We are a team that runs ISO 27001 audits, writes ISMS concepts, advises other companies and regularly explains how information security is done „properly“. And now we have had ourselves certified.
„Suddenly we were no longer the engineer – we were the building being tested for stability.“
The beginning: the moment of decision
We knew: if we want to stay credible, we have to be certified ourselves. Not because we had to. But because we want to lead by example. Because it is not enough to talk the talk – you also have to walk the walk.
So in the spring we made the decision: we would build our own ISMS and get certified – not just „somehow“, but to a DAkkS-accredited standard.
The reality: auditors don’t enjoy auditing themselves
And then the self-experiment began. We, who normally stand behind the checklists and risk matrices, suddenly sat in the meeting asking ourselves:
- „How do we document this process in a way that makes sense?“
- „Why do we actually do it this way?“
- „Is this enough for the auditor?“
- „Or is it too little… or too much?“
Spoiler: our biggest opponent was not the technology. It was our own standards.
The challenges: the processes you overlook every day – and that decide your audit
Our most important insights came from exactly those places where processes had long been taken for granted:
- Onboarding of new team members that assumes knowledge but secures nothing
- Risk analyses for tools that have „grown organically“
- Regular communication that was never documented because „it has always worked“
After our own audit we know: process maturity does not show in complexity. It shows in whether a process is workable in daily business – and actually lived.
That is why we integrated all policies and processes for our daily work into our WIKI. We even moved the external publication of our policies directly into the WIKI.

This does not only avoid the effort of jumping between different worlds (SharePoint, Google Drive, Confluence, etc.) – it also increases how much our people actually engage with it.
What we deliberately excluded
Not everything that is possible in ISO 27001 has to be inside your scope. Every company has to decide that for itself, based on its processes, activities and risks. That is why we deliberately left some controls out of scope:
- 🔒 Physical security – as a remote-first company, we excluded several of the physical controls.
- 💻 Software development – since we do not develop software, we removed the technical controls for software development from the scope.
We work transparently – so it was important to us to also tell you what we did not include. Because clarity matters, especially in audits.

That was our path – from the GAP analysis to the certificate.
Six months later: the certificate in our hands
After six months of intensive work, many discussions, new routines and a few mistakes along the way (yes, those happened too), we can say with pride:
✅ We are ISO 27001 certified – DAkkS-accredited.

And a certificate is not a one-off event: in June 2026 we also passed our first surveillance audit – the best proof that our ISMS does not just exist on paper, but works in everyday business.
The certificate does not just hang on the wall – it changes the way we work. Because now we too remember what it is like to fight your way through policies, to weigh documentation against productivity – and to ask yourself: „Why exactly are we doing this again?“
For trust. For clarity. For sustainable security.
Our learning: every serious consultant should be certified
When you are looking for an information security consultancy, please do not only ask: „How many clients have you supported?“ Ask as well: „How do you live information security yourselves?“
Because information security is not theory. It is a daily, sometimes tedious, but extremely effective process. And believe me: the certificate on the wall is only the symbol. The real value lies in the resilience of the organisation.
🔐 Certification is not an end in itself.
🔍 It forces you to take an honest look.
💡 And that is a good thing.
We now know even better how information security feels in practice – and we pass that experience on to our clients in our ISO 27001 consulting.
PS: If you are considering an ISO 27001 certification yourself – we know exactly how that feels. Talk to us: no buzzwords, no PowerPoint battles. 👉 We would rather talk about what actually works.
Want to start on your own first? Our ISO 27001 checklist gives you an overview of the most important steps.
About the Author

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX® consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.
