What the work covers
- Clause 4 to 10 gap assessment against ISO 27001:2022.
- Annex A control review with the evidence each one needs.
- Statement of Applicability draft with justified exclusions.
- Risk assessment method your team can repeat.
- Internal audit plan and certification body liaison.