03 · ISO Readiness

Told to get certified? This is the route.

When a customer, a market, or your own risk position requires a certified management system, the route is the same every time: gap assessment, build, evidence, certification audit. We run that route for any ISO management system standard, self guided or guided, and we never do the certifying.

Gap assessment through build to the certification audit
Certification performed independently by an external certification provider
The work

One route, any standard

The three below are the ones customers ask for most; if your requirement names a different ISO management system standard, the same route applies. Every engagement is scoped to the standard, the certification goal, and the size of the organization, so pricing follows a scoping conversation rather than a page.

Information security

Management system gap assessment through full build to the certification audit, for organizations whose customers or markets require certified information security. The privacy extension is available where personal information is in scope.

Business continuity & disaster recovery

Continuity management readiness: business continuity planning, ICT disaster recovery, exercising, and the evidence that the plans work, built to a certifiable standard.

AI management systems

Readiness for organizations formalizing AI governance to a certifiable standard, from inventory and risk assessment through operating controls and records.

Independence: ascio provides readiness and implementation support. Certification, where required, is performed independently by an external certification provider.
How the engagement runs

Six steps, scope to certificate

The same sequence in both delivery modes. Self guided, your team runs it with ascio reviewing at fixed points; guided, ascio runs it with you. Every stage produces an artifact you keep.

  1. Scope

    The smallest defensible boundary of systems, people, and locations. Scope is the main cost lever, and we defend it.

  2. Gap assessment

    Against the standard you are pursuing, producing a register and a sequenced plan.

  3. Build

    Policies, controls, and operating rhythm. Your team implements; we design, support, and verify.

  4. Evidence

    A record behind every control, assembled as the work happens rather than reconstructed before the audit.

  5. Internal audit and review

    Prove the system operates, not just exists, before anyone external looks at it.

  6. Certification audit support

    Enter the assessment prepared, with nothing improvised, and a plan for the findings that come back.

Afterwards

Ongoing support

Most clients keep us on after the initial work. The Assurance Desk maintains your evidence, manages your renewal dates, and handles new questionnaires as they arrive. Starting from $495 CAD per month.

Questions

Asked often

Why is there no pricing on this page?

Every engagement depends on the standard, the goal, and the size of your organization, so we price after a short scoping call. The quote you get is the price you pay.

Can ascio certify us?

No. Certification audits are always done by an independent certification body. We prepare you to pass them.

We already hold one certification. Does that shorten the next one?

Usually, yes. Much of the work carries over between standards, and we check what you already have before building anything new.

A customer set a certification deadline?

A scoping conversation tells you the size of the work, the realistic timeline, and the price. Twenty minutes, no obligation.