Viewee
Start free
Pricing
Sign in
← Legal and assurance

DRAFT - FOR REVIEW

Viewee ISO/IEC 27001 Programme Roadmap

From zero to certification-ready | Version 0.1 | 16 September 2026

Build a small, operating ISMS around the whole Viewee service, not a paperwork-only project. Allow 9-12 months from an agreed scope to a credible Stage 2 audit for a two-person team, assuming roughly 0.5-1 founder-day per week during build, 1-2 days per month during the evidence period, and short peaks around audit and remediation. Faster is possible, but rushing before Viewee has several months of operating evidence increases rework and audit risk.

Viewee is not certified today and should say "working towards ISO/IEC 27001 alignment", never "ISO compliant" or "certification-ready", until an accredited certification body has completed the process.

Proposed ISMS scope

The design, development, hosting, operation and support of Viewee's feedback-to-action SaaS for UK adult social care, including founders and contractors, production and non-production environments, marketing site, web application, API, source code and CI/CD, corporate endpoints and identity, customer support, and suppliers that process or can affect customer information.

Record physical and organisational boundaries, exclusions, interfaces and dependencies. Revisit the scope before certification if the architecture, team, offices or services change.

Roadmap

PhaseTimingWork and outputsTypical founder effort
0. MobiliseWeeks 1-2Name ISMS sponsor and owner; approve scope; identify interested parties and legal/contract requirements; set document control and programme rhythm.2-4 days total
1. Understand riskWeeks 2-6Asset and data-flow registers; risk method; first risk register; treatment plan; objectives; initial Statement of Applicability.4-8 days total
2. Close priority gapsMonths 2-5Policies and working controls for identity, suppliers, secure development, vulnerability handling, backups, logging, incidents, continuity, privacy, retention and support access.0.5-1 day/week
3. Operate and evidenceMonths 4-8Run access reviews, scans, restore tests, supplier reviews, incident exercise, metrics, change records, training and risk reviews. Retain evidence of actual use.1-2 days/month plus fixes
4. Check and correctMonths 7-9Internal audit by someone sufficiently objective; founder management review; corrective actions, root causes and effectiveness checks.3-6 founder days plus auditor
5. CertifyMonths 9-12Select UKAS-accredited certification body; Stage 1 readiness/document review; close findings; Stage 2 implementation audit; resolve nonconformities.3-6 founder days plus audit
6. MaintainAfter certificationObjectives, metrics, risk reviews, internal audit, management review, corrective action and certification surveillance.1-2 days/month, with peaks

Risk method and register

  1. Define assets/processes, risk owners and confidentiality, integrity and availability impacts.

  2. Use a simple 1-5 likelihood and 1-5 impact scale. Score inherent risk before controls and residual risk after controls.

  3. Set written acceptance thresholds. Example: 1-4 accept locally; 5-9 owner treatment/acceptance; 10-15 founder approval and dated treatment; 16-25 immediate action or stop the activity. Validate thresholds against customer and legal duties.

  4. Choose treatment: reduce, avoid, transfer or accept. Every treatment needs an owner, due date and evidence.

  5. Review quarterly and after material changes, incidents, new suppliers or customer requirements.

Minimum register fieldsExample evidence
ID, asset/process, threat/event, vulnerability/cause, impact, owner, existing controls, inherent score, treatment, due date, residual score, acceptance, review dateTicket, configuration export, scan, access review, test result, contract, meeting decision

Statement of Applicability

Build the SoA from the risk treatment process and compare selected controls with every Annex A control. For each control record applicability, justification for inclusion or exclusion, implementation status, control owner and evidence link. The SoA is not a copied checklist. It must match Viewee's risks, scope and real operating controls.

Minimum ISMS evidence set

Internal audit and management review

The internal audit must test both conformity and effective operation across the full scope. The auditor must be objective and must not simply approve their own work. A specialist external internal auditor is sensible for a two-person team. Track findings to closure.

After the internal audit, founders should hold a minuted management review covering prior actions, context changes, interested parties, performance and metrics, audit results, objectives, incidents/nonconformities, risk and treatment status, resources, supplier issues and improvement decisions.

Certification stages

StageWhat to expectGo/no-go test
Choose certification bodyCheck the body's live UKAS accreditation and scope for ISO/IEC 27001. Get comparable quotes and audit-day assumptions.Accreditation verified directly with UKAS.
Stage 1Readiness and documented-system review, scope confirmation and planning for Stage 2.ISMS defined; required documents and at least one internal audit and management review complete.
Stage 2Audit of implementation and effectiveness using interviews and records across the scope.Several months of coherent evidence; Stage 1 findings closed.
After certificationSurveillance audits and continual improvement through the certification cycle.ISMS remains active between audits.

Do now versus later

Do nowDo later, when the product is operating
Scope; roles; context; obligations; registers; risk method and first assessment; SoA v0.1; policies tied to how Viewee actually works; supplier due diligence; secure architecture; document control.Accumulate access reviews, tickets, scan/remediation history, backup restores, incident exercise, metrics and review cycles; independent testing; internal audit; management review; certification-body engagement.

The existing Legal-folder compliance pack already identifies the core gaps: no formal scope, risk register, SoA, internal audit, management review or operating-evidence set. Reuse its ISO requirements tracker as the control/evidence index instead of creating a competing checklist.

First 30 days

Sources