Most companies engage ISO 27001 and GDPR consultancy in order to pass an audit. That is the trap. Certification is the by-product — the real goal is to have a management system that survives the day after the audit. And the day after is increasingly dangerous: CERT.PT recorded 2,758 cybersecurity incidents in Portugal in 2024, a 36% increase compared with 2023, with around 78% occurring in private entities (CNCS, 2024). Passing the audit is not the same as being protected. This guide gives you a concrete method to assess, engage and monitor certified consultancy, with a 16-point checklist you can take to tomorrow's meeting.

What you need before you start

Before speaking to any consultant, consolidate these eight points internally. Without them, the diagnosis will cost more and take longer — and the consultant will charge you for time that should have been yours.

  • Up-to-date inventory of systems: ERP, MES, servers, cloud, industrial terminals.
  • Map of personal data processed — employees, customers, suppliers.
  • Organisation chart with those responsible for IT, operations and compliance.
  • Service provision contracts with data access clauses (GDPR processors).
  • Log of security incidents over the last 24 months, even if informal.
  • Documented backup policy — or its absence, acknowledged in writing.
  • Definition of scope: full or partial certification (e.g. only the datacentre, only the ERP).
  • Indicative budget approved by top management — without this, the roadmap does not move forward.

Step 1 — Define the scope before requesting proposals

The most expensive mistake we see in ISO 27001 consultancy projects is requesting proposals without a defined scope. The consultant quotes for the minimum; the company assumes the maximum. The result is an addendum halfway through the project — and an unpleasant discussion about who should have said what.

Think in three dimensions. First, the systems in scope: which information assets are critical to the business? The MULTI ERP that manages production and invoicing is always in. The HR file server, almost always. The sales rep's tablet, it depends. Second, the processes in scope: production, sales, HR, finance — or only those that process sensitive personal data? Third, the locations: head office, branches, remote warehouses, teleworking.

Document the scope on a single A4 page. That document is the first deliverable of the project — not the last. Presenting it to the certification body before the stage 1 audit avoids surprises that cost time and money.

  • ☐ Scope approved by top management in writing.
  • ☐ Assets out of scope explicitly excluded and justified.
  • ☐ Scope communicated to the certification body before the stage 1 audit.

Step 2 — Assess the consultant against the right criteria

There is one operational detail the manuals do not mention: in Portugal, most ISO 27001 consultants have experience in banking and insurance. Manufacturing industry — textiles, footwear, metal — has specificities that a financial services consultant does not master. Industrial terminals connected to the production network, real-time WIP in real time, SCADA systems, integrations between ERP and shop floor: all of this expands the attack surface in ways that a generic checklist does not capture. A garment factory with 120 employees in Famalicão has production terminals communicating with the ERP in real time. That data flow rarely appears in a threat model designed for an accounting office.

Demand this evidence before signing:

  • ISO 27001 lead auditor certification (IRCA or equivalent) — of the consultant, not the company.
  • At least two completed projects in industrial companies with a production scope.
  • Documented risk analysis methodology — ask for the template, not the description.
  • A reference from a DPO (Data Protection Officer) they have worked with in an industrial GDPR context.
  • Clarity on who does what: the consultant drafts policies, the company approves and implements them.
  • ☐ Lead auditor's CV verified.
  • ☐ Industrial references contacted (not merely listed).
  • ☐ Risk analysis template received and assessed internally.

Step 3 — Structure the project in phases with verifiable deliverables

A well-run ISO 27001 + GDPR project has four phases. Each ends with a deliverable that your team can read and validate — not just the consultant. If only the consultant can interpret what was produced, the knowledge has not stayed in the company.

  1. Assessment (weeks 1-4): asset inventory, gap analysis against Annex A of ISO 27001 and against GDPR. Deliverable: gap analysis report with priorities.
  2. Design (weeks 5-10): security policy, risk analysis, treatment plan, records of processing activities (GDPR Art. 30). Deliverable: documented ISMS version 1.0.
  3. Implementation (weeks 11-20): technical and organisational controls, training, testing. Deliverable: implementation evidence per control.
  4. Internal audit + management review (weeks 21-24): simulation of the certification audit. Deliverable: internal audit report and review minutes.

