Live 4-week Bootcamp

Master ISO 27001, get certified, and become the person your company trusts with the audit.

A live, project-based bootcamp with Aron Lange — practising ISO 27001 Lead Auditor who has trained 32,000+ GRC professionals in 100+ countries. Official TRECCERT Lead Implementer exam and free retake included.

var(--variable-XyHDm_4NX)

Taught by Aron Lange

English

Cohort start date

20 seats

per cohort

TRECCERT

approved Trainer

Founding price ends in:
00
Days
00
Hours
00
Minutes
00
Seconds

Live Workshops

Live Q&A

On-demand Course

Exam Voucher

Study Guide

ISO 27001 Toolkit

Free retake is included

Founding price ends in:
00
Days
00
Hours
00
Minutes
00
Seconds

Live Workshops

Live Q&A

On-demand Course

Exam Voucher

Study Guide

ISO 27001 Toolkit

Free retake is included

Certified. Trained. And still not sure you could actually run the project.

I audit management systems for a living. I’ve lost count of how often this happens: a trained, certified professional shows me the policy — and freezes when I ask why it exists.


Not because they didn’t study. Because knowing the standard and building an ISMS are two different skills, and almost every course only teaches the first one.

You know the standard.

Clauses 4–10, Annex A. Maybe a certificate on the wall.

You’ve been handed the project.

“You’re the ISO person now.” Or you want to be.

You don’t know what to do on Monday.

Where to start. What to write first. What the auditor will actually ask.

The gap costs you every month it stays open: the consultant runs the project instead of you, the Stage 2 auditor finds the risk method nobody can explain, or the certification slips another quarter — together with the customer deal that depended on it.

One real ISO 27001 project. Scope to audit-ready. Four weeks. An auditor in the room.

I don’t teach you about the standard — you already have that. You build an ISMS, step by step, with the same 12-step roadmap I follow as an implementer and check as an auditor.


Every Monday I work the week’s steps live on a real project. In between, you apply them to your own organisation — or to the case company if you don’t have one yet. Every Friday you bring whatever is blocking you, and we solve it before it stalls you.

Live workshops · Mondays · 2 h

16:00 CEST · 10:00 ET · 15:00 UK. Watch a real implementation unfold, then apply the same step to your project.

On-demand in between · ~3 h/week

The full 12-hour Lead Implementer course (18,000+ students, 4.7★), lifetime access.

Live Q&A · Fridays · 1 h

Same time. Every blocker solved by a practising Lead Auditor. Recorded if you miss it.

Built for the person who has to make it work.

This is for you if:

You’re a security officer, ISMS or compliance manager with an ISO 27001 project on your desk — or about to land there.

You’re the IT or operations lead who was “made the ISO person”.

You’re a consultant who wants to run implementations, not just advise on them.

You’re an internal auditor who wants the implementer’s view of the standard.

Not for you if:

You want a certificate without building anything. Take the on-demand course.

You can’t put in about six hours a week for four weeks.

You want theory only.

Agenda

Four weeks. Twelve steps. A working ISMS.

Live Workshop

Live

Every Monday · 2 hours ·

Live Q&A

Live

Every Friday · 1 hour ·

Scope & Foundation

Steps 1–3

Week 1

01

Kickoff workshop — scoping the ISMS on a real project

Live

02

Scope of the ISMS · Gap analysis — Steps 1–2

On-demand

03

Management support & project setup — Step 3

On-demand

04

Q&A — blockers, scope reviews, first deliverables

Live

Governance & Assets

Steps 4–6

Week 2

05

Workshop — writing the information security policy

Live

06

Policy · Competence & awareness — Steps 4–5

On-demand

07

Inventory of assets — Step 6

On-demand

08

Q&A — policies, awareness plans, asset registers

Live

Risk, End to End

Steps 7–9

Week 3

09

Workshop — running the risk assessment

Live

10

Risk methodology · Risk assessment — Steps 7–8

On-demand

11

Risk treatment & Statement of Applicability — Step 9

On-demand

12

Q&A — defending your risk method in an audit

Live

Audit-Ready & Exam

Steps 10–12

Week 4

13

Workshop — preparing for stage 1 and stage 2

Live

14

Performance evaluation · Improvement — Steps 10–11

On-demand

15

Certification audit · Practice exam — Step 12

On-demand

16

Q&A — final review and exam strategy

Live

What's included

Every blocker I've seen stall an ISMS project — solved before it stalls you.

8 live sessions across 4 weeks
LIVE SESSIONS

8 Live Sessions Across 4 Weeks

Four Monday implementation workshops and four Friday Q&A sessions — every blocker solved by a practising Lead Auditor, on a fixed cohort deadline that pulls you through.

ISO 27001 Toolkit templates
ISO 27001 toolkit documents, including policies and a risk register
TOOLKIT

ISO 27001 Toolkit

Standard-aligned policies, processes, and records — ready to adapt to your organisation.

Lead Implementer on-demand course
Video training lessons shown on a laptop screen
COURSE

12-Hour Lead Implementer Course

The full on-demand course (30,000+ students, 4.7★) to work through between sessions — with lifetime access to every future update.

Exam voucher with free retake
var(--variable-gKO55sYIs)
VOUCHER

Exam Voucher with Free Retake

Your enrollment includes the official certification exam voucher plus a free retake — a second chance at no additional cost.

Practice exam preview
Sample question from the ISO 27001 practice exam
EXAM

Practice Exam

A full practice exam that mirrors the style and format of the real thing, so you know exactly what to expect on exam day.

