🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
ISO 27001CR-ISO-02

ISMS Scope & Policy Document Pack

ISO 27001 foundation documents: ISMS scope, security policy, roles matrix, interested parties. First documents auditors request. Stage 1 ready. €449.

ISMS Scope & Policy Document Pack by Optimum Web is a fixed-price compliance service covering ISO 27001 Clauses 4-5 — Context and Leadership. It costs €449 with 7–10 business days delivery by senior security engineers. ISMS Scope document (locations, systems, processes, data in scope). 14-day warranty included.

€449
Fixed price, VAT excluded
7–10 business daysSenior only
ISMS Scope document (locations, systems, processes, data in scope)
Information Security Policy (ready for top management signature)
Roles and responsibilities matrix for ISMS
Interested parties analysis + internal/external issues assessment
🛡️
14-Day Warranty
If the delivered pack does not match your ISMS scope and Statement of Applicability, we rework it at no cost, or refund in full within 14 days of delivery.

Secured by PayPal · 256-bit SSL encryption

or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-ISO-02

This Service Covers

ISO 27001Clauses 4.1-4.4, 5.1-5.3 — Context, scope, leadership, policy

What You Get

Foundation documents required for ISO 27001 ISMS (Information Security Management System): ISMS Scope document (defining boundaries — which locations, systems, processes, and data are in scope), Information Security Policy (signed by top management), roles and responsibilities matrix, interested parties analysis, and internal/external issues assessment. These are the first documents auditors request at Stage 1 — without them, the audit cannot proceed.

Optimum Web provides audit preparation, documentation and technical verification. We are not a certification body, we do not employ auditors, and we do not perform internal or certification audits. The Clause 9.2 internal audit is conducted by a person independent of the area audited within your organisation, or by an auditor you appoint; the certification audit is conducted by an accredited certification body. Our role is to make sure you are ready for both.

Who Needs This

  • Companies starting ISO 27001 certification from scratch
  • Organizations that completed the readiness assessment and need to begin documentation
  • Businesses whose Stage 1 auditor requested ISMS scope and policy documents
  • Companies with informal security practices needing formal ISMS documentation

How It Works

  1. 1
    Workshops

    2-3 workshops with management to define scope, roles, and context

  2. 2
    Scope Definition

    Document ISMS boundaries: systems, locations, processes, data

  3. 3
    Policy Drafting

    Create Information Security Policy aligned with management's vision

  4. 4
    Delivery

    Complete document pack ready for management review and approval

ONGOING COMPLIANCE

Don't Want to Think About Compliance Every Quarter?

Compliance-as-a-Service: €729/month. Quarterly reviews, scans, documentation, and security questionnaire support — as an extension of your team, not a replacement for your compliance owner.

Start CaaS — €729/month

Ready to Start?

€449 · 7–10 business days · 14-day warranty

Secured by PayPal · 256-bit SSL encryption

or order without payment

Want ongoing compliance? Compliance-as-a-Service — €729/month

Learn more

Frequently Asked Questions

What should be in scope for ISO 27001?+
Start narrow: your core business processes and the IT systems supporting them. We recommend excluding non-critical parts initially (e.g., marketing systems) to reduce scope and certification cost. You can expand later.
Does the security policy need CEO/board signature?+
Yes. ISO 27001 Clause 5.2 requires top management commitment demonstrated by signing the Information Security Policy. We prepare the document; your leadership reviews and signs.
Can we use these documents for NIS2 compliance?+
Some overlap: the Information Security Policy satisfies NIS2 Article 21(2)(a). The ISMS scope and roles are ISO-specific. For NIS2-specific documents, see CR-NIS2-03.
How detailed should the scope be?+
Enough for an auditor to understand exactly what is and isn't covered. We specify: physical locations, IT systems, business processes, data types, and organizational units. Excluded areas are documented with justification.
Is this the same as the Information Security Policy from CR-NIS2-03?+
Similar but different focus. CR-NIS2-03 includes risk analysis and NIS2-specific policy content. This pack focuses on ISMS establishment documents (scope, context, interested parties) required for ISO 27001 Stage 1.

Service page last reviewed 15 August 2026 by the Optimum Web compliance team.

Secured by PayPal · 256-bit SSL encryption

or order without payment