Canada-based · ISO 27001:2022 · certification in 3 months

ISO 27001 Certification Service

We build and operate your ISMS, prepare every document an auditor will ask for, and take you through Stage 1 and Stage 2 — on the current 2022 version of the standard. Toronto-based, delivered across Ontario and Canada.
3

Months to the certification audit

93
Annex A controls, scoped to your risk
3 yrs
Certificate cycle, annual surveillance
Canada
Canadian data residency, hosted in-country
The service

ISO 27001 is not a checklist. It is a management system you have to run.

A risk assessment, a Statement of Applicability, internal audits and management reviews that an accredited body will test. Nank.ai builds that system and operates it with you — a named compliance manager owns the certification, supported by AI agents that collect evidence and monitor controls continuously.
Nank.ai does not issue the certificate. Only an accredited certification body can, and it must be independent of the party that built the ISMS. We prepare you, help you select the body, and support both audit stages.
Who it is for

Four situations that bring companies here

Selling into Europe or enterprise

ISO 27001 is the recognised standard outside North America, and increasingly the one procurement asks for alongside or instead of SOC 2.

No ISMS and no one to build it

The management system — not the controls — is where first-time certifications fail. It needs someone who has done it before.

Certified on the 2013 version

The transition deadline passed on 31 October 2025. Certificates against ISO/IEC 27001:2013 are no longer valid.

Holding a certificate already

Surveillance audits, scope changes and the three-year recertification still need running, without absorbing your security team.

The standard

What certification actually requires

Two things, and most projects underestimate the first. Clauses 4–10 are the management system requirements — context, leadership, planning, support, operation, performance evaluation, improvement. None can be excluded. Annex A is a list of 93 controls from which you select based on your risk assessment, and justify every inclusion and exclusion in the Statement of Applicability.

The mistake that costs the most time

Working through Annex A as a checklist before completing the risk assessment. ISO 27001 requires controls to be selected on the basis of risk, and auditors test whether your Statement of Applicability traces back to the risk register. Teams that implement controls first and reverse-engineer the risk assessment end up with controls they never needed and a document set that contradicts itself. We do these in the right order.
The engagement

How it runs, week by week

Weeks 1–2

Scope and gap assessment

We define what the ISMS covers — entities, products, locations, systems and people — because your certificate will state it verbatim and a customer will read it. Scope too narrow and the certificate does not answer the question you were asked; too broad and you are implementing controls across parts of the business that have nothing to do with the product.
Weeks 2–5

Risk assessment and treatment

A defensible risk assessment with a repeatable scoring method, risk owners, and a treatment plan — the document everything else is built on. This is done before we open Annex A, not after.
Weeks 4–8

Statement of Applicability and controls

Every one of the 93 controls recorded as applicable or excluded, with justification traceable to the risk assessment. Then implementation, sized to your risk rather than to the most thorough reading of the guidance. Policies are written against how your company actually operates — auditors notice template policies that describe a company that does not exist.
Weeks 6–11

Evidence, internal audit and management review

AI agents collect evidence continuously from your cloud, identity and ticketing systems. We then run a genuine internal audit — independent of the people who built the ISMS — and a documented management review. An internal audit that raises no findings is itself a finding. Ours will find things, which is what makes Stage 2 uneventful.
Weeks 10–14

Stage 1 and Stage 2 with an accredited body

We help you select a certification body accredited by the Standards Council of Canada or an equivalent IAF member, then support Stage 1 (documentation review) and Stage 2 (testing that the ISMS operates as documented). Your compliance manager handles the auditor relationship and any nonconformities.
Years 2–3

Surveillance and recertification

The certificate runs three years with annual surveillance audits. Monitoring, internal audits and management reviews continue so surveillance is routine rather than an annual scramble.
Deliverables

What you get

Toronto · Ontario · Canada

ISO 27001 certification in Toronto, Ontario and across Canada

Nank.ai is based in Toronto. We deliver ISO 27001 certification programmes for organisations across Ontario and the rest of Canada — in your time zone, under Canadian law, with your evidence held in-country.

That matters more than it sounds. Most compliance vendors selling into Canada are US companies running your evidence through US infrastructure, which is the first question a Canadian enterprise or public-sector buyer will ask about.

Toronto and the GTA

We are here. Workshops, risk assessment sessions and management reviews can be run in person where that moves things faster, and everything else in your working hours.

Ontario and Canada-wide

The same programme runs remotely for clients in Ottawa, Montreal, Calgary, Vancouver and anywhere else in Canada, with a certification body accredited by the Standards Council of Canada.

SOC 2 and ISO 27001 for Canadian buyers

Canadian companies selling into the US and Europe are frequently asked for both. Run together from Toronto, one programme satisfies both requests.

Canadian data residency compliance

ISO 27001 does not itself mandate where data lives — but your customers, your contracts and Canadian privacy law frequently do, and the ISMS is where you prove it. We host your compliance evidence in Canada and design the controls so residency obligations are demonstrable rather than asserted. The regimes that usually drive the requirement:
Choosing

ISO 27001 or SOC 2 — or both

They answer the same customer question in different ways. The control sets overlap heavily — run together, one evidence pipeline and one policy set can serve both. Sequenced separately, you largely pay twice. See our SOC 2 compliance service.

ISO 27001

SOC 2

Frequently asked questions

Three to four months from kick-off to the Stage 2 audit is realistic for a focused scope with reasonable starting maturity. Organisations with no existing controls, complex infrastructure or a broad multi-entity scope should plan for longer. The constraint is usually evidence: controls need to have been operating long enough for an auditor to sample them.
Yes. Nank.ai is based in Toronto and delivers ISO 27001 certification programmes across Ontario and the rest of Canada — Ottawa, Montreal, Calgary, Vancouver and elsewhere. Toronto and GTA clients can have workshops and management reviews run in person; everything else is delivered remotely in your time zone. We help you select a certification body accredited by the Standards Council of Canada or an equivalent IAF member.
Your compliance evidence is hosted in Canada. ISO 27001 does not itself mandate data residency, but Canadian privacy law and customer contracts frequently do — PIPEDA federally, PHIPA for Ontario health information, Quebec Law 25 for transfers outside the province, and the PIPA regimes in Alberta and British Columbia. Public-sector RFPs often require in-country hosting outright. We design the ISMS controls so those obligations are demonstrable to an auditor rather than simply asserted.
No. Only an accredited certification body can issue an ISO 27001 certificate, and it must be independent of the party that built the ISMS. We prepare you, help you select the body, and support both audit stages.
No. You select controls based on your risk assessment and justify exclusions in the Statement of Applicability. Excluding a control is legitimate when nothing in the risk register requires it — what auditors challenge is an exclusion that contradicts your own risk assessment.
The transition period ended on 31 October 2025, so certificates issued against ISO/IEC 27001:2013 are no longer valid. Moving to the 2022 version means remapping to the four themes and 93 controls, addressing the 11 new controls, and updating your Statement of Applicability. We run this as a defined transition rather than a fresh certification.
You need ISO/IEC 27001 itself. ISO/IEC 27002 — the implementation guidance for the Annex A controls — is optional but hard to work without. See ISO 27001 vs ISO 27002 for how the two differ.
Yes. If you already run Vanta, Drata, Secureframe or similar, we can operate inside it. What we add is the expertise and the ownership of the deadline, not another tool.

Talk to a Toronto-based ISO 27001 team

A short call will tell you what your ISMS scope needs to cover, where your real gaps are, and how long certification will realistically take. We will tell you if you would be better served by SOC 2 first.
[EDITOR: insert engagement pricing before publishing. Deliberately left blank rather than invented.]
Scroll to Top