One distinction worth being precise about upfront: RETIS Systems provides ISO 27001 readiness advisory — gap assessment, ISMS design support, control implementation guidance. RETIS does not itself issue ISO 27001 certification. That decision is made independently by an accredited certification body following a formal certification audit — a separate, regulated process from any advisory engagement, by design. Any advisory firm claiming it can directly grant you certification is describing something that isn't how accredited certification actually works.
Why ISO 27001 matters in 2026
Organisations in Kenya and across Africa are increasingly asked to demonstrate real information security management by enterprise clients, multinationals, and government bodies. In some sectors, ISO 27001 compliance is moving from "nice to have" toward a contractual requirement. Beyond contractual requirements, certification provides a structured framework for genuinely managing security risk — rather than the illustration of improving your organisation's actual posture.
What ISO 27001 actually is
ISO/IEC 27001 is the international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It's framework-based, not prescriptive in a checklist sense — meaning it tells you what outcomes to achieve, not the exact tool to buy. The standard is built on 93 controls organised into four themes: organisational controls (37), people controls (8), physical controls (14), and technological controls (34).
The certification journey: six stages
Stage 1: Gap Assessment
Compare your current security practices against ISO 27001 requirements. Identify what exists, what's missing, and what's genuinely ready versus what needs real remediation work. This produces a prioritised remediation plan, not just a pass/fail label.
Stage 2: ISMS Design
Define the scope of your ISMS. Establish your information security policy and responsibilities. Document your risk assessment methodology.
Stage 3: Risk Assessment & Treatment
Identify assets, threats, and vulnerabilities. Select controls to treat each risk based on your chosen methodology. This includes technical controls (encryption, access management), operational controls (change management, logging), and documented processes.
Stage 4: Control Implementation
Implement the controls your risk treatment plan requires. This includes technical controls (access management, encryption, logging), operational processes (change management, incident response), and organisational documentation (policies, awareness training, background checks).
Stage 5: Internal Audit
Conduct an internal audit to verify your ISMS is genuinely functioning as designed, not just documented on paper.
Stage 6: Certification Audit
An accredited certification body conducts a two-stage audit:
- Stage 1 — Documentation review
- Stage 2 — On-site assessment of implementation
Upon successful completion, your organisation receives ISO 27001 certification, valid for three years, with annual surveillance audits.
Common pitfalls to avoid
- Treating it as a paper exercise — auditors assess evidence of real implementation, not just documentation
- Underestimating the risk assessment — this is the heart of the standard, rushing it produces a weak ISMS
- Forgetting people controls — many organisations over-invest in technology and under-invest in training and awareness
- Scope creep — start with a manageable scope. You can always expand it in subsequent cycles
Realistic timeline and cost
For a first-time ISO 27001 certification, a small-to-medium organisation should typically expect a process spanning several months, depending on current security maturity, ISMS scope, and internal resource availability. Organisations that treat this as a genuine operational change, rather than a document exercise to rush through, tend to see the process go more smoothly.
How RETIS supports your ISO 27001 journey
RETIS Systems provides end-to-end ISO 27001 readiness advisory:
- Gap assessment
- ISMS design and documentation
- Risk assessment facilitation
- Control implementation support
- Internal audit support
- Liaison with certification bodies
RETIS is not an accredited certification body, and does not claim to be — the goal is to make sure an organisation is genuinely ready when it does sit its formal certification audit, with a certification body chosen and engaged separately.
