Agile, straightforward, and customized support, regardless of your industry, company size, or level of maturity. We adapt our approach to your specific situation—not the other way around.
.webp)
+ Over 200 companies have already placed their trust in us
ISO/IEC 27001 is the leading international standard for information security management. It defines the requirements for establishing, implementing, maintaining, and continuously improving an Information Security Management System (ISMS).
In its 2022 version, it outlines 93 security measures organized into four categories (organizational, human, physical, and technological) to address all of an organization’s information risks, regardless of its size or industry.
Certification is issued by an accredited body following a two-phase audit. It is valid for three years, with annual surveillance audits to ensure continuous improvement.
Every year, hundreds of companies embark on a certification process only to fail or get bogged down. Here’s why.
Without a structured approach, certification projects drag on for 18 to 24 months, placing a strain on internal teams that are already stretched thin.
ISO 27001 requires dozens of policies, procedures, and supporting documents. Producing relevant documents—rather than just filling space—is a delicate task.
This is the core of the standard. If not implemented properly, it leads to non-conformities during the audit and calls the entire process into question.
The standard covers governance, HR, IT, suppliers, and more… Coordinating all business units without the necessary expertise is an ongoing challenge.
Between the certification body, service providers, and internal time, the budget can quickly spiral out of control. Without an initial framework, surprises are inevitable.
Obtaining the certificate is just the beginning. Annual surveillance audits and continuous improvement require ongoing management of the ISMS.
Our program leads you to certification in less than 6 months, with personalized support at every stage.
Talk to an expert →Whether you're starting from scratch or looking to accelerate an existing initiative, we offer the format that best suits your organization.
Take controlof your certification. At yourown pace.
Access our GRC platform and a comprehensive ISO 27001 playbook to independently structure your ISMS. The tool provides the framework; you stay in control.
An expert by your side. No blind spots.
Take advantage of a structured support program that combines consulting, training, and auditing to help you move faster, avoid critical mistakes, and feel confident on the day of your certification audit.
Leave it all to us. Get certified.
We manage every step of your ISO 27001 project: from the initial scoping to obtaining your certificate. Your team can stay focused on its core business.
Each step is clearly defined, documented, and monitored using specific metrics. You always know where you stand.
Assessment of your current readiness, definition of the ISMS scope, and documentation of Chapter 4 of the standard. You’ll leave with a personalized and realistic roadmap.
Risk analysis to determine system sizing, drafting of security policies, and definition of the 93 applicable controls. Each deliverable complies with the standard’s requirements.
Implementing controls, training teams, and managing the system. You demonstrate how the ISMS actually works.
Simulation of the full audit, correction of non-conformities, management review, followed by support during both phases of the audit conducted by the accredited certification body.
In addition to ISO 27001, we cover all information security certifications
Here’s what those who have experienced the program firsthand have to say.
"
We had very good support. Our quality system was very well studied by the project manager, which made the whole project easier."

Stefano FIORENTINI - CTO
"
Feel Agile has great process knowledge, a project plan with an efficient tempo and existing documentation material to save time."
.webp)
Mickaël KLAUS
"
Thanks to Feel Agile, we were able to obtain ISO 27001 certification without a single non-conformity, which is a rare achievement."

Julien Cassagnabère -RSSI
All you need to know about ISO 27001
ISO 27001 is intended for all organizations, regardless of their size or industry: microbusinesses, small and medium-sized enterprises (SMEs), mid-sized companies, large corporations, and government agencies. It is particularly relevant for technology companies, service providers, healthcare and financial institutions, and any supplier that handles sensitive customer data.
An ISO 27001 certification can be broken down into different phases (estimates are given for a company with around twenty employees and a less complex product or organization).
Thecost of certification itself (certifying body): Over each 3-year period, the cost of the various certifier interventions (initial, surveillance, and renewal audits) is €10-15k. (As a reminder, the cycle of any ISO certification is 3 years)
Thecost linked to the time spent on implementation:This is the hourly cost of personnel dedicated to the implementation of the ISMS. During the important phases at the beginning of the project (2 months) and at the end of the project (2 months), the work of upgrading skills represents between 1 and 2 man-days per week. In the project monitoring and coordination phases, the project manager's workload amounts to 1 man-day per week. You can choose to be more moderately involved by delegating a large part of the work to the project manager. With a consultant who acts as project manager and consultant/trainer.
Cost ofISO project managering and training: The cost of ISO 27001 certification necessarily varies according to the size of the company: it could double for a company of 150 people, compared with an SME of 10 people. It also varies according to the scope chosen and the tasks entrusted to the consultant (training, consultancy, mock audit, formalization of procedures, etc.) For a 20-strong SME, the cost can therefore range from €25k to €45k. The average cost is around €30k.