Official study guide
Official TRECCERT study guide and course templates
STUDY GUIDE

Official Study Guide

The extensive official TRECCERT study guide covers everything you need to pass the exam — and doubles as a valuable on-the-job reference.

Certification

Become a certified ISO/IEC 27001 Lead Implementer.

PARTNER

Official TRECCERT Partner

GRCLab is a TRECCERT approved trainer and reseller. Everything you need to sit the official exam is included with your seat. Most GRCLab candidates pass at the first attempt — and if you don't, the retake is free.

Abstract white flowing lines background
TRECCERT Approved Reseller badge
Abstract white flowing lines background
TRECCERT Approved Reseller badge
Abstract white flowing lines background
TRECCERT Approved Reseller badge
Lirim Bllaca, TRECCERT
Aron Lange headshot

Lirim Bllaca

COO @ TRECCERT

"We could not be prouder of our partnership with GRC Lab. When it comes to delivering top-tier training for our certifications, we’ve found an exceptional match in Aron. Our candidates have greatly benefited from his expertise leading to outstanding success rates on certification exams."

"We could not be prouder of our partnership with GRC Lab. When it comes to delivering top-tier training for our certifications, we’ve found an exceptional match in Aron. Our candidates have greatly benefited from his expertise leading to outstanding success rates on certification exams."

14-day money-back guarantee badge
GUARANTEE

100% Peace of Mind

Every option includes one free retake. If you do not pass on your first attempt, we send you a second voucher at no cost. No forms, no justification, no additional payment.

Meet your trainer

Aron Lange, ISO 27001 trainer at GRC Lab

Aron Lange

CISM

CISA

CRISC

CGEIT

ISO 27001 Lead Implementer

ISO 27001 Lead Auditor

For years I was the auditee. As a Security Officer, I implemented and ran an ISMS in accordance with ISO 27001, and in every audit I was the one answering for it. You learn quickly what holds up and what falls apart the moment someone asks why.

Then I switched sides. As a Lead Auditor for ISO 27001 and ISO 27701, I now ask the questions. Across dozens of management systems, I kept meeting the same problem I once had myself: trained, certified professionals who could show me the policy but froze when I asked why it exists. I knew that feeling. I had been in their seat.

So I built this course from both sides of the audit table. The 12 steps follow how implementations actually unfold, because I have run one. The lessons dwell on why each requirement exists, because asking why is now my job.

More than 32,000 professionals in over 100 countries have trained with me since. The exam tests whether you know the standard. The audit tests whether you understood it. This bootcamp prepares you for both — because I sit on both sides of the table.

Hear it from our partners and students

Johannes Hussak

Co-Founder @ Kertos

I was so impressed by this course that we decided to license it for our customers at Kertos. Together with our platform, this course has helped many of our clients in becoming ISO/IEC 27001 certified at record speed.

Jacob Hill

Directory of Cybersecurity @ Summit 7

"Aron is very knowledgeable and his content is excellent! His ISO 27001 course helped me prepare for our certification audit!"

Oliver Gehrmann

Business Lead Security & Compliance @ PCG

This course is my top recommendation for GRC onboarding. With clear content, practical examples, and excellent structure, it's the perfect choice for quickly and effectively diving into Governance, Risk & Compliance. Highly recommended!

Nouha Schönbrunn

CEO @ Schönbrunn TASC

We’ve been working with Aron as one of our trusted external trainers, and his courses have become a core part of our onboarding for new junior consultants. Aron’s training approach is clear, down-to-earth, and tailored to help beginners really understand the essentials. He makes complex topics accessible, and I’ve seen firsthand how much confidence his courses give our new hires right from the start. 

Marcel Rieger

Managing Director @ JAMORIE Consulting

I appreciated Aron’s courses, as they illustrate complex concepts in an engaging and practical way! They have greatly supported my learning journey in information security.

Alexander Steinmoeller

Founder and Principal Consultant @ Cybrbolt

This course truly simplifies the complex ISO 27001 standard into practical steps. I've successfully applied Aron's approach in both in my practice and with my clients. Aron's clear, detailed teaching style makes the material easily digestible. I regularly check for updates as it has become my go-to resource.

Johannes Hussak

Co-Founder @ Kertos

I was so impressed by this course that we decided to license it for our customers at Kertos. Together with our platform, this course has helped many of our clients in becoming ISO/IEC 27001 certified at record speed.

Jacob Hill

Directory of Cybersecurity @ Summit 7

"Aron is very knowledgeable and his content is excellent! His ISO 27001 course helped me prepare for our certification audit!"

Oliver Gehrmann

Business Lead Security & Compliance @ PCG

This course is my top recommendation for GRC onboarding. With clear content, practical examples, and excellent structure, it's the perfect choice for quickly and effectively diving into Governance, Risk & Compliance. Highly recommended!

Pricing

Next cohort starts October 5th.

FAQ

The answers to the most frequently asked questions.

How is the Bootcamp different from the on-demand course?

How much time do I need each week?

What if I miss a live session?

How does the certification exam work?

Who is this Bootcamp for?

Why should I apply instead of just buying?

Founding price ends in:
00
Days
00
Hours
00
Minutes
00
Seconds

Live Workshops

Live Q&A

On-demand Course

Exam Voucher

Study Guide

ISO 27001 Toolkit

Free retake is included

Close the gap between knowing and doing.

Founding Cohort starts October 5, 2026. The founding price ends September 15.

00
Days
00
Hours
00
Minutes
00
Seconds

Application takes 3 minutes · You hear back within 2 business days