a certificate, but a certificate is not possible without an ISMS.
Who does the ISG obligation apply to by the end of 2026?
Operators of critical infrastructure: energy, health, finance, transport, drinking water, wastewater, telecommunications, food and public safety. Even without an obligation, many customers require ISO 27001 as a precondition.
Do we need new tools for ISO 27001?
Usually not. We first check what is in place and effective. A lean ISMS often works with the existing means instead of buying new licenses.
"With ODCUS, we have a partner by our side who not only understands our IT but also tackles our challenges with us."
An ISMS that stands
Discuss without obligation whether an ISO 27001 ISMS is the right step for your company. In 30 minutes you know where you stand.