The time needed to prepare for ISO 27001 certification depends on several key factors.
Firstly, it varies according to the organization's information security maturity. If the organization has already put in place security processes or practices similar to ISO 27001 requirements, preparation will be quicker. On the other hand, if the organization is starting from scratch, it will take longer, as both technical and organizational measures will need to be put in place, such as security policies, staff training and the definition of appropriate processes.
Secondly, the complexity of the ISMS plays an important role. The scope of the ISMS, the size of the company, and the number of sites or entities to be included in the information security management system will have a direct influence on the preparation time. The broader the scope or the more complex the company, the longer and more detailed the preparation process will be.
As a general rule, preparation for ISO 27001 certification can take between 6 months and 1 year, but this will depend on the specific situation of each organization.
The ISMS (Information Security Management System) is the core framework required by ISO 27001. It encompasses the processes, security policies, governance structures, metrics, and tools needed to manage information-related risks on an ongoing basis. It covers technical, organizational, human, and physical aspects.
No. ISO 27001 certification is valid for three years, with mandatory annual surveillance audits. At the end of the three-year period, a renewal audit is conducted. This cycle ensures continuous improvement and maintains the value of the certification over time. FeelAgile offers ongoing support to help you prepare for each milestone with confidence.
An ISMS management tool allows you to centralize documentation,automate risk and action tracking, facilitate internal audits, and monitor performance metrics. Without a dedicated tool, compliance relies on scattered files that are difficult to maintain. Our platform Oversecur is designed specifically to simplify this management process and reduce your team’s administrative burden.
Yes, they complement each other very well. ISO 27001 provides the operational framework (risk management, access control, encryption, incident response, etc.) that meets many of the GDPR’s technical requirements. ISO 27001 certification does not replace GDPR compliance, but it significantly accelerates the process and demonstrates to authorities a structured and documented approach to personal data security.
The mock audit is a preparation for the certifier's audit.
This audit is a training exercise that takes place under similar conditions, and enables us to verify the company's degree of preparation in terms of information security.
Obtaining ISO 27001 certification is an obvious goal for any company committed to continuous improvement in information security.
During the mock audit, the external viewpoint of the auditor is uncompromisingly focused on the issues at stake. During the audit, teams are prepared to meet the potential demands of the certifier. This examination, which takes place in real-life situations but is not sanctioned, verifies the effective implementation of the ISMS, identifies any shortcomings and ensures that the certification audit runs smoothly.
Depending on the ISO scope and the type of company, the audit can be carried out in 2 to 5 days. What's more, this audit helps to meet some of the internal audit requirements of ISO 27001. We can audit your information systems for you
The most important thing is to choose a certification body accredited by COFRAC (the French Accreditation Committee).
This accreditation guarantees the certifier's competence to assess your ISO 27001 project.
Other criteria are also important:
- the certifier's experience with the ISO 27000 family of standards
- the certifier'sreputation in your market (France? international?)
- the ability to handle several certifications, if you are in the process of ISO 9001 or other.
Finally, it's essential to choose a certifier who really listens to your needs and is prepared to take account of your choices (field of application, measures chosen, corporate culture...), rather than imposing a rigid framework ill-suited to your particular case.
The certifier body must listen, but cannot assist you in your approach. It cannot be judge and jury.
It is quite possible to embark on an ISO 27001 implementation by scrupulously following the standard, without actually carrying out an audit to obtain the certificate.
A priori, this approach would bring the same benefits in terms of process structuring and information protection.
However, it is by submitting your ISMS to the scrutiny of an independent auditor that you will make the most lucid assessment of your degree of control over information-related risks.
What's more, the absence of certification is no way of gaining the trust of customers and prospects.
Certification is therefore the logical culmination of the process, and the reward for your efforts in information management.
Finally, you must never forget that the system you have put in place is designed to better satisfy your customers, and not to please the Security Manager.
ISO 27001 project managering is quite complex. To maintain your initial motivation and obtain certification efficiently, you need to call on the services of an experienced project manager.
A committed project manager knows how to use his or her experience to :
- Explain and advise through all the stages
- Train teams with a realistic sense of management
- Provide proven and adaptable document templates
- Formalize documents
- Prepare for the certification audit
- Integrate the ISMS into the company for sustainable adoption of ISO 27001
The assistance of a project manager is therefore a guarantee of success in building a useful and pragmatic management system.
Want to go further with our articles on ISO 27001?
Do you have any questions? Would you like a quote for certification or support?