CASE STUDY

Regional managed services provider achieving ISO 27001 certification with Armour Cyber

ISO 27001 Certification for a Regional Managed Services Provider


Background

A well-established managed services provider in Austin, Texas had been serving corporate clients across Texas and neighboring markets for over a decade. Their services included cloud infrastructure management, helpdesk support, network administration, and IT consulting for clients in banking, retail, and government-adjacent sectors.

As their client base grew to include larger organizations with more formal procurement requirements, they began encountering a consistent barrier: ISO 27001 certification. International clients, multinational companies operating in Peru, and public sector prospects were all requiring ISO 27001 as a baseline vendor qualification. Without it, the MSP was being disqualified from opportunities their technical capabilities fully qualified them for.

Leadership made the decision to pursue ISO 27001:2022, the most recent revision of the standard, and recognized that doing it correctly would require external expertise. ISO 27001 is not a checklist. It is a comprehensive information security management system (ISMS) that must be designed, implemented, operated, and continually improved. Getting it wrong would mean a failed audit, wasted investment, and continued exclusion from the contracts they were trying to win.


Challenge

ISO 27001:2022 requires organizations to establish, implement, maintain, and continually improve a formal ISMS, a structured system of policies, processes, technical controls, risk management procedures, and governance mechanisms designed to protect information assets systematically.

For this MSP, the challenge was layered. As a technology services company, they had strong technical capabilities, but technical competence and compliance documentation are fundamentally different disciplines. Their engineers knew how to secure systems. They didn’t know how to document a Statement of Applicability, conduct a formal ISO-compliant risk assessment, define the ISMS scope, establish a management review process, or structure the internal audit program that ISO 27001 requires before any external certification audit can occur.

Additionally, as an MSP, their information security perimeter extended beyond their own offices, they had to account for client environments, third-party tools, remote staff across multiple locations, and the complex web of data flows that their service delivery model created. Defining the ISMS scope alone required weeks of careful analysis.

The company had previously attempted to begin the ISO 27001 process independently, purchasing a template framework online. Eighteen months later, the templates were partially filled in, nothing had been formally adopted, and the certification goal remained as distant as when they started.


Action

Armour’s compliance team began with a structured ISO 27001 gap assessment, evaluating the company’s current information security practices, documentation, and technical controls against all requirements of the ISO 27001:2022 standard and its Annex A controls.

The gap assessment identified three categories of work required: governance and documentation gaps, technical control gaps, and process gaps. A six-month project plan was built around these three workstreams, with clear milestones, ownership assignments, and evidence requirements at each stage.

Key work delivered across the engagement included:

  • ISMS Scope Definition: Worked with leadership to formally define the ISMS scope, covering the MSP’s core service delivery operations, physical locations, key assets, and relevant interfaces with client environments, creating a scope document that was defensible, practical, and appropriately bounded for a first certification.
  • Risk Assessment & Treatment: Conducted a full ISO-compliant information security risk assessment, identifying, analyzing, and evaluating risks across the organization’s information assets, then developing a formal Risk Treatment Plan documenting how each identified risk would be addressed, accepted, transferred, or avoided.
  • Statement of Applicability (SoA): Developed the formal SoA, one of the most critical ISO 27001 documents, mapping all 93 Annex A controls from the 2022 standard to the organization’s environment, documenting which controls were applicable, which were excluded, and the justification for each decision.
  • Policy & Procedure Development: Built a complete ISMS documentation set including the Information Security Policy, Acceptable Use Policy, Access Control Policy, Supplier Security Policy, Incident Management Procedure, Business Continuity Plan, and 16 additional supporting documents.
  • Internal Audit Program: Designed and executed the mandatory internal audit program, conducting internal audits across all ISMS processes and documenting findings, corrective actions, and evidence of management review, all required before the external certification audit.
  • Technical Control Remediation: Implemented required technical controls including asset inventory management, privileged access reviews, network segmentation improvements, and a formal vulnerability management program.
  • Stage 1 & Stage 2 Audit Support: Managed the entire external certification audit process, a two-stage process in which the certification body first reviews documentation (Stage 1) and then conducts on-site assessment of ISMS implementation (Stage 2). Armour coordinated all evidence submission, prepared staff for auditor interviews, and managed all corrective action responses in real time during the audit.

Impact

  • ISO 27001:2022 certification achieved, first attempt, zero major nonconformities
  • 2 minor nonconformities identified during Stage 2 audit, both resolved and closed within the audit window
  • Full ISMS documentation suite 22 policies and procedures developed and formally adopted
  • 93 Annex A controls assessed, documented, and implemented or formally justified as excluded
  • 3 previously stalled enterprise contracts progressed to signing within 60 days of certification
  • Annual surveillance audit readiness program established, ongoing Armour support ensures certification is maintained
  • Staff across all departments trained on ISMS responsibilities and ISO 27001 awareness

Conclusion

ISO 27001 is not a project with an end date, it is an ongoing commitment to managing information security as a business discipline. The MSP that earned this certification didn’t just unlock new contracts. They built an information security management system that makes them a fundamentally more resilient, more trustworthy, and more competitive organization.

The eighteen months they spent trying to do it alone produced nothing. The six months they spent with Armour produced a certification, a functioning ISMS, and a pipeline of contracts that had previously been inaccessible. The math speaks for itself.