Twenty-four weeks is the realistic minimum for an industrial SME starting from scratch. Be wary of proposals promising certification in 12 weeks without a pre-existing management system. What you get in 12 weeks is documentation — not a system that works.

  • ☐ Timeline with dates and responsible persons defined per phase.
  • ☐ Deliverables contracted — not merely described in the proposal.
  • ☐ Internal checkpoint after each phase before moving forward.

16-point checklist — take it to the meeting

# Checkpoint ISO 27001 GDPR Status
1 ISMS scope documented and approved
2 Complete inventory of information assets
3 Risk analysis with documented methodology
4 Risk treatment plan approved by management
5 Records of processing activities (GDPR Art. 30)
6 Legal basis identified for each data processing operation
7 Contracts with GDPR processors (Art. 28) signed
8 Information security policy published internally
9 Incident management procedure documented
10 Breach notification deadline to CNPD (72h) known by the team
11 Access controls reviewed (principle of least privilege)
12 Backup policy tested in the last 6 months
13 Awareness training carried out and recorded
14 Internal audit carried out by an auditor independent of the area audited
15 Management review with documented minutes
16 Alignment with NIS2 verified (if company in a critical sector)

Step 4 — Integrate GDPR and ISO 27001 instead of treating them separately

Treating ISO 27001 and GDPR as two parallel projects duplicates the effort and creates contradictions between documents. The standard's risk analysis and the regulation's data protection impact assessment (DPIA) share 80% of the inputs — use the same assets, the same threats, the same measures.

In practice, the records of processing activities (GDPR Art. 30) feed the ISMS asset inventory. The ISO 27001 risk analysis supports the DPIA when the processing is high-risk. The Annex A controls of the standard implement the technical and organisational measures required by Art. 32 of the GDPR. A consultant who does not show you this overlap map is charging you for duplicated work — and creating two sets of documents that will diverge at the first update.

There is a specific mistake we see repeatedly in industrial companies: the IT manager runs the ISMS and the HR manager runs GDPR, with no formal coordination. The result is that the records of processing activities list the time-and-attendance system as an asset, but the ISMS risk analysis does not include it in scope. The auditor finds the contradiction. The company pays for the non-conformity.

  • ☐ ISO 27001 ↔ GDPR overlap map delivered by the consultant.
  • ☐ Documentation shared between the two systems (not duplicated).
  • ☐ Single person responsible for coordinating the two processes internally.

Step 5 — Monitor after certification

ISO 27001 certification does not immunise anyone. What immunises is the continuous improvement cycle the standard requires — and which most companies abandon in the six months following the certification audit, once the consultant has left and the adrenaline has subsided.

The Verizon Data Breach Investigations Report 2025 is unequivocal: in small and medium-sized enterprises, ransomware was present in 88% of the data breaches analysed, against 39% in large organisations. SMEs are the disproportionate target — precisely because certification tends to be treated as a one-off event rather than a continuous process. Having the certificate on the wall does not replace the monitoring cycle.

Define three minimum monitoring metrics and assign someone responsible for each. Number of open non-conformities: target of zero left unresolved for more than 30 days. Average incident response time: below the threshold defined in the internal procedure, reviewed annually. Annual training coverage: 100% of employees with access to systems in scope — not just IT staff, but also industrial terminal operators and sales reps with access to KORA Sales Suite on their mobile devices.

Review these metrics at the management review meeting. The standard requires at least once a year; companies with a history of incidents should do so quarterly. Managed cybersecurity can support this cycle when the internal team lacks the capacity to maintain it alone — the global shortfall of cybersecurity professionals reached around 4.76 million people in 2024, a 19% increase compared with 2023 (ISC2, 2024), and Portugal is no exception.

  • ☐ Security metrics dashboard defined and assigned to a responsible person.
  • ☐ Internal audit calendar for the next 12 months.
  • ☐ Change management process active — any new system enters the scope before going into production.

Common mistakes and how to avoid them

Delegating everything to the consultant without transferring knowledge. The consultant leaves; the documents remain; no one can explain them to the auditor. Demand knowledge transfer sessions at each phase. The internal lead should be able to present the risk analysis without external support — if they cannot, the project has failed regardless of the certificate issued.

