Advisory & Conformity Assessment
Independent assessment against ISO guidelines
For ISO guideline standards and frameworks that are not certifiable management-system standards, we assess your alignment against the guideline and report our findings plainly.
What this service is — and isn't
Documents such as ISO/IEC 27002 and ISO 31000 are guidelines and codes of practice, not certifiable management-system standards. Formal accredited certification is not available or applicable for them. What we offer instead is a conformity assessment: we review your organization against the relevant guideline and report our findings.
This is clearly distinct from accredited management-system certification. Nothing on this page, or in any report we issue under it, should be read as an accredited certification — see Accreditation & Recognition for exactly what CCI's accreditation does and doesn't cover.
CCI does not provide management-system consultancy, documentation drafting or implementation support. Engaging ISOXPERT Management & IT Consultants — an independent consulting and technology firm under common ownership with CCI — any other consultant, or no consultant has no bearing on any certification decision, and equally no bearing on the outcome of any assessment we issue.
What you receive
A detailed assessment report against the relevant guideline and, where appropriate, a statement of conformity valid for one year — clearly identified as a conformity assessment, never as accredited management-system certification.
Guidelines and frameworks we assess against
Information Security & Privacy
ISO/IEC 27002, 27005, 27017, 27018, 27032, 27035, 27036, 27037, 27040, 27050, 29100, 29134
IT Governance, AI & Continuity
ISO/IEC 90003, ISO/IEC TR 38502, ISO/IEC TR 24028, ISO/IEC 24762
Risk, Resilience & Business Continuity
ISO 31000, ISO 22320, ISO 22313, ISO 45003
Sustainability & Responsible Business
ISO 20400, ISO 26000
Governance, Relationships & Auditing
ISO 19011, ISO 44001
Quality, Projects, Assets & Energy
ISO 10002, ISO 21502, ISO 50004, ISO 55002
Agriculture
Independent Organic Practice Assessment
Where a certifiable, accredited management-system standard exists alongside one of these guidelines — such as ISO/IEC 27001 for information security, or ISO 22301 for business continuity — organizations that want a certificate rather than an assessment report should look there instead.
Not sure which service fits?
Request a scoping discussion and we'll tell you plainly whether it's a conformity assessment or an accredited certification you need.