Treating training as a formality. Awareness training recorded on an attendance sheet is not the same as training that changes behaviour. A distribution company with 40 warehouse employees needs a simulated phishing exercise, not a 20-slide presentation on password policy. The auditor will ask the warehouse operator what they do when they receive a suspicious email. Prepare them to answer.

Ignoring NIS2 because you do not recognise yourself as being in a critical sector. The NIS2 Directive (Directive EU 2022/2555, transposed in Portugal by Decree-Law No. 65/2025) extends cybersecurity obligations to medium and large companies across 18 critical sectors, including manufacturing industry. Many Portuguese industrial SMEs have not yet assessed whether they are covered. A plastic injection company supplying components for the automotive chain may be in scope without knowing it. Check before CNCS notifies you.

Not managing scope changes. The company implements a new WMS module, integrates an e-commerce platform or opens a remote warehouse — and no one updates the ISMS scope. At the renewal audit, the auditor finds systems in production outside the documented scope. The non-conformity is major. The change management process must include an ISMS scope check before any new system goes into production.

The certification that lasts is the one the company can maintain without the consultant. That is the criterion that distinguishes a well-done project from a project that passed the audit.

Frequently asked questions

What is the difference between passing an ISO 27001 audit and having a genuinely functional management system?

Passing the audit is a one-off moment; a functional system is continuous. Certification validates compliance on a specific day. The real goal is to have controls that work after the audit, when real incidents arise. In Portugal, CERT.PT recorded 2,758 incidents in 2024 — real protection is measured by response capability, not by the certificate on the wall.

Do I need external consultancy or can I do ISO 27001 with my internal team?

It depends on internal maturity. If you have an IT manager with security experience and available time, you can reduce costs with partial consultancy. But the risk analysis, the security policy and the internal audit require distance — an external eye catches gaps that the internal team normalises. The ideal is consultancy for design and internal audit; implementation can be mostly internal.

How long does it really take to implement ISO 27001 in an SME?

The realistic minimum is 24 weeks from scratch: 4 weeks of assessment, 6 of design, 10 of implementation, 4 of internal audit. Be wary of proposals promising certification in 12 weeks without a pre-existing system. What you get in 12 weeks is documentation — not an operational system that survives the day after.

What is the difference between a banking ISO 27001 consultant and a manufacturing industry one?

Enormous. Most Portuguese consultants have experience in financial services. Manufacturing industry has specificities: production terminals connected to the network, real-time WIP, SCADA systems, ERP-shop floor integrations. A threat model designed for an accounting office does not capture these risks. Demand proven industrial references before engaging.

What is a "gap analysis" and why is it important before starting?

It is the comparison between your current state and the requirements of ISO 27001 (Annex A) and GDPR. It identifies what exists, what is missing and what the priority is. Without a gap analysis, the consultant works blind and the project becomes more expensive. It is the first real deliverable — it should be read and validated internally, not just by the consultant.

Do I need a DPO (Data Protection Officer) to implement ISO 27001?

It is not mandatory under ISO 27001, but it is under GDPR if you process personal data on a large scale. If you engage consultancy, the DPO can be external. The important thing is to have someone who understands GDPR accompanying the project — information security and privacy go hand in hand, not in parallel. Ask the consultant for a reference from a DPO they have worked with.

How do I define the certification scope without leaving critical systems out?

Think in three dimensions: systems (ERP, servers, cloud), processes (production, sales, HR) and locations (head office, branches, teleworking). Document what is in and what is out on a single A4 page — with justification. Present it to the certification body before the stage 1 audit. A clear scope avoids expensive surprises halfway through the project and unpleasant discussions about responsibilities.

Sources

  • CNCS (National Cybersecurity Centre) — Report on Cybersecurity Incidents in Portugal 2024, available at https://www.cncs.gov.pt/
  • ISO/IEC 27001:2022 — International standard for information security management systems
  • Regulation (EU) 2016/679 (GDPR) — Article 30 (Records of processing activities) and general provisions on the protection of personal data
  • IRCA (International Register of Certificated Auditors) — ISO 27001 lead auditor certification scheme, available at https://www.irca.org/
  • CNPD (National Data Protection Commission) — Guidance on Data Protection Officers and GDPR compliance in an industrial context, available at https://www.cnpd.pt/